4.9 • 696 Ratings
🗓️ 17 December 2024
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Tuesday, December 17th, 2024 edition of the Sands and it's Storms and a |
0:08.0 | stormcast. My name is Johannes Ulrich and I'm recording from Washington, D.C. |
0:15.5 | Data Talk Security Labs published an interesting blog post showing the inner workings a little bit of an attack group |
0:24.1 | that they're calling Mutt 1244. |
0:28.4 | This group specialized among others on targeting security researchers. |
0:35.2 | If you attack salespeople, you may threaten them with an updated commission |
0:39.6 | structures for security people. The lure of choice is usually exploit code. So what MUT 1244 did |
0:48.9 | is that they published a number of different repostories on GitHub promising new exploit code that, |
0:57.0 | of course, was backdoored. |
0:59.0 | This is a common theme. |
1:01.0 | Nothing really new if you are working with a code that you're downloading from GitHub |
1:06.6 | in particular. |
1:07.4 | If it claims to be malicious, well, you better assume it's malicious, but malicious |
1:12.0 | not in the way that you are expecting. It isn't clear exactly how successful this was. |
1:19.1 | Their goal was to then install a malicious Cryptocon miner update that, of course, steals |
1:26.2 | credentials. There was a leak, of course, steals credentials. |
1:33.8 | There was a leak of 390,000 credentials associated with this group, but these are credentials for WordPress accounts, so there is likely other data that also has been leaked by this particular |
1:42.2 | group. |
1:42.9 | In addition to the malicious GitHub reposit, the group also used fishing in the particular |
1:51.2 | phishing email that was published here by Datadog. |
1:54.5 | They promised an update to CPU microcode. |
1:59.3 | It looked actually pretty good at the email. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.