Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • Exploring vulnerabilities of off-the-shelf software.

    Guest Tomislav Peričin, Reversing Labs' Chief Software Architect and Co-Founder, joins Dave to discuss his team's research that addresses the importance of validating third-party software components as a way to manage the risks that they can introduce. Developing software solutions is a complex task requiring a lot of time and resources. In order to accelerate time to market and reduce the cost, software developers create smaller pieces of functional code which can be reused across many projects. The concept of code reuse is one of the cornerstones of modern software engineering and it is universally accepted that everybody should strive towards it. However, in addition to the positives, organizations need to be aware of the security risks introduced by such third-party components.

    The growing number of cyber incidents that target the software supply chain are focused on high-value target compromises. With the latest surge and public uproar, the US President Biden has issued the Executive Order on Improving the Nation’s Cybersecurity in order to create an institutional framework addressing these kinds of security risks.

    The research can be found here:

    • Third-party code comes with some baggage

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    17 min
  • You can add new features, just secure the old stuff first.

    Guests Will Schroeder and Lee Christensen from SpecterOps join Dave to share the research they recently presented at Black Hat USA on the security of Microsoft's Active Directory Certificate Services.

    Their abstract:

    Microsoft’s Active Directory Public Key Infrastructure (PKI) implementation, known as Active Directory Certificate Services (AD CS), has largely flown under the radar of both the offensive and defensive communities. AD CS is widely deployed, and provides attackers opportunities for credential theft, machine persistence, domain escalation, and subtle domain persistence. We present relevant background on certificates in Active Directory, detail the abuse of AD CS through certificate theft and active malicious enrollments for user and machine persistence, discuss a set of common misconfigurations that can result in domain escalation, and explain a method for stealing a Certificate Authority’s private key in order to forge new user/machine “golden” certificates. By bringing light to the security implications of AD CS, we hope to raise awareness for both attackers and defenders alike of the security issues surrounding this complex, widely deployed, and often misunderstood system.

    The blog post and white paper can be found here:

    • Certified Pre-Owned blog post
    • Certified Pre-Owned white paper
    • Learn more about your ad choices. Visit megaphone.fm/adchoices

      31 min
    • SideCopy malware campaigns expand and evolve.

      Guest Asheer Malhotra, Threat Researcher of Cisco Talos Intelligence Group, joins Dave to discuss his team's research "InSideCopy: How this APT continues to evolve its arsenal." Cisco Talos has observed an expansion in the activity of SideCopy malware campaigns, targeting entities in India. In the past, the attackers have used malicious LNK files and documents to distribute their staple C#-based RAT. We are calling this malware "CetaRAT." SideCopy also relies heavily on the use of Allakore RAT, a publicly available Delphi-based RAT.

      Recent activity from the group, however, signals a boost in their development operations. Talos has discovered multiple new RAT families and plugins currently used in SideCopy infection chains.

      Targeting tactics and themes observed in SideCopy campaigns indicate a high degree of similarity to the Transparent Tribe APT (aka APT36) also targeting India. These include using decoys posing as operational documents belonging to the military and think tanks and honeytrap-based infections.

      The research can be found here:

      • InSideCopy: How this APT continues to evolve its arsenal blog post
      • InSideCopy: How this APT continues to evolve its arsenal report
      • Learn more about your ad choices. Visit megaphone.fm/adchoices

        21 min
      • China's influence grows through Digital Silk Road Initiative.

        Guest Charity Wright, Cyber Threat Intelligence Expert in Recorded Future's Insikt Group, joins Dave to discuss her research "China’s Digital Colonialism: Espionage and Repression Along the Digital Silk Road". Through the Digital Silk Road Initiative (DSR), announced in 2015, the People’s Republic of China (PRC) is building an expansive global data infrastructure and exporting surveillance technologies to dictators and illiberal regimes throughout the developing world, in some cases trading technology for access to sensitive user data and facial recognition intelligence. Domestically, China uses this type of technology to assert authority over its citizens, censor the media, quell protests, and systematically oppress religious minorities. Now, over 80 countries are enabled to do the same with Chinese surveillance technology.

        The research can be found here:

        • China’s Digital Colonialism: Espionage and Repression Along the Digital Silk Road

        Learn more about your ad choices. Visit megaphone.fm/adchoices

        20 min
      • Free malware with cracked software.

        Guest Christopher Budd, Senior Global Threat Communications Manager at Avast, joins Dave to talk about some research his team did when they looked into a Reddit report saying their Avast folder was empty and other reports like it. The team found a new malware they’re calling “Crackonosh” in part because of some possible indications that the malware author may be Czech. Crackonosh is distributed along with illegal, cracked copies of popular software and searches for and disables many popular antivirus programs as part of its anti-detection and anti-forensics tactics.

        The research can be found here:

        • Crackonosh: A New Malware Distributed in Cracked Software

        Learn more about your ad choices. Visit megaphone.fm/adchoices

        17 min
      • Enabling connectivity enables exposures.

        Guest Nathan Howe, Vice President of Emerging Technology at Zscaler, joins Dave to discuss his team's work, "2021 “Exposed” Report Reveals Corporate and Cloud Infrastructures More at Risk Than Ever From Expanded Attack Surfaces." The modern workforce has resulted in an increase of users, devices, and applications existing outside of controlled networks, including corporate networks, the business emphasis on the “network” has decreased and the reliance on the internet as the connective tissue for businesses has increased.

        Zscaler analyzes the attack surface of 1,500 organizations and identifies trends affecting businesses of all sizes and industries, across all geographies. Key findings include:

        • The attack surface impact based on company size
        • The countries with the greatest attack surface
        • The industries that are most exposed

        • The research can be found here:

          • “Exposed”: The world’s first report to reveal how exposed corporate networks really are.

          Learn more about your ad choices. Visit megaphone.fm/adchoices

          21 min
        • Dealing illicit goods on encrypted chat apps.

          Guest Daniel Kats, Senior Principal Research Engineer at NortonLifeLock, joins Dave to discuss his team's work, "Encrypted Chat Apps Doubling as Illegal Marketplaces." Encrypted chat apps are gaining popularity worldwide due to their central premise of not sending user data to tech giants. Some popular examples include WhatsApp, Telegram and Signal. These apps have also been adopted by businesses to securely communicate directly to their users. Additionally, these apps have been instrumental to subverting authoritarian regimes.

          However, NortonLifeLock found that encrypted chat apps are also being used by criminals to sell illegal goods. Because content moderation is, by design, nearly impossible on these apps, they allow for an easy vector for dealers of illicit goods to communicate directly to customers without fear of law enforcement involvement.

          The research can be found here:

          • Encrypted Chat Apps Doubling as Illegal Marketplaces

          Learn more about your ad choices. Visit megaphone.fm/adchoices

          21 min
        • Malware in pirated Windows installation files.

          Guest Tom Roter from Minera Labs joins Dave to discuss his team research: "Rigging a Windows Installation." It is common knowledge that pirated software might contain malware, yet millions still put themselves and their devices at risk and download from dubious sources. It is even more surprising to see the popularity of torrented operating system installations, which are ranked at the top of most torrent tracker ranking lists. Today we will prove conventional wisdom right and show off a devious, yet clever attack chain employed by an infected Windows 10 image, frequently shared and downloaded by tens of thousands of users.

          Over the last year, numerous malicious PowerShell events popped up in our telemetry. The events caught our attention because a payload was being downloaded into the “C:\Windows” directory, which is usually well guarded under NTFS permissions, this implies that the attacker had very high privilege on the compromised system. 

          The research can be found here:

          • Rigging a Windows installation

          Learn more about your ad choices. Visit megaphone.fm/adchoices

          15 min
        • Exhibiting advanced APT-like behavior.

          Guest Yonatan Striem-Amit joins Dave to talk about Cybereason's research "Prometei Botnet Exploiting Microsoft Exchange Vulnerabilities." The Cybereason Nocturnus Team responded to several incident response (IR) cases involving infections of the Prometei Botnet against companies in North America, observing that the attackers exploited recently published Microsoft Exchange vulnerabilities (CVE-2021-27065 and CVE-2021-26858) in order to penetrate the network and install malware. Yonatan shares his team's findings of the investigation of the attacks, including the initial foothold sequence of the attackers, the functionality of the different components of the malware, the threat actors’ origin and the bot’s infrastructure.

          The research can be found here:

          • Prometei Botnet Exploiting Microsoft Exchange Vulnerabilities

          Learn more about your ad choices. Visit megaphone.fm/adchoices

          22 min
        • Primitive Bear spearphishes for Ukrainian entities.

          Guests Gage Mele and Yury Polozov join Dave to talk about Anomali's research "Primitive Bear (Gamaredon) Targets Ukraine with Timely Themes." Anomali Threat Research identified malicious samples that align with the Russia-sponsored cyberespionage group Primitive Bear’s (Gamaredon, Winterflounder) tactics, techniques, and procedures (TTPs). Primitive Bear, known primarily to focus on Ukraine, has been very active in 2021. However, the themes of the samples Anomali found, as well as those shared by the security community, could also be used to target multiple former Union of Soviet Socialist Republic (USSR) countries. Anomali Threat Research found malicious .docx files being distributed by Primitive Bear, likely through spearphishing, that attempted to download remote template .dot files through template injection.

          The research can be found here:

          • Primitive Bear (Gamaredon) Targets Ukraine with Timely Themes

          Learn more about your ad choices. Visit megaphone.fm/adchoices

          15 min

        About Research Saturday

        From the publisher's feed

        Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

        More shows like Research Saturday

        Risky Business by Risky Business Media

        Risky Business

        375 Listeners

        CyberWire Daily by N2K Networks

        CyberWire Daily

        1,028 Listeners

        ChinaPower by CSIS | Center for Strategic and International Studies

        ChinaPower

        206 Listeners

        Smashing Security by Graham Cluley

        Smashing Security

        317 Listeners

        Click Here by Recorded Future News

        Click Here

        420 Listeners

        Darknet Diaries by Jack Rhysider

        Darknet Diaries

        8,058 Listeners

        Cybersecurity Today by David Shipley

        Cybersecurity Today

        179 Listeners

        Hacking Humans by N2K Networks

        Hacking Humans

        314 Listeners

        CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

        CISO Series Podcast

        191 Listeners

        Career Notes by N2K Networks

        Career Notes

        14 Listeners

        Pekingology by Center for Strategic and International Studies

        Pekingology

        141 Listeners

        Cybersecurity Headlines by CISO Series

        Cybersecurity Headlines

        138 Listeners

        The AI Fix by Mark Stockley

        The AI Fix

        32 Listeners

        The FAIK Files by Perry Carpenter | N2K Networks

        The FAIK Files

        18 Listeners