ISC StormCast for Wednesday, October 26th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 26 October 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Wednesday, October 26, 2000, 22 edition of the Sansonet Storm Center's Stormcast. |
| 0:08.0 | My name is Johannes Ulrich and today I'm recording from Augusta, Georgia. |
| 0:15.0 | The first story is sort of a, well, what took them so long, a kind of a story. |
| 0:20.0 | GitHub actions are apparently used to mine |
| 0:23.5 | crypto coins. Security company SISDIC wrote up this campaign that they're calling a purple |
| 0:31.9 | urchin. As this is, well, a pretty obvious abuse of free computer resources, SISTIC writes that many providers |
| 0:39.5 | implemented CAPTCHAs and other countermeasures to make it, well, just too painful, really, to |
| 0:45.6 | abuse the free but limited resources. Purple Urchin highly automates their tag using GitHub, |
| 0:53.5 | Heroku, and Buddy other three services they're using. |
| 0:57.3 | And then they essentially open thousands of accounts. |
| 1:00.1 | They have about 130 different Docker images that they use then to run actions in GitHub, |
| 1:08.4 | which will allow Purple Urchin to use about 33 hours a month of free compute time |
| 1:16.1 | from GitHub. |
| 1:17.6 | Now, of course, the compute resource you get within these 33 hours are limited and well, but |
| 1:24.6 | the way they make it still work for them is by highly automating everything. |
| 1:29.3 | They have like an image, a Docker image that sort of serve as a command control server. |
| 1:35.5 | It also proxies all the mining pool connections via that command and control server. |
| 1:44.1 | But the lesson overall is that sadly if you offer free resources, |
| 1:48.0 | yes, they're going to get abused, then you probably need to be ready for that. |
| 1:54.0 | Sisa and the FBI are warning about a ransomware group that they're calling the Dakesin team, if I pronounce this correctly. |
| 2:08.5 | This group appears to be targeting healthcare providers and initial access happens via VPN servers, |
| 2:16.2 | via previously compromised credentials. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

