meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, March 19th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 19 March 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Python Keylogger; XcodeSpy; Zoom Screen Sharing Leak; MyBB RCE

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, March 19th, 2021 edition of the Santernut Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm virtually teaching from San Diego, California.

0:15.0

Keyloggers are a standard component of malware and Xavier took a closer look at key loggers implemented in Python,

0:25.6

with Python, of course, being a language that does show up more and more in malware.

0:31.6

Xavier used Varys Total Retrohunt to look for samples that implement keyloggers in Python.

0:39.6

And he found a small number of them a total of nine occurrences only, but many of them

0:46.9

were submitted in the last couple months.

0:49.5

So let me indicate that the bad guys are actually taking notice and are starting to experiment

0:56.6

more with Python keyloggers.

1:00.2

Well, I'm talking about keyloggers recording the user's keystrokes.

1:04.7

Why not also record sounds with the microphone and images with the camera while you're at.

1:11.8

That is apparently what a new piece of Malver is doing that is targeting Mac developers.

1:18.9

Xcode Spy is what Sentinel One called it in its blog post.

1:25.3

And it is infecting developers' systems if they are trying to install a malicious

1:31.8

module. The legitimate module they are trying to install is called tabbar interaction, but

1:38.8

there is a look-alike project on GitHub that is easily mistaken for this legitimate module.

1:46.9

And the result is that once you are compiling a project with the malicious version of

1:53.4

Tapbar interaction, it takes advantage of a feature of Xcode, the Apple developer environment, that can execute code while it compiles a project,

2:06.8

and this malicious code will then install a backdoor on developers' system.

2:12.9

Of course, it's of your classic supply chain attack.

2:15.7

Once the attacker has a foothold on the developer system,

2:19.4

they now are able to modify and corrupt any software that is being created on that

2:27.4

developer's system as well. This backdoor may go back to September last year.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.