Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • The rise of Karakurt Hacking Team.

    Guest Rob Boyce, Accenture's Global Lead for Cyber Incident Response and Transformation Services, joins Dave to discuss their research "Karakurt rises from its lair." Accenture Security has identified a new threat group, the self-proclaimed Karakurt Hacking Team, that has impacted over 40 victims across multiple geographies. The threat group is financially motivated, opportunistic in nature, and so far, appears to target smaller companies or corporate subsidiaries versus the alternative big game hunting approach. Based on intrusion analysis to date, the threat group focuses solely on data exfiltration and subsequent extortion, rather than the more destructive ransomware deployment. In addition, Accenture Security assesses with moderate-to-high confidence that the threat group’s extortion approach includes steps to avoid, as much as possible, drawing attention to its activities.

    The research can be found here:

    • Karakurt rises from its lair

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    13 min
  • Encore: When big ransomware goes away, where should affiliates go?

    Our guest Doel Santos, Threat Research Analyst at Palo Alto Networks, joins Dave Bittner to talk about Unit 42's work on "Ransomware Groups to Watch: Emerging Threats." As part of Unit 42’s commitment to stop ransomware attacks, they monitor the activity of existing groups, search for dark web leak sites and fresh onion sites, identify up-and-coming players and study tactics, techniques and procedures. During their operations, Unit 42 observed four emerging ransomware groups that are currently affecting organizations and show signs of having the potential to become more prevalent in the future. Doel discusses these (AvosLocker, Hive Ransomware, HelloKitty, and LockBit 2.0) with Dave.

    The research can be found here:

    • Ransomware Groups to Watch: Emerging Threats

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    20 min
  • CyberWire Pro Research Briefing from 12/21/2021.

    Enjoy a peek into CyberWire Pro's Research Briefing as the team is off taking our long winter's nap. This is the spoken edition of our weekly Research Briefing, focused on threats, vulnerabilities, and consequences, as they’re played out in cyberspace. This week's headlines: US Commission on International Religious Freedom reportedly hacked. Sophistication of NSO exploit on par with nation-state tooling. Conti ransomware actors exploit Log4Shell. Like what you hear? Consider subscribing to CyberWire Pro for $99/year. Learn more.

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    10 min
  • Discovering ChaosDB, a critical vulnerability in the CosmosDB.

    Guests Sagi Tzadik and Nir Ohfeld of cloud security company Wiz join Dave to discuss their research "ChaosDB: How we hacked thousands of Azure customers’ databases." Nearly everything we do online these days runs through applications and databases in the cloud. While leaky storage buckets get a lot of attention, database exposure is the bigger risk for most companies because each one can contain millions or even billions of sensitive records. Every CISO’s nightmare is someone getting their access keys and exfiltrating gigabytes of data in one fell swoop.

    Database exposures have become alarmingly common in recent years as more companies move to the cloud, and the culprit is usually a misconfiguration in the customer’s environment. In this case, customers were not at fault.

    The research can be found here:

    • ChaosDB: How we hacked thousands of Azure customers’ databases
    • ChaosDB: How to discover your vulnerable Azure Cosmos DBs and protect them
    • Learn more about your ad choices. Visit megaphone.fm/adchoices

      17 min
    • FIN7 repositioning focus into ransomware.

      Guest Ilya Volovik, Team Lead of Cyber Intelligence at Gemini Advisory, discusses his team's work on "FIN7 Recruits Talent For Push Into Ransomware." The cybercriminal group FIN7 gained notoriety in the mid-2010s for large-scale malware campaigns targeting the point-of-sale (POS) systems. In 2018, Gemini Advisory reported FIN7’s compromise of Saks Fifth Avenue and Lord & Taylor stores and the subsequent sale of over 5 million payment cards on the dark web. According to the US Department of Justice, the broader FIN7 carding campaigns have resulted in the theft of over 20 million payment card records and cost victims over $1 billion, making FIN7 one of the most infamous and prolific cybercriminal groups of the last decade. Now with ransomware proving to be cybercriminals’ preferred high-profit, jackpot venture, FIN7 has redeployed their expertise and capacity towards ransomware, with reports indicating that the group was involved in attempted ransomware attacks on US companies as early as 2020. Furthermore, despite focus from law enforcement and the arrest of four FIN7 members from 2018 to 2020, FIN7’s continued activity shows that the group remains a powerful, active threat.

      The research can be found here:

      • FIN7 Recruits Talent For Push Into Ransomware

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      29 min
    • Getting in and getting out with SnapMC.

      Guest Christo Butcher of NCC Group's Research and Intelligence Fusion Team discusses their research into a cybercriminal group they dubbed SnapMC. Forget ransomware, too expensive and too much hassle. Randomly enter through a known vulnerability, take a look around, lock away data and leave again. And all that within half an hour: hit & run. An email is then sent to the affected organization: pay or else the stolen data will be published and/or sold.

      This is the opportunistic approach of a new group of blackmailers who don't even bother to encrypt data. NCC Group has given them the name SnapMC: a combination of 'snap' (a sudden, sharp cracking sound or movement) and MC, from mc.exe, the primary tool they use to exfiltrate data. They have only seen SnapMC's attacks in the Netherlands for the time being. They do not target specific sectors and we have not (yet) been able to associate them with known attackers.

      The research can be found here:

      • SnapMC: extortion without ransomware
      • SnapMC skips ransomware, steals data
      • Learn more about your ad choices. Visit megaphone.fm/adchoices

        18 min
      • CyberWire Pro Research Briefing from 11/23/2021

        Enjoy a peek into CyberWire Pro's Research Briefing as the team is off recovering from our Thanksgiving feasts. This is the spoken edition of our weekly Research Briefing, focused on threats, vulnerabilities, and consequences, as they’re played out in cyberspace. This week's headlines: Iranian threat actors target the IT supply chain. North Korean cyberespionage. More information on Emotet's return. Like what you hear? Consider subscribing to CyberWire Pro for $99/year. Learn more.

        Learn more about your ad choices. Visit megaphone.fm/adchoices

        9 min
      • Using bidirectionality override characters to obscure code.

        Guests Nicholas Boucher and Ross Anderson from the University of Cambridge join Dave Bittner to discuss their research, "Trojan Source: Invisible Vulnerabilities." The researchers present a new type of attack in which source code is maliciously encoded so that it appears different to a compiler and to the human eye. This attack exploits subtleties in text-encoding standards such as Unicode to produce source code whose tokens are logically encoded in a different order from the one in which they are displayed, leading to vulnerabilities that cannot be perceived directly by human code reviewers. ‘Trojan Source’ attacks, as they call them, pose an immediate threat both to first-party software and of supply-chain compromise across the industry. They present working examples of Trojan-Source attacks in C, C++, C#, JavaScript, Java, Rust, Go, and Python. They propose definitive compiler-level defenses, and describe other mitigating controls that can be deployed in editors, repositories, and build pipelines while compilers are upgraded to block this attack.

        The project website and research can be found here:

        • Trojan Source: Invisible Source Code Vulnerabilities project website
        • Trojan Source: Invisible Vulnerabilities research paper
        • Learn more about your ad choices. Visit megaphone.fm/adchoices

          26 min
        • A glimpse into TeamTNT.

          Senior Intelligence Researcher at Anomali, Tara Gould, joins Dave to discuss their team's work on "Inside TeamTNT’s Impressive Arsenal: A Look Into A TeamTNT Server." Anomali Threat Research discovered an open server to a directory listing that they attribute with high confidence to the German-speaking threat group, TeamTNT. The server contains source code, scripts, binaries, and cryptominers targeting Cloud environments. Other server contents include Amazon Web Services (AWS) Credentials stolen from TeamTNT stealers are also hosted on the server.

          This inside view of TeamTNT infrastructure and tools in use can help security operations teams to improve detection capabilities for related attacks, whether coming directly from TeamTNT or other cybercrime groups leveraging their tools.

          The research can be found here:

          • Inside TeamTNT’s Impressive Arsenal: A Look Into A TeamTNT Server

          Learn more about your ad choices. Visit megaphone.fm/adchoices

          16 min
        • An incident response reveals itself as GhostShell tool, ShellClient.

          Guest Mor Levi, Vice President of Cyber Practices from Cybereason, joins Dave Bittner to discuss her team's work on "Operation GhostShell - Novel RAT Targets Global Aerospace and Telecoms Firms." In July 2021, the Cybereason Nocturnus and Incident Response Teams responded to Operation GhostShell, a highly-targeted cyber espionage campaign targeting the Aerospace and Telecommunications industries mainly in the Middle East, with additional victims in the U.S., Russia and Europe. 

          The Operation GhostShell campaign aims to steal sensitive information about critical assets, organizations’ infrastructure and technology. During the investigation, the Nocturnus Team uncovered a previously undocumented and stealthy RAT (Remote Access Trojan) dubbed ShellClient which was employed as the primary espionage tool. To learn more, listen to the episode.

          The research can be found here:

          • Operation GhostShell - Novel RAT Targets Global Aerospace and Telecoms Firms

          Learn more about your ad choices. Visit megaphone.fm/adchoices

          19 min

        About Research Saturday

        From the publisher's feed

        Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

        More shows like Research Saturday

        Risky Business by Risky Business Media

        Risky Business

        375 Listeners

        CyberWire Daily by N2K Networks

        CyberWire Daily

        1,028 Listeners

        ChinaPower by CSIS | Center for Strategic and International Studies

        ChinaPower

        206 Listeners

        Smashing Security by Graham Cluley

        Smashing Security

        317 Listeners

        Click Here by Recorded Future News

        Click Here

        420 Listeners

        Darknet Diaries by Jack Rhysider

        Darknet Diaries

        8,058 Listeners

        Cybersecurity Today by David Shipley

        Cybersecurity Today

        179 Listeners

        Hacking Humans by N2K Networks

        Hacking Humans

        314 Listeners

        CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

        CISO Series Podcast

        191 Listeners

        Career Notes by N2K Networks

        Career Notes

        14 Listeners

        Pekingology by Center for Strategic and International Studies

        Pekingology

        141 Listeners

        Cybersecurity Headlines by CISO Series

        Cybersecurity Headlines

        138 Listeners

        The AI Fix by Mark Stockley

        The AI Fix

        32 Listeners

        The FAIK Files by Perry Carpenter | N2K Networks

        The FAIK Files

        18 Listeners