ISC StormCast for Friday, October 13th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 13 October 2023
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Friday, October 13th, 2020, |
| 0:04.7 | edition of the Sancent Storm Center's Stormcast. |
| 0:08.9 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:14.1 | I've already mentioned that on Saturday I'll be speaking here at B-Sides in Jacksonville, |
| 0:19.1 | and of course the talk will be about attacks against developers. |
| 0:22.4 | So thanks Philem for coming up with a new blog post today with yet another attack that I probably can include in my talk now. |
| 0:32.1 | The attack in this case targets.net developers by adding malicious packets to the Nuget Gallery. |
| 0:41.5 | Nuget is the packet manager of 4.net and the packages here appear to impersonate some |
| 0:51.3 | crypto coin related packages like for example Solana wallet or Krakhan Exchange. |
| 0:58.5 | Sadly, these packages all from the same developer called Disti had about 2 million downloads. |
| 1:07.4 | Now, in case someone fell for these packages, you will end up with the Cerro Sen rat. |
| 1:16.4 | This particular remote access tool is actually sold more or less somewhat commercially for $60, |
| 1:23.7 | or you can also get a subscription for $15 a month. |
| 1:28.7 | Why would anybody install these packages? |
| 1:31.8 | Well, they try to impersonate some legitimate packages, |
| 1:36.1 | so essentially it's just typosquoting they're doing here. |
| 1:41.2 | The actual matter is then being installed by an install script that will |
| 1:47.0 | download the malicious remote access tool via a number of sort of obfuscated PowerShell scripts. |
| 1:55.2 | Now it took a while, but earlier on Thursday, Microsoft did remove the malicious packages from Nuget. |
| 2:02.6 | Also, the malware installed by these packages has a pretty good antivirus coverage, according to a virus total. |
| 2:12.2 | And sometimes it's almost sad to see how old, old Malware is still around and still learning new tricks. |
| 2:20.3 | Latest example here comes courtesy of ASEC, who observed a new variant of Shellbot. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

