Security Serengeti

SS-NEWS-076: Criminal Groups Moving to Sliver Framework over Cobalt Strike


Listen Later

In this episode, we discuss Cloudflare IP's being banned in Austria due to overzealous Copyright enforcement, how attackers are moving off of Cobalt Strike as it's getting too well known, and finally Stego!  Yes, that's right, all of that CTF experience in stegonagraphy will finally come in handy!  Attackers were spotted downloading malware hidden in the cert of a JPG.
Article 1 - Pirate sites ban in Austria took down Cloudflare CDNs by mistakeSupporting Links:How content delivery networks (CDNs) workWahrnehmung von Leistungsschutzrechten GmbH - Informationen
Article 2 - Cybercrime Groups Increasingly Adopting Sliver Command-and-Control FrameworkSupporting Links:A How-To Guide for Using Sliver
Article 3 - James Webb telescope images used to hide malwareSupporting Links:How to monitor/detect Microsoft Office macro execution?Command line process auditing
If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!
...more
View all episodesView all episodes
Download on the App Store

Security SerengetiBy David Schwendinger and Matthew Keener

  • 5
  • 5
  • 5
  • 5
  • 5

5

1 ratings