Recently I researched activity from some DPRK baddies called Andariel. The investigation involved 2 set of attacks, a staging server, some new RATs, and tools/TTPs - all attributable to Andariel.
The report is now live: https://t.co/ZkupalpvRI
#malware#andariel#dprk
A couple thoughts on ATT&CK Evaluations...yes, the marketing is ridiculous. I also hope the useful parts of these evaluations won't get completely lost in that. You can find a lot of insight on tools if you dive into the results. Here are some example questions to consider...
🧵
#DUCKTAIL has adapted their infection chain in a short span of time since our latest report was published.
I have summarized their latest execution chain in the attached figure.
In short:
1/3 I am happy to share the latest research I had been working on - "Meet the Ducks".
We've witnessed an uptick of threat activity surrounding #Meta's ad ecosystem from Vietnam since early 2023 - some highlighted by us as well as other vendors & security researchers in the past.
NEW RESEARCH: In their latest report, @mkazemhn and @_ginnare dive into Vietnamese cyber crime targeting Meta Business accounts, with specific attention paid to DUCKTAIL & a new threat called DUCKPORT
https://t.co/qNQjfxCGLP
#meettheducks#ducktail#duckport#CyberSecurity
Are language model "hallucinations" always useless?
Might they be used to generate new research ideas?
After all, some of the most interesting developments in machine learning have happened by chance.
In this short thread, I'll present some findings on this topic.
1/10
NEW RESEARCH: WithSecure Labs publishes a report documenting the movement of SILKLOADER from Chinese cyber criminals to Russian #ransomware gangs, including CONTI and it’s various affiliates/offspring.
Read the report here--> https://t.co/6RgzjqAUs9
#SILKLOADER#Cyberattack
Let's continue our ATT&CK misunderstandings series & discuss procedures.
People sometimes assume ATT&CK is trying to cover every possible way a (sub-)technique can be done, but our procedures only cover what we've seen in public reporting tied to Groups, Software, or Campaigns.
NEW RESEARCH: WithSecure’s @r0zetta details several interesting prompt engineering tricks that could be used to creatively abuse GPT-3, forcing people to become even more skeptical about what they read>> https://t.co/L6pVl8QEug
#AI#GPT3#MachineLearning#cybersecurity#infosec
NEWS: DUCKTAIL, a Vietnam-based cyber crime group discovered by WithSecure, has expanded and evolved their operations. Their attacks cost businesses hundreds of thousands of dollars.
Read more in our new report >>
https://t.co/cAtNLFjTI3
#cyberattacks#Ducktail#cybersecurity
SOC analysts and detection engineers who like to publicly write/talk about detection content should put out more about the false positives they usually have to deal with. I feel that false positives often suffer from what academics call the "Publication bias"
[1/5] Well as you know me there is no trash I would recommend -> I highly recommend to give a try and play with these newly released set of tools #GarbageMan made by @WithSecure. Works like charm for #NET analysis🙏🙌😍
Github:https://t.co/UoKCcjizIq
Blog:https://t.co/SJIE14OBr4
NEWS: WithSecure™ has discovered a new Infostealer Malware, dubbed “DUCKTAIL” which can hijack Facebook Business accounts
https://t.co/lUnm6R5l3h
#CyberAttack#cybersecurity#malware#Facebook
F-Secure reports the NRSMiner cryptocurrency miner, known to user EternalBlue to propagate inside networks, has updated to a newer version https://t.co/Uzgt48sP8V