Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • Ezuri: Regenerating a different kind of target.

    Guests Fernando Martinez and Tom Hegel from AT&T Alien Labs join Dave to discuss their team's research "Malware using new Ezuri memory loader." Multiple threat actors have recently started using a Go language (Golang) tool to act as a packer and avoid Antivirus detection. Additionally, the Ezuri memory loader tool acts as a malware loader and executes its payload in memory, without writing the file to disk. While this technique is known and commonly used by Windows malware, it is less popular in Linux environments.

    The research can be found here:

    • Malware using new Ezuri memory loader

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    20 min
  • How are we doing in the industrial sector?

    Guest Sergio Caltagirone from Dragos joins us to take us through their 2020 ICS Cybersecurity Year in Review report. Dragos's annual ICS Year in Review provides an overview and analysis of ICS vulnerabilities, global threat activity targeting industrial environments, and industry trends and observations gathered from customer engagements worldwide. The goal of the report is to give asset owners and operators proactive, actionable information and defensive recommendations in order to prepare for and combat the world’s most significant industrial cybersecurity adversaries.

    The report can be found here:

    • 2020 ICS CYBERSECURITY YEAR IN REVIEW

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    22 min
  • BendyBear: difficult to detect and downloader of malicious payloads.

    Guest Jen Miller-Osborn from Palo Alto Networks' Unit 42 joins us to discuss their research into BendyBear. Highly malleable, highly sophisticated and over 10,000 bytes of machine code. The code behavior and features strongly correlate with that of the WaterBear malware family, which has been active since as early as 2009. The malware is associated with the cyber espionage group BlackTech, which many in the broader threat research community have assessed to have ties to the Chinese government, and is believed to be responsible for recent attacks against several East Asian government organizations. Due to the similarities with WaterBear, and the polymorphic nature of the code, Unit 42 named this novel Chinese shellcode “BendyBear.” It stands in a class of its own in terms of being one of the most sophisticated, well-engineered and difficult-to-detect samples of shellcode employed by an Advanced Persistent Threat (APT).

    The research can be found here:

    • BendyBear: Novel Chinese Shellcode Linked With Cyber Espionage Group BlackTech

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    16 min
  • Keeping data confidential with fully homomorphic encryption.

    Guest Dr. Rosario Cammarota from Intel Labs joins us to discuss confidential computing. Confidential computing provides a secure platform for multiple parties to combine, analyze and learn from sensitive data without exposing their data or machine learning algorithms to the other party. This technique goes by several names — multiparty computing, federated learning and privacy-preserving analytics, among them. Confidential computing can enable this type of collaboration while preserving privacy and regulatory compliance.

    The research and supporting documents can be found here:

    • Intel Labs Day 2020: Confidential Computing
    • Confidential Computing Presentation Slides
    • Demo video
    • Learn more about your ad choices. Visit megaphone.fm/adchoices

      24 min
    • Diving deep into North Korea's APT37 tool kit.

      Guest Hossein Jazi of Malwarebytes joins us to take a deep dive into North Korea's APT37 (aka ScarCruft, Reaper and Group123) toolkit. On December 7 2020 the Malwarebytes Labs threat team identified a malicious document uploaded to Virus Total which was purporting to be a meeting request likely used to target the government of South Korea. The meeting date mentioned in the document was 23 Jan 2020, which aligns with the document compilation time of 27 Jan 2020, indicating that this attack took place almost a year ago.

      The file contains an embedded macro that uses a VBA self decoding technique to decode itself within the memory spaces of Microsoft Office without writing to the disk. It then embeds a variant of the RokRat into Notepad.

      Based on the injected payload, the Malwarebytes team believes that this sample is associated with APT37. This North Korean group is also known as ScarCruft, Reaper and Group123 and has been active since at least 2012, primarily targeting victims in South Korea.

      The research can be found here:

      • Retrohunting APT37: North Korean APT used VBA self decode technique to inject RokRat

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      19 min
    • Shining a light on China's cyber underground.

      Guest Maurits Lucas from Intel471 joins us to discuss his team's research into cybercrime in China. Data from Intel 471 show that the Chinese cybercrime underground proliferates through use of common methods or platforms, but behaves differently in large part due to the caution that actors take with regard to their identity. While the average citizen must follow the heavy handed nature of the government’s surveillance of cyberspace, Chinese threat actors take special precautions to protect their forums, TTPs and themselves. This leads to the Chinese cybercrime underground being disorderly when compared to others, particularly Russia, which tend to be much more organized.

      The research can be found here:

      • No pandas, just people: The current state of China’s cybercrime underground

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      24 min
    • Attackers (ab)using Google Chrome.

      Guest Bojan Zdrnja of Infigo IS and a certified instructor at SANS Institute shares an incident he discovered where attackers were using a pretty novel way of exfiltrating data and using that channel for C&C communication. The code that was acquired was only partially recovered, but enough to indicate powerful features that the attackers were (ab)using in Google Chrome. The basis for this attack were malicious extensions that the attacker dropped on the compromised system.

      The research can be found here:

      • Abusing Google Chrome extension syncing for data exfiltration and C&C

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      20 min
    • Using the human body as a wire-like communication channel.

      Guest Dr. Shreyas Sen, a Perdue University associate professor of electrical and computer engineering, joins us to discuss the following scenario:. Instead of inserting a card or scanning a smartphone to make a payment, what if you could simply touch the machine with your finger? A prototype developed by Purdue University engineers would essentially let your body act as the link between your card or smartphone and the reader or scanner, making it possible for you to transmit information just by touching a surface.

      The research can be found here:

      • Tech makes it possible to digitally communicate through human touch (press release)
      • BodyWire-HCI: Enabling New Interaction Modalities by Communicating Strictly During Touch Using Electro-Quasistatic Human Body Communication (research paper)

        Learn more about your ad choices. Visit megaphone.fm/adchoices

        20 min
      • "Follow the money" the cybersecurity way.

        Guest Joe Slowik joins us from Domain Tools to share their research "Current Events to Widespread Campaigns: Pivoting from Samples to Identify Activity" where they examined technical artifacts emerging around the 2020 conflict between Armenia and Azerbaijan in the Caucasus region. 

        Cyber Threat Intelligence (CTI) practitioners can gain insight into adversary operations by tracking conflicts or geopolitical tensions. Similar to a “follow the money” approach in criminal investigations, looking at conflict zones can reveal cyber capabilities deployed as part of events —either by the parties to the conflict itself, or third parties interested in monitoring events for their own purposes.

        Based on precedent, analysts can identify developments in adversary operations and technical capabilities by tracking identifiers related to major events and conflict zones. Identifying capabilities deployed to take advantage of such items can yield insights into fundamental attacker tradecraft and behaviors, and enable defense and response for incidents which may strike far closer to home at a later date.

        The research can be found here:

        • Current Events to Widespread Campaigns: Pivoting from Samples to Identify Activity

        Learn more about your ad choices. Visit megaphone.fm/adchoices

        28 min
      • The Kimsuky group from North Korea expands spyware, malware and infrastructure.

        Guest Yonatan Striem-Amit joins us from Cybereason to share their Nocturnus Team research into Kimsuky. The Cybereason Nocturnus Team has been tracking various North Korean threat actors, among them the cyber espionage group known as Kimsuky, (aka: Velvet Chollima, Black Banshee and Thallium), which has been active since at least 2012 and is believed to be operating on behalf of the North Korean regime. The group has a rich and notorious history of offensive cyber operations around the world, including operations targeting South Korean think tanks, but over the past few years they have expanded their targeting to countries including the United States, Russia and various nations in Europe.

        The research can be found here:

        • Back to the Future: Inside the Kimsuky KGH Spyware Suite

        Learn more about your ad choices. Visit megaphone.fm/adchoices

        18 min

      About Research Saturday

      From the publisher's feed

      Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

      More shows like Research Saturday

      Risky Business by Risky Business Media

      Risky Business

      375 Listeners

      CyberWire Daily by N2K Networks

      CyberWire Daily

      1,028 Listeners

      ChinaPower by CSIS | Center for Strategic and International Studies

      ChinaPower

      206 Listeners

      Smashing Security by Graham Cluley

      Smashing Security

      317 Listeners

      Click Here by Recorded Future News

      Click Here

      420 Listeners

      Darknet Diaries by Jack Rhysider

      Darknet Diaries

      8,058 Listeners

      Cybersecurity Today by David Shipley

      Cybersecurity Today

      179 Listeners

      Hacking Humans by N2K Networks

      Hacking Humans

      314 Listeners

      CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

      CISO Series Podcast

      191 Listeners

      Career Notes by N2K Networks

      Career Notes

      14 Listeners

      Pekingology by Center for Strategic and International Studies

      Pekingology

      141 Listeners

      Cybersecurity Headlines by CISO Series

      Cybersecurity Headlines

      138 Listeners

      The AI Fix by Mark Stockley

      The AI Fix

      32 Listeners

      The FAIK Files by Perry Carpenter | N2K Networks

      The FAIK Files

      18 Listeners