meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, March 24th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 24 March 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Mars Stealer; Okta/MSFT/Lapsus$ Update; Azure npm Attack;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, March 24th, 2020 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich. And today I'm recording from Jacksonville, Florida.

0:13.7

We've got another great malware write-up by Brad, and he this time looked at Mars Steeler.

0:27.7

Mars Steeler is derived from older Malware and, well, Brad documents that Vidal and Oski Steeler were basically precursors of this Malware.

0:32.5

What's sort of interesting here is that the malware, when it's being installed, it's not

0:36.9

it's just installing itself, it's being installed is not just installing itself.

0:38.5

It's also installing six different DLL files that are actually themselves not malicious.

0:46.1

Four of these are Thunderbird files like DLLs, like for example, NSS and SoftToken and Mosklu are some of these DLs that are being

0:57.5

installed by Mars Steeler, and it uses the functionality of these legitimate DLs then in order

1:04.7

to facilitate its data exfiltration.

1:08.9

Mars Dealer may arrive via various downloaders.

1:12.8

It's then downloaded as a SIP file.

1:14.8

The SIP file does also include these non-malicious DLs.

1:20.1

And well, then it starts with exfiltrating, commonly stolen data from the system it infects.

1:28.3

The X-Filtrate data is wrapped up in a SIP file and then essentially just uploaded to a website.

1:35.3

P-CAPs of actually all three different variants, so the old ones going back to 2019, as well as the latest one, the Mars dealer from this month,

1:47.2

are available with links in Brad's diary.

1:52.7

And we got a little bit more insight in what happened with Octa.

1:56.1

So apparently on January 20th, an employee of Sightel.

2:01.5

Cytle is a company that provides outsourced customer support was compromised,

2:08.2

and then the access gained from this employee's system was used to access 366 different octa customers.

2:18.3

How much access was gained here with these customers

2:22.3

isn't necessarily obvious based on the blog post.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.