meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, February 19th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 19 February 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Trickbot; AppleJeus; Python 3 Buffer Overflow; Apple Security Guide

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, February 19th, 2021 edition of the Sandcent Storm Center's Stormcast.

0:08.7

My name is Johannes Ulrich.

0:10.2

And today I'm recording from Jacksonville, Florida.

0:14.5

Brad today has an analysis of the latest Trickbot sample that he came across.

0:23.4

Trickbot in the past has had some interesting, innovative features. This time around, nothing really too special and actually

0:29.0

looks like they're slacking off a little bit and messing it up here. They're downloading a DLL file,

0:36.0

not an executable. well, that's ultimately nothing

0:39.5

really new. And then they're setting up a scheduled task to start that DLL. The problem is

0:46.6

they're slightly messing up the path. So this DL, at least the sample that Brad, didn't actually then run. The emails that carry

0:57.9

this particular trick-bought version, nothing really all too fancy. DocuSign, again, is sort of their

1:04.5

theme here, and the user has to open an Excel spreadsheet and enable macros for the malware to run.

1:14.0

You may have heard the news about the indictment that was unsealed against some

1:19.5

hackers that are working for the North Korean government and were involved in the theft

1:26.1

of cryptocurrencies.

1:28.3

Today, the cybersecurity infrastructure security agency followed up with seven different

1:34.3

bulletins that contain details about the particular malver being used and, well, they call these

1:42.3

samples Apple Juice, where Juice is spelled

1:46.2

J-E-U-S. This malware operates on different platforms, so you'll find it on Apple as well as on Windows,

1:54.7

but the common denominator here is that they try to impersonate legitimate cryptocurrency trading applications and essentially

2:04.1

trick the user into willingly installing the application. There is no technical exploit really

2:10.5

involved in getting the application installed. In some cases, like for example for the Apple versions, it's not even digitally signed,

2:21.0

so you will get a prominent warning and may even have to jump through some hoops to install

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.