Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • Leveraging legitimate tools.

    Researchers at Symantec spotted a Sodinokibi targeted ransomware campaign in which the attackers are also scanning the networks of some victims for credit card or point of sale (PoS) software.

    It is not clear if the attackers are targeting this software for encryption or because they want to scrape this information as a way to make even more money from this attack.

    Joining us in this week's Research Saturday to discuss the report is Jon DiMaggio of Symantec. 

    The research can be found here: 

    • Sodinokibi: Ransomware Attackers also Scanning for PoS Software, Leveraging Cobalt Strike

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    32 min
  • Going after the most valuable data.

    A look at the realities of ransomware from Sophos, including an industry-first detailed look at new detection evasion techniques in WastedLocker ransomware attacks that leverage the Windows Cache Manager and memory-mapped I/O to encrypt files. A complementary article examines the evasion-centric arms race of ransomware, providing a months-long review of how cybercriminals have been escalating and markedly changing evasion techniques, tactics and procedures (TTPs) since Snatch ransomware in December 2019. 

    The research also breaks down the five early warning signs organizations are about to be attacked by ransomware and why ransomware attacks continue to occur.

    Joining us on this week's Research Saturday to walk us through the research and share their findings is Sophos' Principal Research Scientist Chet Wisniewski and EVP & Chief Product Officer Dan Schiappa.

    The media alert and research articles can be found here: 

    • Media Alert: Sophos Reports on the Realities of Ransomware
    • WastedLocker’s techniques point to a familiar heritage
    • Ransomware’s evasion-centric arms race
    • 5 signs you’re about to be hit by ransomware
    • The realities of ransomware: extortion goes social
    • Ransomware: why it’s not just a passing fad
    • Learn more about your ad choices. Visit megaphone.fm/adchoices

      26 min
    • They fooled a lot of people.

      Docker containers have been gaining popularity over the past few years as an effective way of packaging software applications. Docker Hub provides a strong community-based model for users and companies to share their software applications. This is also attracting the attention of malicious actors intending to make money by cryptojacking within Docker containers and using Docker Hub to distribute these images.

      Palo Alto Networks' Unit 42 researchers identified a malicious Docker Hub account, azurenql, active since October 2019 that was hosting six malicious images intended to mine the cryptocurrency, Monero. The images hosted on this account have been collectively pulled more than two million times. Additionally, when last checked minexmr.com for this wallet ID, Palo Alto's team saw recent activity indicating that it’s still being used.

      Joining us on this week's Research Saturday is Jen Miller-Osborn from Palo Alto Networks' Unit 42 group to share the research and findings.

      The research and blog post can be found here: 

      • Attackers Cryptojacking Docker Images to Mine for Monero

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      15 min
    • Using global events as lures.

      The goal of malicious activity is to compromise the system to install some unauthorized software. Increasingly that goal is tied to one thing: the user. Over the past several years, we as an industry improved exploit mitigation and the value of working exploits has increased accordingly. Together, these changes have had an impact on the threat landscape. We still see large amounts of active exploitation, but enterprises are getting better at defending against them.

      This has left adversaries with a couple of options, develop or buy a working exploit that will defeat today's protections, which can be costly, or pivot to enticing a user to help you. In today's threat landscape, adversaries are always trying to develop and implement the most effective lures to try and draw users into their infection path. They've tried a multitude of different tactics in this space, but one always stands out — current events.

      Joining us on this week's Research Saturday from Craig Williams from Cisco's Talos Outreach team to walk us through how current events are used as lures.

      The research and blog post can be found here: 

      • Adversarial use of current events as lures


      The CyberWire's Research Saturday is presented by Juniper Networks.

      Thanks to our sponsor Enveil, closing the last gap in data security.

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      22 min
    • Waiting for their victims.

      Bitdefender researchers have recently found the APT group StrongPity has been targeting victims in Turkey and Syria. Using watering hole tactics to selectively infect victims and deploying a three-tier C&C infrastructure to thwart forensic investigations, the APT group leveraged Trojanized popular tools, such as archivers, file recovery applications, remote connections applications, utilities, and even security software, to cover a wide range of options that targeted victims might be seeking.

      Joining us on this week's Research Saturday to discuss the research is Bitdefender's Liviu Arsene. 

      You can find the research here:

      StrongPity APT – Revealing Trojanized Tools, Working Hours and Infrastructure

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      24 min
    • Like anything these days, you have to disinfect it first.

      “Cyberbunker” refers to a criminal group that operated a “bulletproof” hosting facility out of an actual military bunker. “Bullet Proof” hosting usually refers to hosting locations in countries with little or corrupt law enforcement, making shutting down criminal activity difficult. Cyberbunker, which is also known as “ZYZtm” and “Calibour”, was a bit different in that it actually operated out of a bulletproof bunker. In September of last year, German police raided this actual Cyberbunker and arrested several suspects.

      While most of the group's assets were seized during the initial raid, the IP address space remained and was later sold to Legaco Networks. Before being shut down, Legaco Networks temporarily redirected the traffic to the SANS Internet Storm Center honeypots for examination.

      Joining us on this week's Research Saturday from SANS Technology Institute is graduate student Karim Lalji and Dean of Research Johannes Ullrich to discuss their experiences. 

      The research and blog post can be found here: 

      Real-Time Honeypot Forensic Investigation on a German Organized Crime Network

      Cyberbunker 2.0: Analysis of the Remnants of a Bullet Proof Hosting Provider

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      27 min
    • Detecting Twitter bots in real time.

      NortonLifeLock Research Group (NRG) released a prototype browser extension called BotSight that leverages machine learning to detect Twitter bots in real-time. The tool is intended to help users understand the prevalence of bots and disinformation campaigns within their Twitter feeds, particularly with the increase in disinformation of COVID-19.

      Joining us on this week's Research Saturday to discuss this tool is Daniel Kats from NortonLifeLock Research Group.

      You can find the research here:

      Introducing BotSight

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      24 min
    • It was only a matter of time.

      On April 29, 2020, the Salt management framework, authored by the IT automation company SaltStack, received a patch concerning two CVEs; CVE-2020-11651, an authentication bypass vulnerability, and CVE-2020-11652, a directory-traversal vulnerability.

      On April 30, 2020, researchers at F-Secure disclosed their vulnerability findings to the public, with an urgent warning for Salt users - patch now. Before the weekend was out, criminals were deploying malware and targeting vulnerable Salt installations, successfully affecting operations at Ghost, DigiCert, and LineageOS. The malware is a cryptominer, but there is an additional component, a Remote Access Tool written in Go called nspps. Researchers at Akamai have also observed in-the-wild attacks on Salt vulnerabilities. 

      Joining us on this week's Research Saturday is Larry Cashdollar, Senior Security Response Engineer at Akamai, to discuss this issue. 

      The research can be found here: 

      SaltStack Vulnerabilities Actively Exploited in the Wild

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      15 min
    • Every time we get smarter, the bad guy changes something.

      Researchers at Symantec identified and alerted customers to a string of attacks against U.S. companies by attackers attempting to deploy the WastedLocker ransomware (Ransom.WastedLocker) on their networks. The end goal of these attacks is to cripple the victim’s IT infrastructure by encrypting most of their computers and servers in order to demand a multimillion dollar ransom. At least 31 Symantec customer organizations have been attacked, meaning the total number of attacks may be much higher. The attackers had breached the networks of targeted organizations and were in the process of laying the groundwork for staging ransomware attacks.

      Joining us in this week's Research Saturday to discuss the report is Jon DiMaggio of Symantec. 

      The research can be found here: 

      • WastedLocker: Symantec Identifies Wave of Attacks Against U.S. Organizations


      Learn more about your ad choices. Visit megaphone.fm/adchoices

      33 min
    • Are you running what you think you're running?

      Built into virtually every hardware device, firmware is lower-level software that is programmed to ensure that hardware functions properly.

      As software security has been significantly hardened over the past two decades, hackers have responded by moving down the stack to focus on firmware entry points. Firmware offers a target that basic security controls can’t access or scan as easily as software, while allowing them to persist and continue leveraging many of their tried and true attack techniques.

      Joining us on this week's Research Saturday is Maggie Jauregui, security researcher at Dell, to discuss this issue. 

      The research can be found here: 

      Three firmware blind spots impacting security

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      17 min

    About Research Saturday

    From the publisher's feed

    Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

    More shows like Research Saturday

    Risky Business by Risky Business Media

    Risky Business

    374 Listeners

    CyberWire Daily by N2K Networks

    CyberWire Daily

    1,028 Listeners

    ChinaPower by CSIS | Center for Strategic and International Studies

    ChinaPower

    206 Listeners

    Smashing Security by Graham Cluley

    Smashing Security

    317 Listeners

    Click Here by Recorded Future News

    Click Here

    419 Listeners

    Darknet Diaries by Jack Rhysider

    Darknet Diaries

    8,055 Listeners

    Cybersecurity Today by David Shipley

    Cybersecurity Today

    179 Listeners

    Hacking Humans by N2K Networks

    Hacking Humans

    314 Listeners

    CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

    CISO Series Podcast

    191 Listeners

    Career Notes by N2K Networks

    Career Notes

    14 Listeners

    Pekingology by Center for Strategic and International Studies

    Pekingology

    141 Listeners

    Cybersecurity Headlines by CISO Series

    Cybersecurity Headlines

    138 Listeners

    The AI Fix by Mark Stockley

    The AI Fix

    32 Listeners

    The FAIK Files by Perry Carpenter | N2K Networks

    The FAIK Files

    18 Listeners