meta_pixel
Tapesearch Logo
Log in
CyberWire Daily

Infostealer Malware 101: mitigating risks and strengthening defenses against this insidious threat. [CyberWire-X]

CyberWire Daily

N2K Networks, Inc.

News, Daily News, Tech News, Technology

4.81.1K Ratings

🗓️ 23 July 2023

⏱️ 31 minutes

🧾️ Download transcript

Summary

With the relentless advancements in technology and a workforce more digitally-enabled than ever before, businesses today face an unprecedented challenge of protecting their sensitive information from cybercriminals. Infostealer malware, often disguised as innocuous files or hidden within legitimate-looking emails, stealthily infiltrate employee and contractor devices – managed and unmanaged – exfiltrating all manner of data for the purposes of executing follow-on attacks including ransomware. The data at risk includes customer details, financial information, intellectual property, and R&D plans stolen from compromised applications that were accessed from infostealer-exfiltrated authentication data like credentials and active session cookies/tokens. This episode digs into the proliferation of infostealers and provides actionable steps for businesses of any size or industry to mitigate the threat. In this episode of CyberWire-X, N2K’s CSO, Chief Analyst, and Senior Fellow, Rick Howard, is joined in the first half by Hash Table member Rick Doten to discuss the early days of incident response and the current thinking of post-infection remediation (PIR) actions. In the second half of the show, CyberWire podcast host Dave Bittner talks with our episode sponsor SpyCloud’s Director of Security Research, Trevor Hilligoss. They chat about the challenges for enterprises and security leaders to identify what was stolen from malware-infected devices and how proper post-infection remediation implemented into existing incident response workflows can help prevent this data from causing ransomware. Trevor shares highlights from an industry report of over 300+ security leaders from North America and the UK on where they stand on malware identification and remediation, and what additional work can be done to minimize cybercriminals' access and impact. Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

You're listening to the CyberWire X, a series of specials where we highlight important security topics

0:25.9

affecting security professionals worldwide.

0:28.8

I'm Rick Howard N2K's chief security officer and the CyberWire's chief analyst and senior fellow.

0:35.0

Today, Dave Bitner, the senior producer and host of many of the CyberWire's podcast,

0:40.0

will be joining me at the CyberWire's hash table to discuss post-infection remediation or PIR.

0:47.0

After the break, you'll first hear my conversation with Rick Dauten, the CSO for Healthcare Enterprises, and Senteen, and then Dave will talk with

0:55.7

Trevor Hilligoss, the director of security research at Spy Cloud, the sponsor of this show.

1:01.8

Come right back.

1:07.0

Spy Cloud disrupt cybercrime by telling you what criminals know about your business and your customer

1:17.0

so you can take action on exposed authentication data to prevent ransomware, session hijacking, account takeover, and online fraud.

1:26.0

With knowledge of the specific dark net data criminals have in hand, like credentials,

1:30.5

cookies, and PII, siphon from malware-infected devices accessing your network

1:35.5

and applications, security teams have better visibility into the expanding attack surface

1:41.1

that puts their organization at risk from cyber attacks and can

1:44.9

respond quickly with SpyCloud's automated solutions.

1:48.2

Visit spycloud.com slash cyberwire to view SpyCloud's Malware Readiness and Defense Report, a benchmark survey

1:56.5

of global security practitioners on how they combat Infostealer malware and are planning

2:02.0

for gaps in their post-infection

2:04.0

that lead the door open for ransomware attacks. That's SpyCloud.com

2:09.3

slash CyberWire and we thank SpyCloud for sponsoring our show. The incident response has been around as a concept since the late 1980s when it

2:27.5

practically sprang out of whole cloth from Dr. Clifford Stoll.

2:31.7

When he published his communication of the ACM journal article called

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.