Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • Iran-linked Lyceum Group adds a new weapon to its arsenal.

    Deepen Desai from Zscaler's ThreatLabz joins Dave to discuss how APTs, like Lyceum Group, create tactics and malware to carry out attacks against their targets. The Lyceum group has been active since 2017 and is a state-sponsored Iranian APT group. This group targets Middle Eastern organizations most notably in the energy and telecommunication sectors, and they rely heavily on .NET based malwares.

    Zscaler said in their research they "recently observed a new campaign where the Lyceum Group was utilizing a newly developed and customized .NET based malware targeting the Middle East by copying the underlying code from an open source tool." They go on to give an analysis explaining why the .NET based DNS backdoor is causing problems.

    The research can be found here:

    • Lyceum .NET DNS Backdoor

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    16 min
  • What malicious campaign is lurking under the surface?

    Israel Barak, CISO from Cybereason, sits down with Dave to discuss their research, "Operation CuckooBees: Cybereason Uncovers Massive Chinese Intellectual Property Theft Operation." Cybereason researchers recently found an attack lurking beneath the surface which was assessed to be the work of Chinese APT Winnti. Cybereason briefed the FBI and the DOJ on the investigation into the malicious campaign.

    The research states, "For years, the campaign had operated undetected, siphoning intellectual property and sensitive data." The team quickly made two reports on the campaign, one sharing an examination on the tactics and techniques. The second gives a detailed analysis of the malware and exploits used.

    The research can be found here:

    • Operation CuckooBees: Cybereason Uncovers Massive Chinese Intellectual Property Theft Operation

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    22 min
  • Has GOLD SOUTHFIELD resumed operations?

    Rob Pantazopoulos from Secureworks, joins Dave to discuss their work on "REvil Development Adds Confidence About GOLD SOUTHFIELD Reemergence." Secureworks researchers published a new analysis on what can be considered the ‘first’ set of ransomware samples associated with the reemergence. These updated samples indicate that GOLD SOUTHFIELD has resumed operations.

    The research states "The identification of multiple samples containing different modifications and the lack of an official new version indicate that REvil is under active development." Researchers identified two samples, one in October of 2021, and the other in March of 2022. The March sample has modifications that lead researchers to distinguish the two samples from one another.

    The research can be found here:

    • REvil Development Adds Confidence About GOLD SOUTHFIELD Reemergence

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    22 min
  • A record breaking DDoS attack.

    Chad Seaman, Team Lead at Akamai SIRT joins Dave to discuss their research about a record-breaking DDoS Attack. The research says "A new reflection/amplification distributed denial-of-service (DDoS) vector with a record-breaking potential amplification ratio of 4,294,967,296:1 has been abused by attackers in the wild to launch multiple high-impact DDoS attacks."

    Starting in mid-February 2022, security researchers, network operators, and security vendors noticed a spike in DDoS attacks. Researchers started to investigate the spike and determined that the devices that were being abused to launch these attacks are MiCollab and MiVoice Business Express collaboration systems. The research goes into how you can help mitigate the attacks and how Mitel has now released patched software.

    The research can be found here:

    • CVE-2022-26143: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    25 min
  • Information operations during a war.

    Alden Wahlstrom, senior analyst on Mandiant's Information Operations Team, shares a comprehensive overview and analysis of the various information operations activities they’ve seen while responding to the Russian invasion. While the full extent of the Russia-Ukraine war has yet to come to light, more than two months after the start of the invasion, Mandiant has identified activity that they believed to be information operations campaigns conducted by actors possibly in support of the political interests of nation-states such as Russia, Belarus, China, and Iran.

    The research shares a chart with all of the known information operations events that have taken place so far dating back to January of 2022. It also states that following the beginning of the Russian attack they have seen concerning signs, including "incidents involving the deployment of wiper malware disguised as ransomware."

    The research can be found here:

    • The IO Offensive: Information Operations Surrounding the Russian Invasion of Ukraine

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    20 min
  • Could REvil have a copycat?

    Larry Cashdollar from Akamai, joins Dave to discuss their research on a DDoS campaign claiming to be REvil. The research shares that Akamai's team was notified last week of an attack on one of their hospitality customers that they called "Layer 7" by a group claiming to be associated with REvil. In the research, they dive into the attack, as well as comparing it to other similar attacks that have been made by the group.

    The research states "The attacks so far target a site by sending a wave of HTTP/2 GET requests with some cache-busting techniques to overwhelm the website." It also stated that this is a smaller attack than they have seen by the group before, and notes that there seems to be more of a political agenda behind the attack, whereas in the past, REvil has been less political.

    The research can be found here:

    • REvil Resurgence? Or a Copycat?

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    15 min
  • Lazarus Targets Chemical Sector With 'Dream Job.'

    Alan Neville, a Threat Intelligence Analyst from Symantec Broadcom, joins Dave to discuss their research "Lazarus Targets Chemical Sector." Symantec has observed the North Korea-linked threat group known as Lazarus conducting an espionage campaign targeting organizations operating within the chemical sector.

    The campaign appears to be a continuation of the group's activity called Operation Dream Job, which Symantec first came across in August of 2020. The research states "evidence includes file hashes, file names, and tools that were observed in previous Dream Job campaigns."

    The research can be found here:

    • Lazarus Targets Chemical Sector

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    22 min
  • Dissecting the Spring4Shell vulnerability.

    Edward Wu, senior principal data scientist at ExtraHop, joins Dave to discuss the company's research, "A Technical Analysis of How Spring4Shell Works." ExtraHop first noticed chatter from social media in March of 2022 on a new remote code execution (RCE) vulnerability and immediately started tracking the issue.

    In the research, it describes how the exploit works and breaks down how the ExtraHop team came to identify the Spring4Shell vulnerability. The research describes the severity of the vulnerability, saying, "The impact of an RCE in this framework could have a serious impact similar to Log4Shell."

    The research can be found here:

    • How the Spring4Shell Zero-Day Vulnerability Works

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    23 min
  • New developments in the WSL attack.

    Danny Adamitis from Lumen's Black Lotus Labs, joins Dave to discuss new developments in the WSL attack surface. Since September 2021, Black Lotus Labs have been monitoring malware repositories as a part of their proactive threat hunting process. Danny shares how researchers discovered a series of suspicious ELF files compiled for Debian Linux .

    The research states how the team identified a series of samples that target the WSL environment, they were uploaded every two to three weeks and started as early as May 3, 2021 and go until August 22, 2021.

    The research can be found here:

    • Windows Subsystem For Linux (WSL): Threats Still Lurk Below The (Sub)Surface
    • No Longer Just Theory: Black Lotus Labs Uncovers Linux Executables Deployed As Stealth Windows Loaders
    • Learn more about your ad choices. Visit megaphone.fm/adchoices

      23 min
    • LemonDucks evading detection.

      Scott Fanning from CrowdStrike's research team, joins Dave to discuss their work on "LemonDuck Targets Docker for Cryptomining Operations." LemonDuck is a well-known cryptomining botnet, and the research suggests attackers are attracted to the monetary gain from the recent boom in cryptocurrency.

      LemonDuck was caught trying to disguise its attack against Docker by running an anonymous mining operation by the use of proxy pools. Scott shares how its unknown which organizations have been targeted and just how much cryptocurrency has been stolen.

      The research can be found here:

      • LemonDuck Targets Docker for Cryptomining Operations

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      16 min

    About Research Saturday

    From the publisher's feed

    Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

    More shows like Research Saturday

    Risky Business by Risky Business Media

    Risky Business

    375 Listeners

    CyberWire Daily by N2K Networks

    CyberWire Daily

    1,028 Listeners

    ChinaPower by CSIS | Center for Strategic and International Studies

    ChinaPower

    206 Listeners

    Smashing Security by Graham Cluley

    Smashing Security

    317 Listeners

    Click Here by Recorded Future News

    Click Here

    420 Listeners

    Darknet Diaries by Jack Rhysider

    Darknet Diaries

    8,058 Listeners

    Cybersecurity Today by David Shipley

    Cybersecurity Today

    179 Listeners

    Hacking Humans by N2K Networks

    Hacking Humans

    314 Listeners

    CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

    CISO Series Podcast

    191 Listeners

    Career Notes by N2K Networks

    Career Notes

    14 Listeners

    Pekingology by Center for Strategic and International Studies

    Pekingology

    141 Listeners

    Cybersecurity Headlines by CISO Series

    Cybersecurity Headlines

    138 Listeners

    The AI Fix by Mark Stockley

    The AI Fix

    32 Listeners

    The FAIK Files by Perry Carpenter | N2K Networks

    The FAIK Files

    18 Listeners