meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, October 14th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 14 October 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Alchimist/Insekt C&C; vm2 vuln; npm package disclosure; Zimbra Patch

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Friday, October 14, 2020 edition of the Sansonet Storm Center's Stormcast.

0:09.7

My name is Johannes Ulrich and I'm recording from Riyadh, Saudi Arabia.

0:16.2

Cisco's Talas research team published a blog post today describing a new attack framework that they're calling

0:23.3

Alchemist and Insect. Alchemist is the command control server implementing a web-based

0:30.1

interface to control systems infected by the insect implant. Alchemist is implemented as a simple single file and executable. This, of course,

0:41.2

makes it kind of easy to install on random compromised web servers that the attacker may be using

0:49.2

as part of their command control infrastructure. It does run on Windows and Linux and TELUS states that the overall

0:59.3

design is reminiscent of Manjuska, if I pronounce this correctly, a command control framework

1:05.7

that TALIS discovered a short while ago. As a victim connects to the Alchemist Command Control

1:13.1

server, the insect payload is then generated on the fly. There is sort of a template that's

1:18.9

present on the server and it hot patches than some customized configuration parameters

1:26.2

for the particular victim connecting.

1:30.0

TALIS lists more details and tips on detections in its blog post,

1:34.2

and of course there are already some snort rules available for that.

1:39.1

The Alchemist command control server has been seen, as I said, on Windows and Linux, but the insect implant does

1:47.0

also work on Mac OS.

1:52.0

VM2 is a JavaScript sandbox meant to isolate untrusted code.

1:58.0

Always something difficult to get right.

2:00.0

The sandbox is not only very popular.

2:03.4

It has 16 million downloads a month, but it also suffered from a vulnerability that, well,

2:10.1

allowed malicious code to escape the sandbox, which then, of course, could lead to arbitrary

2:14.8

code execution on the host running any software that depends on the VM2 sandbox.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.