Events

Another day in Amsterdam

While the situation with the weather hasn’t gotten any better, the atmosphere at BlackHat is still good.

It’s quite obvious to see that Rootkits are a hot topic right now with three presentations tackling this topic.

I just attended a presentation about ACPI Rootkits but it hasn’t quite taken away my sceptisism regarding this subject.

Earlier today there was an interesting presentation on how Skype works, which brought us some topics to think about.

Skype isn’t unbreakable, and it’s not unblockable. But breaking or blocking it (particularly the first) would take quite a lof of effort.

However this only applies to outsiders trying to decrypt traffic. Skype Inc. has no problem decrypting intercepted traffic.

And now we’re off to see the last presentation of BlackHat Europe 2006. It’s been a fun couple of days.

Another day in Amsterdam

Your email address will not be published.

 

Reports

Kimsuky’s GoldDragon cluster and its C2 operations

Kimsuky (also known as Thallium, Black Banshee and Velvet Chollima) is a prolific and active threat actor primarily targeting Korea-related entities. In early 2022, we observed this group was attacking the media and a think-tank in South Korea.

Andariel deploys DTrack and Maui ransomware

Earlier, the CISA published an alert related to a Stairwell report, “Maui Ransomware.” Our data should openly help solidify the attribution of the Maui ransomware incident to the Korean-speaking APT Andariel, also known as Silent Chollima and Stonefly.

Subscribe to our weekly e-mails

The hottest research right in your inbox