Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • Scam papers served.

    ⁠⁠Thomas Elkins⁠⁠, SOC L3 Analyst from ⁠⁠BlueVoyant⁠⁠, is discussing "Unpacking Augmented Marauder’s Multi-Pronged Casbaneiro Campaigns." BlueVoyant researchers uncovered a large-scale phishing campaign by a Brazil-linked threat group targeting Spanish-speaking users across Latin America and Europe, using fake judicial summons emails, WhatsApp attacks, ClickFix tactics, and email phishing to spread the Casbaneiro banking trojan through the Horabot malware framework.

    The campaign uses sophisticated evasion methods including password-protected PDFs, dynamically generated ZIP filenames, anti-sandbox checks, fileless execution, and customized phishing lures to bypass security tools while turning infected systems into self-propagating botnets that hijack Outlook and webmail accounts to spread further attacks. Researchers say the operation highlights how the Augmented Marauder group (also known as Water Saci) is rapidly evolving its malware ecosystem, combining WhatsApp automation, dynamic phishing infrastructure, and advanced banking malware delivery into a highly adaptable, multi-pronged cybercrime operation.

    The research and executive brief can be found here:

    • ⁠Unpacking Augmented Marauder’s Multi-Pronged Casbaneiro Campaigns⁠

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      27 min
    • The spy who logged me in.

      Mark Kelly, Staff Threat Researcher at Proofpoint, is discussing their work on "I’d come running back to EU again: TA416 resumes European government espionage campaigns." China-linked threat group TA416 has resumed large-scale phishing and malware campaigns targeting European governments, diplomatic missions tied to the EU and NATO, and more recently Middle Eastern entities following the outbreak of conflict in Iran.

      The group has continually evolved its tactics between mid-2025 and early 2026, using techniques like fake Cloudflare verification pages, Microsoft OAuth redirect abuse, and malicious C# project files to deliver customized PlugX malware through spearphishing campaigns. Researchers say the renewed activity reflects shifting geopolitical priorities tied to EU-China tensions, the Russia-Ukraine war, and instability in the Middle East, while highlighting TA416’s ongoing focus on intelligence gathering against diplomatic networks.

      The research and executive brief can be found here:

      • I’d come running back to EU again: TA416 resumes European government espionage campaigns

        Learn more about your ad choices. Visit megaphone.fm/adchoices

        25 min
      • Double-edged threat.

        Today we are joined by Justin Albrecht, Principal Researcher at Lookout, discussing "Attackers Wielding DarkSword Threaten iOS Users." DarkSword is a highly sophisticated iOS exploit chain discovered by Lookout that targets iPhones (iOS 18.4–18.6.2), enabling near zero-click compromise and rapid theft of sensitive data, including credentials and cryptocurrency wallet information.

        Likely deployed by a Russia-linked threat actor (UNC6353) against Ukrainian users, it uses watering hole attacks on compromised websites and operates in a “hit-and-run” fashion—exfiltrating data within minutes before wiping traces. The campaign highlights a growing secondary market for advanced exploits, allowing financially motivated groups to access powerful tools once reserved for state actors, significantly expanding the mobile threat landscape.

        The research and executive brief can be found here:

        • ⁠Attackers Wielding DarkSword Threaten iOS Users

          Learn more about your ad choices. Visit megaphone.fm/adchoices

          31 min
        • A QRazy clever scam.

          This week, we are joined by Juliana Testa, Senior Security Engineer from 7AI, sharing their work on "Quish Splash - When the QR Code Is the Weapon: A Multi-Wave Phishing Campaign That Slipped Past Every Filter." A large-scale “quishing” campaign used QR codes embedded in image attachments to hide phishing URLs, allowing 28 out of 33 emails to bypass SPF, DKIM, DMARC, and Microsoft Defender and land directly in inboxes.

          Each recipient received a unique QR code and tracking ID, defeating traditional detection methods and enabling attackers to scale the campaign to over 1.6 million emails across multiple organizations while shifting execution to less-secure mobile devices. The attack was ultimately uncovered through AI-driven alerting combined with human analysis and threat hunting, highlighting a major blind spot in email security and the need for QR code inspection, mobile protections, and tighter auto-reply controls.

          The research and executive brief can be found here:

          • Quish Splash - When the QR Code Is the Weapon: A Multi-Wave Phishing Campaign That Slipped Past Every Filter.
          • Learn more about your ad choices. Visit megaphone.fm/adchoices

            19 min
          • A new breed of RAT.

            Today we are joined by Dr. Darren Williams, Founder and CEO of BlackFog, to discuss his team's work on "Steaelite RAT Enables Double Extortion Attacks from a Single Panel." A new remote access trojan, Steaelite, is being marketed on underground forums as an all-in-one platform that combines remote access, credential theft, surveillance, and ransomware deployment through a single browser-based dashboard.

            Unlike traditional cybercrime toolchains, it merges data exfiltration and ransomware capabilities into one interface, with automated credential harvesting beginning as soon as a victim is infected. The tool signals a growing shift toward streamlined “double extortion” attacks, where data theft and encryption happen within the same system—raising the stakes for defenders to stop threats before data is exfiltrated.

            The research and executive brief can be found here:

            • Steaelite RAT Enables Double Extortion Attacks from a Single Panel
            • Learn more about your ad choices. Visit megaphone.fm/adchoices

              22 min
            • A wolf in admin clothing.

              Today we are joined by Selena Larson, Threat Researcher from Proofpoint research team and co-host of Only Malware in the Building, talking about their work on "(Don't) TrustConnect: It's a RAT in an RMM hat." Proofpoint uncovered TrustConnect, a malware-as-a-service platform posing as a legitimate remote monitoring and management (RMM) tool, but actually functioning as a remote access trojan (RAT) sold to cybercriminals for $300/month.

              The operation used a fake business website, legitimate-looking certificates, and branded installers (like fake Microsoft Teams or Zoom apps) to trick victims, while providing attackers with full remote control, file transfer, and surveillance capabilities. Although parts of its infrastructure were disrupted, the threat actor quickly rebounded with new variants, highlighting both the resilience of the operation and its deep ties to the broader cybercriminal ecosystem abusing RMM tools.

              The research and executive brief can be found here:

              • (Don't) TrustConnect: It's a RAT in an RMM hat
              • Learn more about your ad choices. Visit megaphone.fm/adchoices

                25 min
              • Startup surge sparks spy interest.

                This week, we are joined by Santiago Pontiroli, Threat Intelligence Research Lead from Acronis TRU team, discussing their work on "New year, new sector: Transparent Tribe targets India’s startup ecosystem." The Acronis Threat Research Unit uncovered a new campaign by Transparent Tribe showing the group has expanded beyond traditional government and defense targets to India’s startup ecosystem, especially cybersecurity and OSINT-focused firms.

                The attackers use startup-themed lures delivered via ISO files and malicious shortcuts to deploy Crimson RAT, a highly obfuscated tool capable of surveillance, data theft, and system control. Despite this shift, the campaign closely mirrors the group’s long-standing espionage tactics, suggesting startups are being targeted for their connections to government, law enforcement, and sensitive intelligence networks.

                The research and executive brief can be found here:

                • New year, new sector: Transparent Tribe targets India’s startup ecosystem
                • Learn more about your ad choices. Visit megaphone.fm/adchoices

                  20 min
                • When “safe” documents aren’t.

                  Omer Ninburg, CTO of Novee Security, joins us on this episode of Research Saturday to discuss their work on "From PDF to Pwn: Scalable 0day Discovery in PDF Engines and Services Using Multi-Agent LLMs." Historically, Portable Document Formats – the immutable, localized PDF – was once considered a “safe” component inside enterprise environments. That is no longer the case.

                  To demonstrate how PDF services and engines can be exploited, the team at Novee used their proprietary, multi-agent LLM system to uncover vulnerability patterns, and systematically scale them into a broad discovery campaign across two PDF vendor ecosystems.

                  The research uncovered 16 verified vulnerabilities across client-side PDF viewers, embedded plugins, and server-side PDF services.


                  The research and executive brief can be found here:

                  • ⁠From PDF to Pwn: Scalable 0day Discovery in PDF Engines and Services Using Multi-Agent LLMs
                  • Hacker-Trained AI Discovers 16 New 0-Day Vulnerabilities in PDF Engines
                  • Learn more about your ad choices. Visit megaphone.fm/adchoices

                    22 min
                  • A subtle flaw, a massive blast radius.

                    Yuval Avrahami from Wiz joins to share their work on "CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild." Wiz Research uncovered “CodeBreach,” a critical supply chain vulnerability caused by a subtle misconfiguration in AWS CodeBuild pipelines that allowed attackers to take over key GitHub repositories, including the widely used AWS JavaScript SDK that powers the AWS Console.

                    By exploiting an unanchored regex filter, unauthenticated attackers could trigger privileged builds, steal credentials, and potentially inject malicious code into software used across a majority of cloud environments. AWS has since remediated the issue and introduced stronger safeguards, but the incident highlights a growing trend of attackers targeting CI/CD pipelines where small misconfigurations can lead to massive downstream impact.

                    The research can be found here:

                    • CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild
                    • Learn more about your ad choices. Visit megaphone.fm/adchoices

                      18 min
                    • Your AI sidekick might be a spy.

                      This week, we are joined by Or Eshed, Co-Founder and CEO from LayerX Security, discussing their work on "How We Discovered A Campaign of 16 Malicious Extensions Built to Steal ChatGPT Accounts." Researchers uncovered a coordinated campaign of 16 malicious browser extensions posing as ChatGPT productivity tools while secretly stealing user accounts.

                      The extensions intercept ChatGPT session authentication tokens and send them to attacker-controlled servers, allowing threat actors to impersonate users and access their conversations, files, and connected services like Google Drive or Slack. The findings highlight how AI-focused browser extensions are creating a new attack surface, emphasizing the need for organizations to closely monitor and restrict third-party AI tools.

                      The research can be found here:

                      • ⁠⁠⁠How We Discovered A Campaign of 16 Malicious Extensions Built to Steal ChatGPT Accounts

                        Learn more about your ad choices. Visit megaphone.fm/adchoices

                        23 min

                      About Research Saturday

                      From the publisher's feed

                      Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

                      More shows like Research Saturday

                      Risky Business by Risky Business Media

                      Risky Business

                      374 Listeners

                      CyberWire Daily by N2K Networks

                      CyberWire Daily

                      1,027 Listeners

                      ChinaPower by CSIS | Center for Strategic and International Studies

                      ChinaPower

                      206 Listeners

                      Smashing Security by Graham Cluley

                      Smashing Security

                      317 Listeners

                      Click Here by Recorded Future News

                      Click Here

                      420 Listeners

                      Darknet Diaries by Jack Rhysider

                      Darknet Diaries

                      8,055 Listeners

                      Cybersecurity Today by David Shipley

                      Cybersecurity Today

                      179 Listeners

                      Hacking Humans by N2K Networks

                      Hacking Humans

                      314 Listeners

                      CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

                      CISO Series Podcast

                      191 Listeners

                      Career Notes by N2K Networks

                      Career Notes

                      14 Listeners

                      Pekingology by Center for Strategic and International Studies

                      Pekingology

                      140 Listeners

                      Cybersecurity Headlines by CISO Series

                      Cybersecurity Headlines

                      138 Listeners

                      The AI Fix by Mark Stockley

                      The AI Fix

                      32 Listeners

                      The FAIK Files by Perry Carpenter | N2K Networks

                      The FAIK Files

                      18 Listeners