Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • Cold lures, hot targets.

    This week, we are joined by Ondrej Kubovič, Security Awareness Specialist from ESET, discussing their work on "FrostyNeighbor: Fresh mischief and digital shenanigans." Ondrej walks us through ESET's latest research into FrostyNeighbor, a long-running Belarus-aligned cyberespionage group that has continued to target Ukrainian government organizations with increasingly sophisticated spearphishing campaigns.

    We discuss how the group uses malicious PDF lures, server-side victim validation, and an updated JavaScript-based malware chain to selectively deploy espionage tools, demonstrating its ongoing efforts to evade detection while compromising high-value targets across Eastern Europe.

    The research and executive brief can be found here:

    • ⁠FrostyNeighbor: Fresh mischief and digital shenanigans
    • Learn more about your ad choices. Visit megaphone.fm/adchoices

      18 min
    • When trusted sites turn.

      Lauren Fievisohn, Ph.D, Senior Threat Researcher from Silent Push, is sharing their work on "Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites." Silent Push researchers have identified a newly named threat actor, DriveSurge, which has compromised thousands of legitimate websites and uses ClickFix and fake browser update lures to distribute malware at scale through a pay-per-install operation.

      The group leverages a traffic distribution system called zTDS to silently redirect visitors from trusted websites to malicious payloads, while employing sophisticated infrastructure, obfuscation, and fingerprinting techniques to evade detection. The report also details how DriveSurge targets both Windows and macOS users and provides defenders with eight infrastructure fingerprints to help identify and disrupt the campaign.

      The research and executive brief can be found here:

      • Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites
      • Learn more about your ad choices. Visit megaphone.fm/adchoices

        18 min
      • Conti-versal opinions.

        Today we are joined by Geoff White, host of Cyber Hack and BBC journalist, taking a deep dive into the Conti ransomware gang. Geoff explores an in-depth investigation into the notorious Conti ransomware gang, drawing from thousands of leaked internal messages to reveal how the group operated behind the scenes.

        The research uncovers surprising internal debates over targeting healthcare organizations, the fallout from accidentally exposing sensitive Saudi royal family data, and frantic efforts to free an arrested gang member. It also offers a rare look at Conti leader Vitaliy Kovalev through newly uncovered video footage, providing an unprecedented glimpse into one of cybercrime's most influential figures.

        Learn more about your ad choices. Visit megaphone.fm/adchoices

        30 min
      • Is your enterprise AI strategy delivering ROI yet? [AI Security Brief]

        While we take a break this 4th of July weekend, please enjoy this encore of AI Security Brief.

        Your enterprise AI strategy isn’t as far along as you think. The reality for most organizations today is that AI is disrupting existing processes more than it’s delivering outcomes… so far. And according to Dr. Grace Trinidad, Research Director at IDC, that’s how it should be.

        In this episode, host Johnny Hand sits down with Dr. Grace to discuss how AI adoption follows the same pattern as almost every major digital transformation, and why this disruption phase we’re in is messy, yet critically important. 

        What we cover:

        • How history demonstrates that automation across industries created disruption well before delivering value

        • Why your AI adoption strategy is much more than simple tool deployment

        • What business and technology leaders need to consider as they integrate AI into operational workflows

        • How token consumption and AI FinOps are the emerging security and cost risk

        • How AI ontologies will be the next real business differentiator

          Why stick around: 

          If you’ve been wondering if your organization’s AI adoption strategy is ahead of the curve, Dr. Grace will give you a much clearer picture of where you really stand.

          Episode resources:

          • Dr. Grace Trinidad on LinkedIn

          • Securing the AI Enterprise: 5 Key Steps for Business Leaders

          • Closing the Governance Gap in Agentic AI

          • ⁠Johnny Hand on LinkedIn

          • TrendAI on LinkedIn

            About AI Security Brief

            AI Security Brief is where security and technology leaders come to get ahead. Join us for real conversations on the AI trends, threats, and decisions that can't wait.

            About TrendAI™

            TrendAI™ empowers organizations to lead the future of AI with proactive security designed to inspire innovation and eliminate risk. TrendAI™. AI Fearlessly.

            Learn more about your ad choices. Visit megaphone.fm/adchoices

            25 min
          • More bark than byte.

            This week we are joined by Daniel Schwalbe, Chief Information Security Officer & Head of Investigations at DomainTools, discussing their work on "ZionSiphon OT Malware First Attempts? Psyops? Both?" Researchers at DomainTools take a closer look at ZionSiphon, a purported operational technology malware sample targeting the water sector, and find that despite its alarming appearance, it lacks many of the capabilities needed to function as a credible cyber-physical weapon.

            They break down the malware's architecture, its operational shortcomings, and why it may be more of a prototype or proof of concept than a deployable threat. With heightened concern surrounding attacks on critical infrastructure amid the ongoing U.S.-Iran conflict, the research offers timely insight into separating genuine OT threats from overhyped malware.

            The research and executive brief can be found here:

            • Threat Intelligence Report: ZionSiphon OT Malware First Attempts? Psyops? Both?
            • Learn more about your ad choices. Visit megaphone.fm/adchoices

              25 min
            • Peeling back Banana RAT.

              This week, we are joined by Tom Kellermann, TrendAI's VP of AI Security and Threat Research, discussing their work on "Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud." Researchers from TrendAI's MDR team uncovered the full operation behind Banana RAT, a sophisticated banking trojan they track as SHADOW-WATER-063, by analyzing both attacker infrastructure and infected victim systems.

              The malware uses fileless PowerShell execution, layered obfuscation, and remote-control capabilities to steal credentials, manipulate banking sessions, intercept Pix QR code payments, and facilitate financial fraud targeting Brazilian banks. The campaign appears to be operated by a Brazilian Portuguese-speaking cybercriminal group with ties to the broader Tetrade banking malware ecosystem and may be evolving toward a malware-as-a-service model.

              The research and executive brief can be found here:

              • ⁠Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud
              • Learn more about your ad choices. Visit megaphone.fm/adchoices

                29 min
              • This Sparrow doesn't migrate.

                Martin Zugec, Technical Solutions Director at Bitdefender, discussing their work on "FamousSparrow APT Targets Azerbaijani Oil and Gas Industry." Bitdefender researchers uncovered a sustained cyber espionage campaign by the China-linked FamousSparrow group targeting an Azerbaijani oil and gas company, highlighting the growing focus on critical energy infrastructure in the South Caucasus. The attackers repeatedly exploited the same vulnerable Microsoft Exchange server over multiple months, deploying evolving versions of Deed RAT and Terndoor malware through sophisticated DLL sideloading techniques designed to evade detection and maintain persistence. The operation underscores FamousSparrow's adaptability and persistence, demonstrating how advanced threat actors continually refine their tooling and return to compromised environments until vulnerabilities are fully remediated and access is cut off.

                The research and executive brief can be found here:

                • FamousSparrow APT Targets Azerbaijani Oil and Gas Industry
                • Learn more about your ad choices. Visit megaphone.fm/adchoices

                  23 min
                • You've been muted...permanently.

                  Ismael Valenzuela, Arctic Wolf’s VP of Labs, Threat Research and Intelligence, discusses their work on "BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector." Arctic Wolf researchers uncovered a sophisticated campaign by North Korean threat group Lazarus Group subgroup BlueNoroff that targets cryptocurrency and Web3 executives through fake Zoom and Microsoft Teams meetings, using typo-squatted links, ClickFix-style attacks, and AI-generated deepfakes to steal credentials and cryptocurrency-related data.

                  The attackers built a self-reinforcing operation that captures victims’ webcam footage and Telegram sessions, then repurposes those assets alongside AI-generated images to create increasingly convincing fake meeting participants for future attacks. Researchers identified more than 100 victims across 20 countries, with the campaign primarily targeting CEOs, founders, investors, and senior leaders in the cryptocurrency, blockchain, and financial sectors as part of a long-running effort to steal digital assets and gain access to high-value networks.

                  The research and executive brief can be found here:

                  • BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector
                  • Learn more about your ad choices. Visit megaphone.fm/adchoices

                    22 min
                  • The skills pay the bills.

                    Today we are joined by Marco Giuliani, Vice President & Head of Research at ThreatDown, discussing their work on "GachiLoader adopts AI skill lure." Threat actors are now using fake AI agent “skills” as highly convincing social engineering lures, with a new campaign disguising the GachiLoader malware as a legitimate OpenClaw tool for automated Polymarket betting.

                    Victims are tricked through fake installation guides and polished Electron apps into downloading malware that deploys the Rhadamanthys infostealer using fileless injection and blockchain-based command-and-control infrastructure. Researchers say the campaign marks an evolution in cybercrime, turning AI skill ecosystems into a new phishing-style attack surface.

                    The research and executive brief can be found here:

                    • ⁠GachiLoader adopts AI skill lure

                      Learn more about your ad choices. Visit megaphone.fm/adchoices

                      25 min
                    • Ghosted by Grafana

                      Today we are joined by ⁠Sasi Levi⁠, Security Research Lead at ⁠Noma Security⁠, sharing their team's work on "GrafanaGhost: The Phantom Stealing Your Data." Researchers at Noma Security disclosed “GrafanaGhost,” a vulnerability that could allow attackers to silently exfiltrate sensitive business data from Grafana dashboards using indirect prompt injection techniques.

                      The attack chains together multiple bypasses, including protocol-relative URLs and AI guardrail manipulation, to trick Grafana into sending sensitive data to attacker-controlled servers without requiring user interaction. Researchers say the flaw highlights growing risks tied to AI-integrated enterprise platforms, where attackers increasingly target AI behavior and weak security controls instead of traditional software bugs.

                      The research and executive brief can be found here:

                      • ⁠GrafanaGhost: The Phantom Stealing Your Data⁠

                        Learn more about your ad choices. Visit megaphone.fm/adchoices

                        26 min

                      About Research Saturday

                      From the publisher's feed

                      Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

                      More shows like Research Saturday

                      Risky Business by Risky Business Media

                      Risky Business

                      374 Listeners

                      CyberWire Daily by N2K Networks

                      CyberWire Daily

                      1,027 Listeners

                      ChinaPower by CSIS | Center for Strategic and International Studies

                      ChinaPower

                      206 Listeners

                      Smashing Security by Graham Cluley

                      Smashing Security

                      317 Listeners

                      Click Here by Recorded Future News

                      Click Here

                      420 Listeners

                      Darknet Diaries by Jack Rhysider

                      Darknet Diaries

                      8,055 Listeners

                      Cybersecurity Today by David Shipley

                      Cybersecurity Today

                      179 Listeners

                      Hacking Humans by N2K Networks

                      Hacking Humans

                      314 Listeners

                      CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

                      CISO Series Podcast

                      191 Listeners

                      Career Notes by N2K Networks

                      Career Notes

                      14 Listeners

                      Pekingology by Center for Strategic and International Studies

                      Pekingology

                      140 Listeners

                      Cybersecurity Headlines by CISO Series

                      Cybersecurity Headlines

                      138 Listeners

                      The AI Fix by Mark Stockley

                      The AI Fix

                      32 Listeners

                      The FAIK Files by Perry Carpenter | N2K Networks

                      The FAIK Files

                      18 Listeners