SANS Stormcast Thursday, February 5th, 2026: Malicious Scripts; Synectix Vuln; Google Chrome; Google Looker;
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 5 February 2026
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, February 5th, 2026 edition of the Sands Internet Storm Center's Stormcast. |
| 0:12.3 | My name is Johannes Ulrich, recording today from Jacksonville, Florida. |
| 0:17.4 | And this episode is brought you by the Sands.edu credit certificate program in penetration testing and ethical hacking. |
| 0:24.6 | When you're dealing with incident like you find an infected system, the problem, probably the hardest thing in instant response is always figuring out if you found everything that's wrong with the system. |
| 0:36.4 | And let's have a little example here that Xavier posted about today. |
| 0:40.7 | Initially this looked, well, like an info stealer that is injected into Chrome |
| 0:45.5 | in order to steal data. |
| 0:47.9 | So nothing really all that fancy. |
| 0:50.0 | And this is where someone may have stopped investigating, |
| 0:53.4 | but not so Xavier. |
| 0:56.1 | Xavier dove deeper into the script |
| 0:59.3 | and found that at the end, |
| 1:01.1 | it actually then downloads another image. |
| 1:04.3 | Now, this image is at first sight, a legitimate image. |
| 1:08.1 | It looks like sort of one of those wallpapers for fans of MSI motherboards, I guess. |
| 1:15.9 | But it does have additional code added at the end. |
| 1:21.3 | And that then installs, well, more malware. |
| 1:24.8 | So after the initial malware runs and keeps running, it then installs X-Worm as the |
| 1:31.0 | additional payload. The other reason why this sometimes happens is just in case antivirus would catch |
| 1:36.8 | the first part. Well, maybe the second makes it through, so that's also one reason. Why an attacker |
| 1:42.0 | may do that? In this case, I think it's probably more that they will try to get more out of the system. |
| 1:47.4 | And adding a couple lines to the existing script was sort of an easy way to expand the capabilities of their malware. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

