meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, January 22nd, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 22 January 2024

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. macOS Malware; Microsoft Breach; Juniper 0-Day Details; Brave

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, January 22nd, 2024 edition of the Sands and its Storm Center's Stormcast.

0:08.8

My name is Johannes Ulrich.

0:10.6

And today I'm recording from Jacksonville, Florida.

0:14.6

Got some really interesting malware from Xavier on Friday.

0:19.7

This particular malware runs on Mac OS. It's written in Python,

0:24.9

and it's designed to emulate and replace two crypto coin applications, the Exodus crypto wallet,

0:32.5

and Bitcoin Core. Once a user downloads and executes the Python script, it will first collect

0:40.3

some information about the host. It will set up a connection to a command control server

0:46.2

that then may send additional Python commands to execute. All of this is done pretty simple,

0:53.1

pretty straightforward. It's just Bay 64 encoded,

0:56.9

so really no attempt here to do anything more sophisticated when it comes to sort of obfuscation

1:03.3

or encryption. It then also downloads replacements for the Exodus app and the Bitcoin Core app. Not really clear at this

1:13.3

point what these particular replacements will do. They also include the electron framework,

1:21.1

and that's of course used by a lot of desktop applications these days to make it easy to develop them a little bit sort of OS

1:29.0

agnostic. It does require that the victim has the X code installed because it does actually

1:38.2

compile a script, an OSA script that's being installed as a part of the malicious package.

1:46.8

Like I said, the script doesn't really do anything special kind of in order to obfuscate itself.

1:51.6

It still has a very low virus total score.

1:56.1

When Xavier looked at it, it was just three out of 59. That has since improved a little bit to 17.

2:05.8

The first upload to virus total was on the 18th. So that was Thursday. And then there was a lot of

2:14.9

news about accounts at Microsoft being compromised.

2:19.2

And I just want to talk briefly about some of the lessons learned here.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.