Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • Trickbot may be down, but can we count it out?

    Guest Mark Arena from Intel471 joins us to discuss his team's research into Trickbot and its evolution from a banking trojan to a long-standing, most likely well-resourced operation that was taken down last year. Mark shares some insight into Trickbot's order of operations and what went on behind the scenes that his team working with Brian Krebs were able to discover.

    Since the separate and independent actions taken against Trickbot, Intel471 has observed successful disruption of its command and control infrastructure. However, the actors linked to Trickbot have not ceased their criminal activities. These actors have continued engaging in ransomware activity, using BazarLoader instead of Trickbot. Intel471 is unable to assess the long-term impact of the Trickbot disruption activity or whether Trickbot will continue to be used by cybercrime groups. This analysis covers the period from Sept. 22, 2020 until Nov. 6, 2020.

    The research can be found here:

    • Trickbot down, but is it out?

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    20 min
  • Manufacturing sector is increasingly a target for adversaries.

    Guest Selena Larson, senior cyber threat analyst at Dragos, Inc., joins us to discuss their research into recent observations of ICS-targeting threats to manufacturing organizations. 

    Cyber risk to the manufacturing sector is increasing, led by disruptive cyberattacks impacting industrial processes, intrusions enabling information gathering and process information theft, and new activity from Industrial Control Systems (ICS)-targeting adversaries. Dragos currently publicly tracks five ICS-focused activity groups targeting manufacturing: CHRYSENE, PARISITE, MAGNALLIUM, WASSONITE, and XENOTIME in addition to various ransomware activities capable of disrupting operations. 

    Manufacturing relies on ICS to scale, function, and ensure consistent quality control and product safety. It provides crucial materials, products, and medicine and is classified as critical infrastructure. Due to the interconnected nature of facilities and operations, an attack on a manufacturing entity can have ripple effects across the supply chain that relies on timely and precise production to support product fulfillment, health and safety, and national security objectives. 

    Ransomware adversaries are adopting ICS-aware functionality with the ability to stop industrial related processes and cause disruptive – and potentially destructive – impacts. Dragos has not observed ICS-specific malware targeting manufacturing operations on the same scale or sophistication as that used in the disruptive TRISIS and CRASHOVERRIDE malware attacks that targeted energy operations in Saudi Arabia and Ukraine, respectively. However, known and ongoing threats to manufacturing can have direct and indirect impact to operations. This report provides a snapshot of the threat landscape as of October 2020 and is expected to change in the future as adversaries and their behaviors evolve. 

    The research can be found here:

    • ICS Threat Activity on the Rise in Manufacturing Sector

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    25 min
  • Emotet reemerges and becomes one of most prolific threat groups out there.

    Deep Instinct's Shimon Oren joins us to talk about his team's research on "Why Emotet's latest wave is harder to catch than ever before - Part 2." Emotet appears to have reemerged more evasive than before, this time with a payload delivered from a loader that security tools aren’t equipped to handle.

    Emotet, the largest malware botnet today, started in 2014 and continues to be one of the most challenging threats in today’s landscape. This botnet causes huge damage by spreading ransomware and info stealers to its infected systems. Recently, a rise in the number of Emotet infections was observed in France, Japan, and New Zealand. The high number of infections shows the effectiveness of the Emotet malware at staying undetected.

    Shimon joins us to discuss how Deep Instinct investigated the payload that was encrypted inside the loader, analyzes the next steps in the infection process, and discovers the techniques used to make this malware difficult to analyze.

    The original blog post and updated post on the research can be found here:

    • Emotet Analysis: Why Emotet’s Latest Wave is Harder to Catch than Ever Before
    • Why Emotet's latest wave is harder to catch than ever before - Part 2
    • Learn more about your ad choices. Visit megaphone.fm/adchoices

      25 min
    • Encore: Unpacking the Malvertising Ecosystem. [Research Saturday]

      Researchers at Cisco's Talos Unit recently published research exploring the tactics, technics and procedures of the global malvertising ecosystem. Craig Williams is head of Talos Outreach at Cisco, and he guides us through the life cycle of malicious online ads, along with tips for protecting yourself and your organization.

      The research can be found here: 

      https://blog.talosintelligence.com/2019/07/malvertising-deepdive.html

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      28 min
    • Encore: Seedworm digs Middle East intelligence. [Research Saturday]

      Researchers at Symantec have been tracking Seedworm, a cyber espionage group targeting the Middle East as well as Europe and North America. The threat group targets government agencies, oil & gas facilities, NGOs, telecoms and IT firms.

      Al Cooley is director of product management at Symantec, and he joins us to share their findings.

      The original research can be found here:

      https://www.symantec.com/blogs/threat-intelligence/seedworm-espionage-group

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      19 min
    • Advertising Software Development Kit (SDK): serving up more than just in-app ads and logging sensitive data.

      On August 24, 2020, Snyk announced the discovery of suspicious behaviors in the iOS version of a popular advertising SDK known as Mintegral. At that time, they had confirmed with partners in the advertising attribution space that at minimum, Mintegral appeared to be using this functionality to gather large amounts of data and commit ad attribution fraud. Their research showed that Mintegral was using code obfuscation and method swizzling to modify the functionality of base iOS SDK methods without the application owner’s knowledge. Further, their research proved that Mintegral was logging all HTTP requests including its headers which could even contain authorization tokens or other sensitive data.

      Since that time Mintegral announced that they were opening the source of their SDK to the market. While the SDK can only be downloaded by registered partners, a major game publisher shared the source code with Snyk for further analysis. They also continued their research by digging deeper into the Android versions of the SDK in which they hadn’t found similar behaviors at the time of the initial disclosure. 

      This has resulted in some significant discoveries that necessitate an update to the previous disclosure. Additionally, Mintegral and the community at large have responded to the situation, and Snyk felt a summary of the events was a good way to finalize their research into this SDK.

      Joining us on Research Saturday to discuss their research is Snyk's Alyssa Miller.

      The original blog and Snyk's update can be found here:

      • SourMint: malicious code, ad fraud, and data leak in iOS
      • SourMint: iOS remote code execution, Android findings, and community response
      • Learn more about your ad choices. Visit megaphone.fm/adchoices

        26 min
      • Following DOJ indictment, a look back on NotPetya and Olympic Destroyer research.

        From US Department of Justice: "On Oct. 15, 2020, a federal grand jury in Pittsburgh returned an indictment charging six computer hackers, all of whom were residents and nationals of the Russian Federation (Russia) and officers in Unit 74455 of the Russian Main Intelligence Directorate (GRU), a military intelligence agency of the General Staff of the Armed Forces. 

        These GRU hackers and their co-conspirators engaged in computer intrusions and attacks intended to support Russian government efforts to undermine, retaliate against, or otherwise destabilize: (1) Ukraine; (2) Georgia; (3) elections in France; (4) efforts to hold Russia accountable for its use of a weapons-grade nerve agent, Novichok, on foreign soil; and (5) the 2018 PyeongChang Winter Olympic Games after Russian athletes were banned from participating under their nation’s flag, as a consequence of Russian government-sponsored doping effort. 

        Their computer attacks used some of the world’s most destructive malware to date, including: KillDisk and Industroyer, which each caused blackouts in Ukraine; NotPetya, which caused nearly $1 billion in losses to the three victims identified in the indictment alone; and Olympic Destroyer, which disrupted thousands of computers used to support the 2018 PyeongChang Winter Olympics. The indictment charges the defendants with conspiracy, computer hacking, wire fraud, aggravated identity theft, and false registration of a domain name."

        Returning to Research Saturday this week to discuss their research of NotPetya and Olympic Destroyer are Cisco Talos' Craig Williams and Matt Olney.

        The indictment and Cisco's research can be found here:

        • Six Russian GRU Officers Charged in Connection with Worldwide Deployment of Destructive Malware and Other Disruptive Actions in Cyberspace
        • New Ransomware Variant "Nyetya" Compromises Systems Worldwide
        • The MeDoc Connection
        • Who Wasn’t Responsible for Olympic Destroyer?
        • Olympic Destroyer Takes Aim At Winter Olympics
        • Learn more about your ad choices. Visit megaphone.fm/adchoices

          33 min
        • SSL-based threats remain prevalent and are becoming increasingly sophisticated.

          While SSL/TLS encryption is the industry standard for protecting data in transit from prying eyes, encryption has, itself, become a threat. It is often leveraged by attackers to sneak malware past security tools that do not fully inspect encrypted traffic. As the percentage of traffic that is encrypted continues to grow, so do the opportunities for attackers to deliver threats through encrypted channels.

          To better understand the use of encryption and the volume of encrypted traffic that is inspected, Zscaler's research team, ThreatLabZ, analyzed encrypted traffic across the Zscaler cloud for the first nine months of 2020, assessing its use within specific industries. The study also set out to analyze the types of attacks that use encryption and the extent of the current risk. 

          Returning to Research Saturday this week to discuss the report is Zscaler's CISO and VP of Security Research, Deepen Desai.

          The research can be found here:

          • 2020: The State of Encrypted Attacks Blog
          • 2020: The State of Encrypted Attacks Report

            Learn more about your ad choices. Visit megaphone.fm/adchoices

            16 min
          • Encore: Using global events as lures for malicious activity.

            The goal of malicious activity is to compromise the system to install some unauthorized software. Increasingly that goal is tied to one thing: the user. Over the past several years, we as an industry improved exploit mitigation and the value of working exploits has increased accordingly. Together, these changes have had an impact on the threat landscape. We still see large amounts of active exploitation, but enterprises are getting better at defending against them.

            This has left adversaries with a couple of options, develop or buy a working exploit that will defeat today's protections, which can be costly, or pivot to enticing a user to help you. In today's threat landscape, adversaries are always trying to develop and implement the most effective lures to try and draw users into their infection path. They've tried a multitude of different tactics in this space, but one always stands out — current events.

            Joining us on this week's Research Saturday from Craig Williams from Cisco's Talos Outreach team to walk us through how current events are used as lures.

            The research and blog post can be found here: 

            • Adversarial use of current events as lures

            Learn more about your ad choices. Visit megaphone.fm/adchoices

            21 min
          • Misconfigured identity and access management (IAM) is much more widespread.

            Identity and access are intrinsically connected when providing security to cloud platforms. But security is only effective when environments are properly configured and maintained. In the 2H 2020 edition of the biannual Unit 42 Cloud Threat Report, researchers conducted Red Team exercises, scanned public cloud data and pulled proprietary Palo Alto Networks data to explore the threat landscape of identity and access management (IAM) and identify where organizations can improve their IAM configurations.

            During a Red Team exercise, Unit 42 researchers were able to discover and leverage IAM misconfigurations to obtain admin access to a customer’s entire Amazon Web Services (AWS) cloud environment – a potentially multi-million dollar data breach in the real-world. These examples highlight just how serious the failure to secure IAM can be for an organization.

            Joining us in this week's Research Saturday to discuss the report for Palo Alto Networks' Unit 42 is CSO of Public Cloud, Matt Chiodi.

            The research can be found here:

            • Highlights from the Unit 42 Cloud Threat Report, 2H 2020

            Learn more about your ad choices. Visit megaphone.fm/adchoices

            20 min

          About Research Saturday

          From the publisher's feed

          Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

          More shows like Research Saturday

          Risky Business by Risky Business Media

          Risky Business

          374 Listeners

          CyberWire Daily by N2K Networks

          CyberWire Daily

          1,028 Listeners

          ChinaPower by CSIS | Center for Strategic and International Studies

          ChinaPower

          206 Listeners

          Smashing Security by Graham Cluley

          Smashing Security

          317 Listeners

          Click Here by Recorded Future News

          Click Here

          419 Listeners

          Darknet Diaries by Jack Rhysider

          Darknet Diaries

          8,055 Listeners

          Cybersecurity Today by David Shipley

          Cybersecurity Today

          179 Listeners

          Hacking Humans by N2K Networks

          Hacking Humans

          314 Listeners

          CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

          CISO Series Podcast

          191 Listeners

          Career Notes by N2K Networks

          Career Notes

          14 Listeners

          Pekingology by Center for Strategic and International Studies

          Pekingology

          141 Listeners

          Cybersecurity Headlines by CISO Series

          Cybersecurity Headlines

          138 Listeners

          The AI Fix by Mark Stockley

          The AI Fix

          32 Listeners

          The FAIK Files by Perry Carpenter | N2K Networks

          The FAIK Files

          18 Listeners