Incident Response Specialist, GERT
Cristian Souza is an Incident Response Specialist at Kaspersky’s Global Emergency Response Team (GERT). He holds a degree in Computer Networks and is currently pursuing a Ph.D. in Computer Science at the University of São Paulo (USP). Cristian’s primary responsibilities include conducting forensic analysis of critical incidents, identifying their root causes, and performing malware reverse engineering. An active contributor to the cyber security community, Cristian has published several research papers and holds certifications including CISSP, GCFA, GREM, and GXPN.Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
An in-depth analysis of Umbrij, a new tool used by the ToddyCat APT group to compromise corporate email communications in Gmail. The attack targeted OAuth authorization tokens, allowing threat actors to gain access to Google services.
Cloud Atlas attacks the public sector and diplomatic structures of Russia and Belarus, using ReverseSocks, SSH, and Tor for persistence in infected systems and its new tool, PowerCloud.
Kaspersky researchers analyze a range of new PebbleDash-based tools used in recent Kimsuky campaigns and reveal their connection to the AppleSeed malware cluster.