meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Friday, August 1st, 2025: Scattered Spider Domains; Excel Blocking Dangerous Links; CISA Releasing Thorium Platform

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 1 August 2025

⏱️ 6 minutes

🧾️ Download transcript

Summary


Scattered Spider Related Domain Names
A quick demo of our domain feeds and how they can be used to find Scattered Spider related domains
https://isc.sans.edu/diary/Scattered+Spider+Related+Domain+Names/32162
Excel External Workbook Links to Blocked File Types Will Be Disabled by Default
Excel will discontinue allowing links to dangerous file types starting as early as October.
https://support.microsoft.com/en-us/topic/external-workbook-links-to-blocked-file-types-will-be-disabled-by-default-6dd12903-0592-463d-9e68-0741cf62ee58
CISA Releases Thorium
CISA announced that it released its malware analysis platform, Thorium, as open-source software.
https://www.cisa.gov/news-events/alerts/2025/07/31/thorium-platform-public-availability

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Friday, August 1st, 2025 edition of the Sands Internet Storm Centers.

0:06.8

Stormcast, my name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:12.3

And this episode is brought you by the Sands.edu Graduate Certificate Program in Cybersecurity Leadership.

0:20.5

Yesterday, SISA in collaboration with other government agencies,

0:25.1

published an updated report about Scattered Spider.

0:29.4

It's not the first time they published a report about this group,

0:32.5

but as I mentioned yesterday, they updated some of the social engineering

0:36.6

kind of techniques being used by the group, but also included some of the social engineering kind of techniques being used

0:38.2

by the group, but also included sort of the usual indicators of a compromise. And the one part

0:45.1

that I was kind of interested in was the new domain patterns that were being used here, like

0:52.7

the targets name-cMS.com or targets name dash helpdesk.com.

0:59.2

So basically that would be the company name and just followed by helpdesk.com.

1:03.5

Then of course, no matches, kind of them impersonating help desks and such.

1:07.9

So I was going over our data to see if we do find any names like this

1:14.2

in yesterday's data. Realized, of course, that after this report was published, Scattered Spider

1:20.9

likely learned about this and may have changed some of their patterns. So I took this also as an opportunity to show a little bit how to use our data here

1:32.2

to find domain names like this.

1:34.9

So we offer a recent domain feed.

1:38.1

That reason domain feed does allow you to essentially look for domains registered on a certain

1:44.0

date or really domains be found on that particular date.

1:48.6

Sometimes, depending on how we find them, it's a little bit delayed.

1:52.5

And in this case, well, I then basically was just searching for this particular pattern like Helpdesk.

...

Transcript will be available on the free plan in 10 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.