ISC StormCast for Thursday, August 1st 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 1 August 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, August 1st, 2019 edition of the Sandcent Storm Center's Stormcast. My name is Johannes Ulrich. |
| 0:09.2 | I'm recording from Boston, Massachusetts. Today we actually have the rare trade to look at a targeted |
| 0:16.8 | fishing attack that was directed at loan officers in financial companies. |
| 0:23.8 | The fish came thanks to Justin Trullo, a cybersecurity analyst from Loan Depot, who not only |
| 0:33.2 | identified this fish, but also was able to retrieve a good part of the fishing kit, which is |
| 0:40.3 | essentially the website being used to collect the credentials. |
| 0:44.3 | What distinguishes these targeted fishing attacks is that the emails being used here |
| 0:50.3 | are specifically crafted for the respective industries. In this case, the email claimed to come |
| 0:57.2 | from a title company and then enticed the victim into clicking on a link to download documents. |
| 1:05.6 | The fishing website did emulate box.com. Box.com, of course, being sort of one of those big enterprise |
| 1:13.8 | file sharing sites, and it did allow the victim to log in using various other cloud services, |
| 1:21.1 | and the goal here in the end was to obtain those respective credentials. |
| 1:27.3 | And we don't, of course, know for sure what would have happened if one of the Lone Depot loan |
| 1:32.9 | officers would have fallen for this particular fish. |
| 1:37.0 | But typically, the attacker will collect these credentials to then log into the victim's |
| 1:43.7 | email account and use it for business email |
| 1:46.9 | compromise. For example, waiting for someone to ask for wire transfer instructions and then |
| 1:53.8 | replying with a fake bank account. When you're installing software and hardware in your environment, it all too often |
| 2:03.6 | does connect back to the particular Wenders network. Now often this is just to check for updates, |
| 2:11.5 | for example, but sometimes it also infiltrates data about the network the system is installed in or |
| 2:20.7 | the host it is installed on. Security company ExtraHop now released a report with a couple of case |
| 2:27.7 | studies where enterprise software actually did exfiltrate data back to the vendor's network. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

