Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • Taking a look behind the Science of Security.

    Guest Adam Tagert is a Science of Security (SoS) Researcher in the National Security Agency Research Directorate. The National Security Agency (NSA) sponsors the Science of Security (SoS) Initiative for the promotion of a foundational cybersecurity science that is needed to mature the cybersecurity discipline and to underpin advances in cyberdefense. Adam works in all aspects of SoS particularly in the promotion of collaboration and use of foundational cybersecurity research. He promotes rigorous research methods by leading the Annual Best Scientific Cybersecurity Paper Competition. Adam joins Dave Bittner to discuss the NSA's SoS Initiative and their Science of Security and Privacy 2021 Annual Report.

    Information on the SoS Initiative and the report can be found here:

    • Science of Security
    • Science of Security and Privacy 2021 Annual Report
    • Learn more about your ad choices. Visit megaphone.fm/adchoices

      25 min
    • Bad building blocks: a new and unusual phishing campaign.

      Guest Karl Sigler of Trustwave's SpiderLabs joins Dave Bittner to talk about their research: "Hidden Phishing at Free JavaScript Site". The research describes an interesting phishing campaign SpiderLabs encountered recently. In this campaign, the email subject pertains to a price revision, followed by some numbers. There is no email body, but there is an attachment about an ”investment.” The attachment’s convoluted filename contains characters the file-naming convention doesn’t allow, notably the vertical stroke, “|.” Even though "xlsx" is in the filename, double-clicking the attachment will prompt the user to open it with the default web browser. Thus, the file indeed appears to be an HTML document. Of course, it’s malicious.

      The research can be found here:

      • HTML Lego: Hidden Phishing at Free JavaScript Site

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      20 min
    • EtterSilent: a popular, versatile maldoc builder.

      Guest Brandon Hoffman of Intel 471 joins Dave Bittner to share his team's research "EtterSilent: the underground’s new favorite maldoc builder". The cybercrime underground often mimics behaviors that we see in everyday facets of life. Intel 471’s latest discovery is an example of one of these patterns: when a product takes off in the marketplace, users will rush to obtain it and find unique ways to use it in order to fit their needs.

      The latest “product” is a malicious document builder, known in the underground as “EtterSilent,” that Intel 471 has seen leveraged by various cybercrime groups. As it has grown in popularity, it has constantly been updated in order to avoid detection. Used in conjunction with other forms of malware, it’s a prime example of how ease of use and a concentration of skill sets leads to a commoditization of the cybercrime economy.

      • EtterSilent: the underground’s new favorite maldoc builder

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      20 min
    • Leveraging COVID-19 themes for malicious purposes.

      Guest Joe Slowik joins us from DomainTools to discuss his team's research "COVID-19 Phishing With a Side of Cobalt Strike." Multiple adversaries, from criminal groups to state-directed entities, engaged in malicious cyber activity using COVID-19 pandemic themes since March 2020. Adversaries continue to leverage the pandemic, arguably the most significant issue globally as of this writing, in various ways. Yet the most persistent avenue remains using COVID-19 themes for building malicious document files. Examples include lures associated with Cloud Atlas-linked activity and broader targeting of health authorities.

      Given the continued significance of the pandemic and persistent use of pandemic themes by adversaries, DomainTools researchers continuously monitor for items leveraging COVID-19 content for malicious purposes. While conducting this research, DomainTools analysts identified an interesting malicious document with what appeared to be unique staging and execution mechanisms.

      Research can be found here:

      • COVID-19 Phishing With a Side of Cobalt Strike

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      25 min
    • Jack Voltaic: critical infrastructure resiliency project, not a person.

      Guest LTC Erica Mitchell from Army Cyber Institute joins us to talk about their infrastructure resiliency research project called Jack Voltaic. The Army Cyber Institute’s (ACI’s) Jack Voltaic (JV) project enables the institute to study incident response gaps alongside assembled partners to identify interdependencies among critical infrastructure and provide recommendations. JV provides an innovative, bottom‐up approach to critical infrastructure resilience in two unique ways. Whereas most federal efforts to improve resiliency focus on regional or multistate emergency response, JV focuses on cities and municipalities where critical infrastructure and populations are most heavily populated. Furthermore, JV deviates from other cybersecurity and national preparedness exercises in that it builds around areas of interest nominated by the participants. Although JV events include national-level capabilities and resources, they are conceptually driven by the concerns of the cities and their infrastructure partners. Through this approach, the ACI, the Army, and the Department of Defense (DoD) are able to harvest insights about potential roles, dependencies, partners, and support requests, while cities are able to discover potential capability gaps and expand their critical infrastructure information-sharing networks before a potential disaster strikes.

      Research links:

      • Jack Voltaic Cyber Research Project
      • Jack Voltaic 3.0 Cyber Research Report Executive Summary
      • Learn more about your ad choices. Visit megaphone.fm/adchoices

        29 min
      • SUPERNOVA activity and its possible connection to SPIRAL threat group.

        Guest Mike McLellan from Secureworks joins us to share his team's insights about SUPERNOVA and threat group attribution. Similarities between the SUPERNOVA activity and a previous compromise of the network suggest that SPIRAL was responsible for both intrusions and reveal information about the threat group.

        In late 2020, Secureworks® Counter Threat Unit™ (CTU) researchers observed a threat actor exploiting an internet-facing SolarWinds server to deploy the SUPERNOVA web shell. Additional analysis revealed similarities to intrusion activity identified on the same network earlier in 2020, suggesting the two intrusions are linked. CTU™ researchers attribute the intrusions to the SPIRAL threat group. Characteristics of the activity suggest the group is based in China.

        The research can be found here:

        • SUPERNOVA Web Shell Deployment Linked to SPIRAL Threat Group

        Learn more about your ad choices. Visit megaphone.fm/adchoices

        21 min
      • A snapshot of the ransomware threat landscape.

        Guest Jen Miller-Osborn from Palo Alto Networks' Unit 42 joins Dave to discuss their 2021 Unit 42 Ransomware Threat Report, which highlights a surge in ransomware demands based on a global analysis of the threat landscape in 2020. To evaluate the current state of the ransomware threat landscape, the Unit 42 threat intelligence team and the Crypsis incident response team collaborated to analyze the ransomware threat landscape in 2020, with global data from Unit 42 as well as US, Canada, and Europe data from Crypsis. The report details the top ransomware variants, average ransomware payments, ransomware predictions, and actionable next steps to immediately reduce ransomware risk.

        The report can be found here:

        • 2021 Unit 42 Ransomware Threat Report

        Learn more about your ad choices. Visit megaphone.fm/adchoices

        24 min
      • Bulletproof hosting (BPH) and how it powers cybercrime.

        Guest Jason Passwaters of Intel 471 joins us to discuss his team's research into bulletproof hosting (BPH). The research team at Intel 471 defined what a typical BPH service offers and how these services can be stopped in order to limit the damage they have on enterprises, businesses and digital society itself. They examined some popular malware families that actors host or leverage via BPH services. While much more goes into a cybercriminal’s full operation, it would be vastly more difficult to pull off without the ability to host malware and be free from impunity. Finally, they listed of some of the BPH providers that are firmly entrenched in the cybercrime underground and how they give support to other cybercriminal enterprises. By recognizing their behaviors, security teams can begin to take measures to figure out who the actors are, how they operate and what their infrastructure looks like. By doing so, organizations can begin to uncover ways to proactively counter maliciously-used infrastructure before criminals have a chance to launch their attacks. 

        The blog posts can be found here:

        • Hiding in plain sight: Bulletproof Hosting’s dueling forms
        • Bulletproof hosting: How cybercrime stays resilient
        • Here’s who is powering the bulletproof hosting market
        • Learn more about your ad choices. Visit megaphone.fm/adchoices

          18 min
        • Social engineering: MINEBRIDGE RAT embedded to look like job résumés.

          Guest Deepen Desai joins Dave to talk about Zsaler's research "Return of the MINEBRIDGE RAT With New TTPs and Social Engineering Lures." In Jan 2021, Zscaler ThreatLabZ discovered new instances of the MINEBRIDGE remote-access Trojan (RAT) embedded in macro-based Word document files crafted to look like valid job resumes (CVs). Such lures are often used as social engineering schemes by threat actors.

          MINEBRIDGE buries itself into the vulnerable remote desktop software TeamViewer, enabling the threat actor to take a wide array of remote follow-on actions such as spying on users or deploying additional malware.The use of social engineering tactics targeting security teams appears to be on an upward trend.

          The research can be found here:

          • Return of the MINEBRIDGE RAT With New TTPs and Social Engineering Lures

          Learn more about your ad choices. Visit megaphone.fm/adchoices

          18 min
        • Strategic titles point to something more than a commodity campaign.

          Guests Gage Mele, Winston Marydasan, and Yury Polozov from Anomali join Dave to discuss their research into Static Kitten targeting government agencies in the UAE and Kuwait. Anomali Threat Research uncovered malicious activity very likely attributed to the Iran-nexus cyberespionage group, Static Kitten (Seedworm, MERCURY, Temp.Zagros, POWERSTATS, NTSTATS, MuddyWater), which is known to target numerous sectors primarily located in the Middle East This new campaign, which uses tactics, techniques, and procedures (TTPs) consistent with previous Static Kitten activity, uses ScreenConnect launch parameters designed to target any MOFA with mfa[.]gov as part of the custom field. Anomali's team found samples specifically masquerading as the Kuwaiti government and the UAE National Council respectively, based on references in the malicious samples.

          The research can be found here:

          • Probable Iranian Cyber Actors, Static Kitten, Conducting Cyberespionage Campaign Targeting UAE and Kuwait Government Agencies

          Learn more about your ad choices. Visit megaphone.fm/adchoices

          23 min

        About Research Saturday

        From the publisher's feed

        Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

        More shows like Research Saturday

        Risky Business by Risky Business Media

        Risky Business

        375 Listeners

        CyberWire Daily by N2K Networks

        CyberWire Daily

        1,028 Listeners

        ChinaPower by CSIS | Center for Strategic and International Studies

        ChinaPower

        206 Listeners

        Smashing Security by Graham Cluley

        Smashing Security

        317 Listeners

        Click Here by Recorded Future News

        Click Here

        420 Listeners

        Darknet Diaries by Jack Rhysider

        Darknet Diaries

        8,058 Listeners

        Cybersecurity Today by David Shipley

        Cybersecurity Today

        179 Listeners

        Hacking Humans by N2K Networks

        Hacking Humans

        314 Listeners

        CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

        CISO Series Podcast

        191 Listeners

        Career Notes by N2K Networks

        Career Notes

        14 Listeners

        Pekingology by Center for Strategic and International Studies

        Pekingology

        141 Listeners

        Cybersecurity Headlines by CISO Series

        Cybersecurity Headlines

        138 Listeners

        The AI Fix by Mark Stockley

        The AI Fix

        32 Listeners

        The FAIK Files by Perry Carpenter | N2K Networks

        The FAIK Files

        18 Listeners