4.9 • 696 Ratings
🗓️ 26 September 2023
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Tuesday, September 26, 2023 edition of the Sands and the Storm Center's Stormcast. |
0:08.8 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
0:14.2 | I don't talk a lot about sort of some more targeted attacks, but there is a report by Sentinel Labs. |
0:20.2 | I figured it is worth talking about because it discusses some malware that has been used |
0:27.4 | to target some telcos in Europe, North Africa and the Middle East. |
0:32.3 | And it uses a couple of interesting techniques. |
0:36.2 | Often these techniques then later trickle down into a sort of |
0:40.4 | more commodity malware. One interesting idea here is that they're using Lua just in time. This is |
0:48.4 | a just in time compiler for the Lua scripting language. The actual maver is written in Lua, which of course makes it more modular, easier to maintain |
0:58.6 | than something that's outright compiled. |
1:01.3 | And by deploying it with the Lua virtual machine, it also does evade some standard detection |
1:09.8 | techniques. |
1:11.1 | The group deploying this malware is also taking advantage yet again of past the hash and |
1:17.1 | NTLM authentication. |
1:19.3 | Talking to other Sandsen structures and such that do pen tests, this is sort of one of their |
1:25.6 | most common finding. |
1:27.8 | It's often exploited for lateral movement, also by ransomware gangs. |
1:32.9 | So even if you don't feel targeted by this malware, yet another good reminder to sort of, you know, harden this part of your infrastructure. |
1:42.3 | Finally, for a command and control channel, what sort of stuck out to me here is that this |
1:48.6 | Malver uses Quick. |
1:50.3 | I haven't really seen Quick being used much. |
1:52.5 | Also, they're using HTTP 2, I believe, here. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.