Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • Noberus ransomware: evolving tactics.

    Brigid O Gorman from Symantec's Threat Hunter team joins Dave to discuss their research on "Noberus Ransomware - Darkside and BlackMatter Successor Continues to Evolve its Tactics." The research states that Noberus ransomware (aka BlackCat, ALPHV) is more dangerous than ever because attackers have been using new tactics, tools, and procedures in recent months.

    In the research, Symantec says, "Among some of the more notable developments has been the use of a new version of the Exmatter data exfiltration tool, and the use of Eamfo, information-stealing malware that is designed to steal credentials stored by Veeam backup software." They go over an in-depth look at how its affiliate program operates.

    The research can be found here:

    • Noberus Ransomware: Darkside and BlackMatter Successor Continues to Evolve its Tactics

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    22 min
  • Google Drive used for malware?

    Jen Miller-Osborn from Palo Alto Networks' Unit 42 joins Dave to discuss their work on the Cloaked Ursa group, with a recent report released called "Russian APT29 Hackers Use Online Storage Services, DropBox and Google Drive." The research shares insights into an active campaign from Russia’s Foreign Intelligence Service, that is leveraging the use of trusted, legitimate cloud services including Google Drive as a staging platform to deliver malware.

    The research states that when these tactics are used, it is extremely difficult for organizations to detect the malicious activity in connection with the campaign. These tactics are used to collect victim information, evade detection, and deliver Cobalt Strike.

    The research can be found here:

    • Russian APT29 Hackers Use Online Storage Services, DropBox and Google Drive

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    23 min
  • Targeting your browser bookmarks?

    David Prefer from SANS sits down with Dave to discuss how a new covert channel exfiltrates data via a browser's built-in bookmark sync. David goes on to describe how this research will "describe how the ability to synchronize bookmarks across devices introduces a novel vector for data exfiltration and other misuses."

    In the research, he shares how he tested his said hypothesis and goes on to describe how the interesting find was tested on multiple browsers including Chrome, Edge, Brave and Opera. In his research, he found that bookmarks are able to keep data and synchronize it, making it easier to infiltrate and extract data from. David shares the rest of his findings, as well as what organizations and browser developers can do to work on this new threat.

    The research can be found here:

    • Bookmark Bruggling: Novel Data Exfiltration with Brugglemark

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    19 min
  • Keeping an eye on RDS vulnerabilities.

    Gafnit Amiga, Director of Security Research from Lightspin, joins Dave to discuss her team's research "AWS RDS Vulnerability Leads to AWS Internal Service Credentials." The research describes how the vulnerability was caught and right after it was reported, the AWS Security team applied an initial patch limited only to the recent Amazon Relational Database Service (RDS) and Aurora PostgreSQL engines, excluding older versions.

    They followed by personally reaching out to the customers affected by the vulnerability and helped them through the update process. The research states "Lightspin's Research Team obtained credentials to an internal AWS service by exploiting a local file read vulnerability on the RDS EC2 instance using the log_fdw extension."

    The research can be found here:

    • AWS RDS Vulnerability Leads to AWS Internal Service Credentials

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    17 min
  • An increase in bypassing bot management?

    Sam Crowther, CEO of Kasada join's Dave to discuss their work on "The New Way Fraudsters Bypass Bot Management." Kasada researchers recently discovered a new type of bot called Solver Services, which is used and created by bad actors to bypass the majority of bot management systems.

    The research states "Now it’s easier than ever for mainstream bot operators to scrape content, take over accounts, hoard inventory, and commit other forms of automated fraud against organizations using legacy bot management solutions." Attackers are able to buy these “Solver” bots, APIs, and services for less than $500 per month to make a profit.

    The research can be found here:

    • The Emergence of Solver Services: The New Way Fraudsters Bypass Bot Management Vendors

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    15 min
  • Evilnum APT returns with new targets.

    Deepen Desai from Zscaler ThreatLabz joins Dave to discuss their work on "Return of the Evilnum APT with updated TTPs and new targets." Zscaler’s ThreatLabz team recently caught a new Evilnum APT attack campaign that uses the document template on MS Office Word to inject malicious payload to the victim's machine. There are three new instances used of the campaign, including updated tactics, techniques, and procedures.

    Researchers have been closely monitoring Evilnum APT’s activity. They ssay ThreatLabz identified several domains associated with the Evilnum APT group. Which has led them to discover that the "group has been successful at flying under the radar and has remained undetected for a long time."

    The research can be found here:

    • Return of the Evilnum APT with updated TTPs and new targets

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    22 min
  • LockBit's contradiction on encryption speed.

    Ryan Kovar from Splunk sits down with Dave to discuss their findings in "Truth in Malvertising?" that contradict the LockBit group's encryption speed claims. Splunk's SURGe team recently released a whitepaper, blog, and video that outlined the encryption speeds of 10 different ransomware families. During their research they cam across Lockbit doing the same thing. After completing the research, the researchers came back to test the veracity of LockBit’s findings.

    The research showed three interesting finds. The first find showed that LockBit’s fastest and slowest samples were closely aligned between the tests, but the other results were very different. They also found that LockBit continues to be the fastest ransomware, but LockBit 2.0 was more efficient yet slower than its previous counterpart, LockBit 1.0. Lastly, once ransomware gets to the point of encrypting your systems, it’s too late.

    The research can be found here:

    • Truth in Malvertising?

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    20 min
  • How a wide scale Facebook campaign stole 1 million credentials.

    Nick Ascoli from ForeTrace in a partnership with PIXM sits down with Dave to provide insight on their team's work on "Phishing tactics: how a threat actor stole 1 million credentials in 4 months." During routine analysis, researchers discovered the connection between the pages using PIXM’s deep html analysis feature, which enabled them to view and analyze the underlying code on the pages after they were flagged as phishing. This led to the ensuing investigation, which was led by PIXM’s threat research team with assistance from Nick Ascoli.

    The research states "we uncovered a campaign whose scale has potentially impacted hundreds of millions of facebook users, and whose complexity offer insight into the evolving nature of phishing operations, especially from a technical perspective."

    The research can be found here:

    • Phishing tactics: how a threat actor stole 1M credentials in 4 months

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    25 min
  • Clipminer: Making millions off of malware.

    Dick O'Brien from Symantec, a part of Broadcom Software, joins Dave to discuss how the cyber-criminal operation, Clipminer Botnet, makes operators behind it at least $1.7 million. Symantec's research says "The malware being used, tracked as Trojan.Clipminer, has a number of similarities to another crypto-mining Trojan called KryptoCibule, suggesting it may be a copycat or evolution of that threat."

    Symantec determined that the malware has the ability to mine for cryptocurrency using compromised computers’ resources. They also share a way to protect against the cyber-criminal operation, as well as sharing some indicators you could be compromised.

    The research can be found here:

    • Clipminer Botnet Makes Operators at Least $1.7 Million

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    17 min
  • Fake job ads and how to spot them.

    Ashley Taylor from SANS.edu, joins Dave to discuss fake job ads and methods to proactively detect these scams. The research shares how job seekers are under attack, with scammers posing as fake job recruiters to steal information from people who are interested in the job posting. The brands being impersonated as are at risk of losing credibility to their brand identity.

    The research shares exactly how these doppelgängers are posing a threat to job seekers and the best practices to detect these scams. It also shares how one company that works in medical device manufacturing industry has been a target for these scams. It concludes with sharing some of the ways to proactively spot these scams before they happen.

    The research can be found here:

    • Doppelgängers: Finding Job Scammers Who Steal Brand Identities

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    19 min

About Research Saturday

From the publisher's feed

Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

More shows like Research Saturday

Risky Business by Risky Business Media

Risky Business

375 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

ChinaPower by CSIS | Center for Strategic and International Studies

ChinaPower

206 Listeners

Smashing Security by Graham Cluley

Smashing Security

317 Listeners

Click Here by Recorded Future News

Click Here

420 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,058 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

Career Notes by N2K Networks

Career Notes

14 Listeners

Pekingology by Center for Strategic and International Studies

Pekingology

141 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

The AI Fix by Mark Stockley

The AI Fix

32 Listeners

The FAIK Files by Perry Carpenter | N2K Networks

The FAIK Files

18 Listeners