meta_pixel
Tapesearch Logo
Log in
CyberWire Daily

PoetRAT: a complete lack of operational security. [Research Saturday]

CyberWire Daily

N2K Networks, Inc.

Technology, News, Daily News, Tech News

4.81.1K Ratings

🗓️ 7 November 2020

⏱️ 21 minutes

🧾️ Download transcript

Summary

Cisco Talos discovered PoetRAT earlier this year. Since then, they observed multiple new campaigns indicating a change in the actor's capabilities and showing their maturity toward better operational security. They assess with medium confidence this actor continues to use spear-phishing attacks to lure a user to download a malicious document from temporary hosting providers. They currently believe the malware comes from malicious URLs included in the email, resulting in the user clicking and downloading a malicious document. These Word documents continue to contain malicious macros, which in turn download additional payloads once the attacker sets their sites on a particular victim. As the geopolitical tensions grow in Azerbaijan with neighboring countries, this is no doubt a stage of espionage with national security implications being deployed by a malicious actor with a specific interest in various Azerbajiani government departments. Joining us in this week's Research Saturday to discuss the research from Cisco's Talos Outreach is Craig Williams. The research can be found here:  PoetRAT: Malware targeting public and private sector in Azerbaijan evolves Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

You're listening to the CyberWire Network, powered by N2K.

0:07.0

Today's episode is sponsored by SRM, your first call for cybersecurity and

0:18.1

investigations. Threats today are evolving faster than ever before and since 2005 SRM has pioneered

0:25.3

tailored security solutions for global corporations and their executives.

0:29.5

Whether it's defending against cyber attacks with their award-winning team of ethical hackers and incident response specialists,

0:36.4

or navigating the murky waters of compliance and ESG challenges,

0:40.9

SRMs, Insight and Straight straightforward advice will help you navigate complex risks

0:46.4

and emerge more resilient.

0:48.4

Their secret, a culture that nurtures the sharpest minds, giving them access to the newest technologies and the freedom

0:55.3

to solve problems in new ways, enabling them to craft simple effective solutions for your

1:01.4

unique cyber challenges.

1:03.7

Search your first call to discover how SRM can help your business. Hello everyone and welcome to the CyberWire's research Saturday.

1:25.0

I'm Dave Bitner and this is our weekly conversation with researchers and analysts

1:29.0

tracking down threats and vulnerabilities, solving some of the hard problems of protecting ourselves in a rapidly

1:35.2

evolving cyberspace.

1:37.3

Thanks for joining us.

1:38.3

We have a data set that's probably unmatched in the industry and so we look through it

1:46.7

constantly trying to find new samples doing strange and interesting things and

1:51.6

while doing that one day we stumbled across Poet Rat.

1:56.3

That's Craig Williams.

1:57.6

He's the head of Talo's outreach at Cisco.

2:00.1

The research we're discussing today is titled Poet Rat.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.