
Wait Just an InfoSec · 2024-01-24 · 49 min
Key moments - from our scoring
Substance score
53 / 100
Five dimensions, 20 points each
The Wait Just An Infosec episode examines evolving ransomware tactics for 2024 through discussions with SANS instructor Mary DeGrazia and threat researcher Ann Pham (Russian Panda from Ecentire). The conversation centers on how stealers - malware designed to exfiltrate credentials and sensitive data - have become the preferred initial access mechanism for ransomware operations, replacing the nuisance-level commodity malware of the 2012-2015 era. Stealers are now commoditized and sold via Telegram bots and dark web forums for as little as $3-10 per compromised account, lowering the technical barrier for threat actors. AI is identified as a force multiplier for social engineering, enabling attackers to generate convincing phishing emails and deepfake voice calls using minimal training data. MFA bypass via SIM swapping is highlighted as an emerging threat, particularly when organizations rely on SMS-based authentication. The hosts and guests stress that drive-by downloads exploiting user error - including malicious Google Ads - remain highly effective delivery mechanisms, often bypassing detection until sensitive data like browser-stored credentials and network documentation have been exfiltrated from tools like Confluence.
A stealer is malware focused on exfiltrating sensitive data like passwords, cookies, and credentials from infected machines rather than disrupting systems. Stealers are often sold on dark web marketplaces for $3-10 per compromised account, and their stolen credentials frequently serve as initial access for ransomware attacks.
Stealers are sold via Telegram bots, dark web forums, and hacking forums where buyers can automate purchases with cryptocurrency. Stealer developers typically retain backdoor access to victim panels, meaning they can see and resell the same stolen credentials to multiple buyers regardless of exclusivity claims.
Stealers are primarily delivered through drive-by downloads and social engineering, often via malicious Google Ads that replicate legitimate installer pages. Users inadvertently download bundled malware while appearing to install legitimate software like Zoom, with the malware running silently in the background.
Use dedicated password managers like LastPass or 1Password that aren't tied to the browser, reference credentials from a phone app without storing them in the browser, or use paper-based storage for highly sensitive passwords - all prevent automatic theft via stealer malware.
AI can be trained on publicly available data to generate convincing phishing emails mimicking specific individuals, and voice synthesis requires only 10 seconds of audio to create deepfakes for vishing attacks, significantly lowering the technical skill required for social engineering campaigns.
Our reviewer’s read on each dimension, with quotes from the episode.
The Ann segment delivers genuine technical value on stealer mechanics, the Google cookie-refresh API abuse, and the competitive stealer-developer ecosystem, but these insights are diluted by a rambling poll segment, conference plugs, generic closing advice, and a second segment (Brian/Phil) that offers little beyond long-standing network-segmentation platitudes. Net density is moderate at best.
the stealers have the backdoor installed, so whenever uh, the buyer receives the locks, the steel developer would get the locks as well. Which means they might as well sell it to someone else
once you fetch the API to the Google server and they give you the fresh cookies for the machine... it gives you the fresh cookies so it never expires. Uh, it means that the attackers always have the access to the user's uh, Google accounts
The AI-phishing angle is thoroughly recycled by 2024, and most predictions (SIM swapping, SEO poisoning, MDM gaps) are industry-standard. The genuinely fresh material - stealer developers forming revenue-sharing arrangements, the cookie-refresher becoming a competitive differentiator among stealer families - is interesting but buried and brief.
Meta Steeler stole like not stole the code but copy pasted the code from redline... I'm pretty uh, sure that you know, Meta Stealer gives up like uh, um, some percentage of their profit to Redline developer for example because they're using their code
you can see how competitive the steel market is actually
Ann (Russian Panda) is a genuine practitioner doing hands-on stealer reverse engineering at eSentire, lending real credibility; however the other contributors (Mary DeGrazia, Phil Hagan, Brian Ventura) are primarily SANS instructors speaking in educator mode rather than operators running security programs at scale, which caps the overall caliber.
she is a threat researcher with Ecentire and I have been following her work for a number of years now. She does some amazing blog articles. She does a lot of documentation of her reverse engineering
I am a SANS instructor and the course author for our network forensic course, uh, forensics 572
The episode provides concrete price ranges for stealer logs, named malware families with behavioral distinctions, a specific attribution case (Lapsus$/Uber 2022 via Group-IB's zip-marker methodology), and a real VirusTotal detection-rate anecdote - all above average for the genre - though the Brian/Phil segment contributes almost no concrete evidence.
they usually pay like from $3 to 10 uh, dollars per lock for example for like the uh, fresh cookie that it's working for valid credentials
VPN logs for sale, RDP logs for sale. And they're usually ranging up from like from $3,000 up to like $10,000
The host sets up questions competently and Mary lands one genuinely probing follow-up about log resale exclusivity that draws out useful information, but there is no meaningful pushback on any claim, several questions are essentially definitional softballs, and the Brian/Phil segment is barely a dialogue at all.
does a threat actor only sell that, you know, those logs to one person?... Or you know, can they sell those logs like 2, 300, you know, 400 people and they're just being passed around everywhere
Ann, predictions in terms of uh, Steelers being used even more so and initial access brokers, uh, first and foremost, let's just get this out there. What is a stealer?
Computed from the transcript - who did the talking, and the words that came up most.
With the continuous evolution of ransomware and its pervasive risks to organizations’ very existence, new threats can be difficult to predict. That’s why, in this newest episode of Wait Just an Infosec, SANS Certified Instructors and leading ransomware authorities, Ryan Chapman and Mari DeGrazia are joined by guest Ann Pham, to break down what they see as the most important ransomware threats of 2024 and provide predictions about the evolving threat landscape. Wait Just an Infosec is
Transcribed and scored by The B2B Podcast Index.
Speaker A: Foreign M this is the Wait Just An Infosec Podcast your weekly opportunity to tap into the minds of some of the world's foremost cybersecurity experts. Wait Just an Infosec is a weekly show live streamed on SANS Institute social media channels on Tuesdays at 10am Eastern Time. The show features a wide range of guests from from across the infosec community. Whether we're diving into the weeds of the latest data breach or exploring the security implications of groundbreaking technology such as generative AI, each episode brings you new insight to keep you engaged in the industry, feed your fire for knowledge and amplify your value as an infosec practitioner. Join the science community and gain free access to cutting edge industry news, cybersecurity resources like technical research and tools that can be found elsewhere. Subscribe for free today@, uh, sans.org join we are now going to introduce the Question of the Week. So we use a platform called Slido S L I D O dot com. You can grab the QR code with your camera that you see on the screen here, or you can Simply, go to slido.com and enter number 244-8590. And the question is, which security product do you believe will serve as the most effective deterrent for malware, slash ransomware in 2024? So if you're sitting there thinking, well, EDR, EDR is going to do it. You know, XDR is going to do it. Epp, endpoint protection platforms, or just general av. If any of you out there want to put Windows Defender, don't do that by the way. Don't make that prediction by the way, uh, whatever you think it might be. Oh, I love seeing MDR up there. I work for a managed threat hunting team and we work alongside our mdr. So, um, that also reminds me that maybe one of your answers could be hunting, right? Like hunting active hunting sessions. And by the way, if you're not running hunting sessions at work, you should maybe look into that. Um, so we'll be covering these answers when we come back, uh, when we pull in our feature segment. But I just want to get some folks to throw in some of uh, your answers. We're going to pull our guests onto the screen in a matter of moments here and then we'll kind of COVID these. And I see the one on the screen right now. None of them. It doesn't work that way. You made me chuckle. You got me on that one. Okay, so we're going to pull, uh, some folks onto the screen here. We're going to Bring in first up, my CO host, Mary DeGrazia.
Speaker B: Hello. How are you?
Speaker C: Hey.
Speaker A: Hey. It's good to see you.
Speaker B: Good to see you too.
Speaker A: For anyone who's not aware, and if you're not, shame on you. Mary is one of our instructors at SANS for Forensics 500 and a number of other courses. And she and I go. I guess I would say we go back now. It's been a number of years.
Speaker B: I think we do get to count it is that if it's I think over three years. Right. You say we, we go back.
Speaker A: Yeah.
Speaker B: At least works for sure.
Speaker A: So, uh, Mary, how you doing? Uh, what are your, what's your primary number one prediction for 2024 and ransomware? What do you think?
Speaker B: Okay, I know it sounds cliche, but this is something near and dear to my heart because it's also a side project I like to work with a lot is generative, uh, AI. Right. I've been working with local language models, building them, uh, in my spare time and kind of seeing the power that they can really harness. I mean, not only are they fun to use, but you can train them on individual data sets, you can give them personality. And I think we're really going to see these starting to be leveraged. I use AI to help me generate cod. So now we are lowering that barrier for threat actors having technical capabilities, we're going to see them use this to craft really good phishing emails. Historically in the past, when we look at phishing emails, we maybe look for something where maybe English isn't their first language or the grammar or the punctuation is off. Now they can use AI to help them generate things like phishing emails and you can load up your own data set. So for instance, if I'm interested in replicating maybe a CEO of a company, I can go find places where they've made blog posts and press releases and written articles. I can load that into an AI and then say, hey, generate me an email that sounds like it, uh, comes from this particular person. So I think AI is really going to start playing a huge role on this and we're going to be seeing it used a lot of, uh, when it comes to ransomware.
Speaker A: I agree with you, unfortunately. Unfortunately, I agree with you on that. Um, we saw a number of leaks of, for example, builders and source code for ransomware. And when those came out, we saw this proliferation of these random groups, groups that before didn't exist. And it's because they were given tooling and when they had access to that tooling, they Utilized that tooling and did ugly dirty things. And AI is just this massive tool set that's going to lead to some wonky stuff. And um, hope everyone's prepared for that.
Speaker B: Absolutely.
Speaker A: Okay, we're going to bring our special guest onto the screen now. Everyone please welcome an PHAM, aka Russian Panda or ANFAM17. And how you doing today? Oh, I think you're muted.
Speaker D: Sorry everyone. Um, how are you guys doing today?
Speaker A: We are good. Our uh, our weather is not super hot like I said at the beginning of the show, and I think that I'm hyper focused on that. I love the rain. I love just not being in freezing, uh, temperatures. Also, for anyone who's not introduced yet to Ann, she goes by Russian Panda and has a website, Russianpanda.com. she is a threat researcher with Ecentire and I have been following her work for a number of years now. She does some amazing blog articles. She does a lot of documentation of her reverse engineering and that's why it near and dear to my heart as a former Forensics 610 instructor. Just extremely excited to have you on the show. Thank you for coming.
Speaker D: Thank you so much for having me.
Speaker A: Uh, let's pop up the question of the week and see what kind of word cloud we've got generated here. Look at that. DMARC actually has a pretty, uh, big lead on this. I don't see DMARC implemented a whole lot within organizations. I'm actually glad to see that because a lot of folks don't require it. They might implement it and there might be something in the headers, but we don't see it used a whole lot. Um, let's see. Deception is in here. Mary, what do you, what do you think about deception? Have you, you seen it work well leading up to 2024?
Speaker C: Yeah.
Speaker B: You know, I think with um, a lot of these, you know, we're talking about specific tools, but um, you know, some people are like, oh, none of them, it doesn't work anyways. I feel kind of like it comes down to the end user a lot of times. Right. A lot of these tools require some type of interaction from somebody at some point in time. Either being trained on the tool, responding to it, alerting to it. Um, you know, the tabletop test, somebody ment hear. You know, a lot of times when we work cases, uh, you know, you think that you have a plan and then when things go south, you know, following that plan is totally, uh, kind of falls apart sometimes. Or the one person that you rely on is on, on vacation. Right. And not sure what the steps are next. So I'm loving a lot of these comments that are popping up. They're making me chuckle a little bit.
Speaker A: A lot of this is focused on the end user.
Speaker D: Mhm.
Speaker A: Quite a bit of it actually. Including just anti phishing. Um, I don't know if anyone else sees the word scissors on the screen. I assume that means just cut the cable. That's how you prevent these things. Uh, another one that's prominent on here is EDR MDR XDR is on here. For anyone not aware, EDR is endpoint Detection and Response and you know, working as a consultant and coming into an organization. If they don't have EDR within the environment, our visibility is just so darn limited. Um, and you've done a number of uh, quite a bit of research. Got some echo there going. We'll fix that with uh, malware. And are you seeing in some of the Steelers you've been looking at some of the malware you've been looking at some like anti EDR XDR stuff. I saw that in one of your articles recently.
Speaker D: Oh yes, um, definitely. Um, so uh, some of the stealers do brag about having EDR bypass, but uh, usually um, it's not how it works. They usually have these features in their stealers embedded to pump the file size. It just bypasses the av, but it does not fully bypass edr. Um, unfortunately stealers can be fast enough to infiltrate uh, and exfiltrate your data that by the time like EDR jumps on the host, um, the threat actors might partially get the logs right. It might not be your, like, it might not be your browsing data but it might be your um, you know, the sensitive files that they exfiltrate. So it's a pretty quick uh, doing the job. And sometimes unfortunately like edr, uh, does not catch that. So yeah, but do uh, not believe all the stealers that says we like bypassed EDR. Um, maybe AVs, but definitely not EDRs.
Speaker A: At least Windows Defender Real Time Protection. We see that disabled in every single case. Just about. Um, we're going to continue the trend here with some predictions. I'm going to give my predictions for ransomware and then we're going to kick it over to Ann because we're going to be talking about Steelers, which spoiler alert. We believe Steelers are going to continue to increase in number. So for me I think that uh, we're going to see a lot more SMS phishing or smishing and we're going to see quite a bit More MFA Multi Factor Authentication bypass via SIM swapping. And the reason I say that is that there's one group that I think I've mentioned them on a number of these episodes now scattered, um, Spider. They also go by a number of other names like Muddled Libra and some others out there. They're a prominent group in the sim swapping arena and they are able to get into large organizations by exploiting the fact that many of us, many. And ask yourself, do we do this? And you'll be like, oh, we do do that. Use SMS for your mfa. In other words, when you sign into whatever system that's MFA M enabled, you get a text message and that text message then allows you to enter in whatever code or say yes or no or whatnot. So sim swapping for anyone not familiar, is basically the act of moving a phone account from one SIM card to another or essentially moving the control of the uh, actual mobile account from a phone that the end user controls and owns their phone to one the threat actor holds. And there's a very large, a vast network of folks who are using that as an initial entry vector. And I'm seeing that increase. And speaking of phones and smishing, a lot of people don't have, um. What's the word I want? Uh, I m. Can't think of the word right now. The mdm, excuse me, Mobile Device Management. And they're using byod. Bring your own device policies where people just, you know, pull a phone out of a drawer, ah, like last year's phone or something and say, oh, I'll just use this for my work phone. And the links that are being sent there, the links that are being clicked from there, the things that are, you know, interactions and messaging and even calls these days. And hey, Mary, we got to worry about AI being driven for these voice based, you know, vishing, I guess technically voice vishing, uh, it's not under the purview of the organization and because of that we're kind of blind to a lot of these attacks and I think that's not a good thing. So, uh, Mary, any comments on MFA bypass with SIM swapping or smishing? Are you seeing an increase of that? Are you worried about that?
Speaker B: Yeah, I think you made a lot of great points especially I'll go back to the AI aspect of it. You know, you can train a voice with, with 10 seconds of audio basically and uh, you know, get some, yeah, some pretty convincing things. And this is just, you know, on your little computer at home, you don't need a lot of processing power to do it. It's uh, a very powerful technique we're going to see moving forward.
Speaker A: Oh, I only got nine seconds here boys.
Speaker B: Was that my countdown?
Speaker A: Yeah, well we'll get, we got 10 over the episode. All right, so um, Ann, predictions in terms of uh, Steelers being used even more so and initial access brokers, uh, first and foremost, let's just get this out there. What is a stealer?
Speaker D: Um, so a stealer is um, quite self explanatory term, right? Um, ah, uh, unlike the disruptive malware types such as ransomware stealers, um, the focus is on exfiltrating the data from sensitive uh, from the host from the infected machines. Um and uh, their goal is to steal, right? The goal is financial gain. Um, so um, yes, uh, like uh, the stealers get on the machines, they steal locks and uh, usually those locks are being sold on dark web, right? Being sold on Telegram because there are multiple groups looking for um, like certain type of locks, like YouTube blocks, LinkedIn locks, Facebook locks. And they usually pay like from $3 to 10 uh, dollars per lock for example for like the uh, fresh cookie that it's working for valid credentials. Um, and those locks can be um, very easily monetized I think. And which kind of leads to the uh, proliferation of stealers nowadays. Uh, as well as uh, the part that the democratization of Steelers in the market nowadays also like promotes the increase of I think of Steelers. Because you uh, see um, Steelers getting uh, sold on like hacking forums on Telegram, even via Telegram bots, right? So the uh, buyer does not have to like directly interact with the seller. They just can like send the crypto coin to the bot and it um, fetches back the zip archive with the panel, um, with the Steeler panel and the manual of how to use the stealer. So even the cybercriminal uh, with limited technical skill set can deploy the stealer and run it. Right? Um, they even have the support people who would help you out with how to deploy the stealer ready to go. So with the uh, right resources in your hands you can easily uh, deploy the stealer even for someone who's not technical enough. So it definitely became um, uh like one of the main reasons why the increase of Steelers.
Speaker A: I remember back in like 2012, 2013 when if you had a banking Trojan in your environment it was like whatever, like that's fine, it's just impacting the one user. We'll let them know, hey, whatever passwords you had stored or you were using, you're going to need to remediate those. And it was just like, close, uh, the ticket out in the security operations center and kind of move on with life. Rebuild that one machine and just move on with life. And now, I mean, moving into 2016, 17, 18, if you saw something like Imitate, which used to be just Considered, or Hansiter, or something like that, which is, oh, they're just a banking Trojans, it's no big deal. Right? Um, all of a sudden, they became one of the preferred initial infection vectors for ransomware. And then you move along to proper stealers that literally just steal every possible darn credential that they can from the computer. Uh, I think one important point to make is that please, please, please, please, please don't allow you, yourself or your users to store passwords in your browsers. Like, directly in your browser. When Chrome or Firefox just says, hey, do you want to store that password? And you're like, yeah, no, don't do that. Because there's a lot of malware out there that will just rip that off so easily. Not even malware, just system utilities. Um, NearSoft has been out since the early 2000s or maybe even before that in the 90s, I don't know. And it just easily retrieves those passwords. But Steelers are specially formulated to steal that data, and we're seeing a lot, a lot more of them. Uh, Mary, do you have experience with stealers? You've seen a lot of organizations fall victim to them?
Speaker B: Yeah, and I think that's one of the. And just like you said, I remember when we first started doing these investigations, when we would come across that, that wasn't what we were really looking for. Looking for the threat actor moving laterally within the environment, detonating the ransomware. And when we saw that more the commodity malware, if you will, like the Steelers, it was like, oh, well, we'll just have to let that employee know that their banking account information was compromised. And now it's just been a total shift to being really valuable data and mechanisms that the threat actors are using. You know, they'll pull those browser passwords, and they'll log into online resources that the company uses. I think there was a mention of Confluence earlier. So they. I've seen them, you know, pull those passwords, get into something like Confluence, and then there they find all the documentation for the client, you know, all the network passwords and all the repositories and everything that belong there. One, um, question I did have for Ann, you mentioned that these are for sale on the you know, the Dark web. Now, does a threat actor only sell that, you know, those logs to one person? And then they're like, okay, I sold that set of logs or are they, you know, is it more valuable if they only sell it to one person? Or you know, can they sell those logs like 2, 300, you know, 400 people and they're just being passed around everywhere. I'm just kind of curious if you know a little bit about that.
Speaker D: That's a very good question. Thank you for asking. Um, so, um, we live in the generation like we cannot trust anyone, right? And especially the threat actors. Uh, that's why it led to like uh, the threat actor developing their own stealers because they don't trust the other stealer developers. And I've seen uh, quite a lot of times when like the stealers have the backdoor installed, so whenever uh, the buyer receives the locks, the steel developer would get the locks as well. Which means they might as well sell it to someone else, you know, and into multiple hands. So it can just not. They tell you that you like it's unique logs, you only receive it and they don't have access to the panels. But it's um, actually not true because the stealer developers have the full access to the panel and they see all your logs. So they might as well also monetize that.
Speaker A: Speaking of the password show up in the logs. We have a question in the chat and there's a number of questions. We're going to need to get to some of these and one of them is what is plan B if they can't store in their browser as in there it is on screen.
Speaker D: I like that.
Speaker A: If the user can't store in the browser, what is the preferred methodology? Who wants to grab that one?
Speaker B: I'll take that. There are a couple of different ways you can do that. Um, there are various programs out there that you can use. Although some of them have browser plugins, something like LastPass or 1Password using something like that that's not tied to the actual browser. Um, you mentioned some nearsoft tools earlier. It's very trivial to dump out all your passwords from browsers when you use a third party program like that to do it. Another thing you can do too is you can use an app on your phone, let's say, and um, actually go old school. Uh, look at the app on your phone and then when you're in your browser, you type it in your browser. So it's not even kind of in the same playground as those two type of things. Or you know, you can go old school, you can write it down on a piece of paper too if you want to be really safe. Right. Uh, there are a couple of passwords where I actually tend to do that to keep it written down because then, you know, someone has to have physical access to my house in my notepad in order to see those. So that might be your plan C right there.
Speaker A: There's a number of, I guess I'll say, malware families out there that attempt to attack password managers themselves. There is that general concern when you store them in the cloud especially. There's also, for example just some open source ones on GitHub, um, that allow you to store it privately, not in the cloud. Those are some of the ones that I tend to prefer. Of course, when you're moving from computer to computer to device to device and you're sitting there like, oh, it's on that computer over there, then you know, you got that issue. Um, but um, let me see, I'm going to grab another um, question from the chat. Um, here's a good one. The malware steelers need a vulnerability to work or just the user to trust, add it to the computer or both. So and you want to feel that do they need some type of vulnerability or how are these essentially, you know, working?
Speaker D: So speaking of how efficient the stealers are, right, We've seen um, a lot of clients are getting infected with stealers and usually the initial access is drive by downloads. So uh, the threat actors just exploit human errors, right? It's very efficient. You might like, you might not, uh, you might, cannot, cannot imagine that. But for example, Bob just got a new laptop, right? He decides like he's late on a meeting and he decides to install the Zoom. He Google is the Zoom installer, search for it and what is the first link, right? It's Google Ads. And you would not spend time like the second thought of like going to another link and just, you know, you click on the first one. And um, yeah, usually they're very efficient because um, the threat actors reproduces the page to look exactly like the Zoom installer or any other kind of installers. So um, the uh, non technical user or less technical user would just you know, run the bundled malicious file that has a stealer in it and it gives you a decoy installer. So you install the Zoom for example and you see, oh, like uh, I just downloaded legitimate software and it's stalling Zoom. But uh, in the background you know, this dealer is making connections to already to Russia or anywhere else. Right. So um, yeah, usually they use a lot of social engineering tactics rather than vulnerabilities.
Speaker B: And I just wanted to hit on something you said there. Um, you mentioned Google Ads. So are you saying that, you know, uh, we run our keyword searches in Google, we get some ads that there can be malicious, like you know, we would want to think that it's safe, right? You figure they're paying for advertising. Are you saying that threat actors are leveraging Google Ads in order to do this type of thing?
Speaker D: Yes, they actually do. Uh, uh, it's uh, as sad as it sounds like, right, because usually um, you know, you might think like Google Ads is totally legitimate service, but uh, it's been abused by a lot of threat actors. And you can see in the headlines nowadays like um, malvertizing, drive by downloads, delivering dark game malware, pick a bot malware, all kind of malware. So it's very efficient. It's proven to be very efficient. And uh, like I mentioned before, we've seen a lot of clients are getting infected through mostly like drive by downloads. And that's like probably the first thing that we're looking for, right? Like where did they go to like uh, the browsing data, like what website they visited. So that triggered the malware.
Speaker A: That's as a threat hunter, I hunt through networks. That's what I do basically now on a day to day basis. On a recent case I was looking for things that were running out of app data. Basically the app data folder, um, for anyone not familiar, it's going to be the C drive, the user directory, app data, and then typically roaming, uh, which is part of the roaming profile, excuse me, I'm not sure what the other word was. And I was just looking for things executing out of there. And it's kind of funny because communication apps like Slack and Teams and you name them, they typically install their binaries there. Um, and we're looking for threat actor stuff, malware stuff in there. But in doing a threat hunt around that I've found a number of Zoom, Slack teams installations that trigger malware alerts and you're like wait a minute, I thought, but that's just zoom, right? Why is that triggering a malware alert? And then you look at it, you find the hash or however you find it and pivot to it on like virustotal or something like that. And then you see the executing parent, the installer has like a 55 out of 65 detection rate and you're like wait, what, why, why is that so high and you look at it and you go, oh, oh, there's a stealer bundle with that. Like that's not legitimate. So you know, SEO Search Engine optimization poisoning. SEO poisoning is used very often and just again just paying through Google Ads or whatever it is to get your link above the actual link is something you have to be very, very careful for, especially depending on the browser the user is using. Um, also where they're egressing from and where they're connecting in from. I'm like right now I just Google Slack and I don't see a Sponsored Slack at the top. I was going to try to make a point and I think I made an anti point. I just did it for zoom and it looks like it's actually the legit zoom towards the top. But you know, with all these ads that are available for purchase, it uh, it becomes, it becomes a problem. And it's, it's funny because, you know, drive by downloads were seen as a thing of the past. Like exploit kits were rampant, just rampant in 2011, 12, 13, you know, um, a number of them, Angler, Orange Red kit, there were a ton of them and that seemed to have gone away and then now, not gone away fully, but mostly gone away. But then now you still have the worry that you simply run a Google search for what you need or what you want to install and it comes with something wrapped up with it and no good, no good.
Speaker B: And this is where I hate to push the point again, but with AI, there's been some recent articles that have came out that now with AI search, uh, engines are getting less effective and the results that they're giving us just because of the ability for people to manipulate the system by using AI to generate content. So now instead of manual writing up websites, blogs, they can use AI to generate that content, um, and you know, just further facilitate you clicking on the wrong page. You know, Google used to be really good at giving us, you know, what we wanted in the first 10 hits. But now with AI generating content for threat actors and malicious actors, getting higher up in those search results is much easier for them to do because they can just say, hey, generate me a blog post about blah blah blah, or a webpage about blah blah blah, it turns it out for them. And they're often running with some really what we would consider, you know, high level content that's been generated from an AI.
Speaker A: Every time you talk about AI worry me.
Speaker B: You should be worried. I mean it's one of these tools that's going to be, I think, really exciting for all the things that we can do with it. But you know as we know what can be used for good can also be used used for bad. So I think this is going to be an issue moving forward for sure.
Speaker A: So let's, let's put uh a bit of practicality into some of this. And what are some of the steelers that you've analyzed recently? Uh and again who are not aware russianpanda uh.com and we can, we'll get the link on the screen. Is their site um just some fantastic low level reverse engineering There it is. Uh check that out. But uh, go ahead and tell us what are some of the ones you've seen recently and what are some of the trends in them or whatever you want to speak to.
Speaker D: Uh, of course the reason one I analyzed was Atomic Stealer because I grew up using Windows system with uh, people working from home nowadays and bring your own device people are switching to macOS devices. Uh I was very interested to analyze the Atomic Stealer because uh, to see how differently stealers ah operate on Windows and macOS devices is pretty interesting. Um because for the Windows the stealers get on your machine and it can easily grab your uh web data like file logins uh file from the browsing folder and then decrypt it on the server. Whereas uh on macOS the stealer would need to social engineer you for you to input your Mac OS password first to get the access to the keychain file where most of your password are stored. It was interesting to see pop up prompt window like please enter your password like to install this file for example and some people would um uh input the passwords and then the stealer grabs the passwords and uh, it escalates the privileges and uh get uh access to the keychain file. Uh another piece of stealer I also looked at uh is metastealer. Uh it's a copycat version of Redline. That's why when you run the metastealer uh on the sandboxes such as Triage any run and Joseon box right. Uh you see the attribute to Redline but it's actually a metastealer and a lot of like um. I've seen a lot of people like misattributing it to like Redline, uh but it's actually a metastealer and uh, it kind of gave me an idea like you know how uh steel developers are collaborating, cooperating with each other uh in Dark Web right. Or in the cybercrime industry because you would see metasteel Promoting redline, redline, Steeler promoting metasteal. Although like Meta Steeler stole like not stole the code but copy pasted the code from redline. So they're working together and I'm pretty uh, sure that you know, Meta Stealer gives up like uh, um, some percentage of their profit to Redline developer for example because they're using their code. Right? Yeah. So that's uh, what's definitely interesting to see. Uh, and you probably have heard about the um, cookie refresher thing in Google. Uh, once you fetch the API to the Google server and they give you the fresh cookies for the machine, uh, once you get the um, decrypted token for the uh, uh, web data file of the infected machine, you can uh, grab that token, send it uh, via the API to the Google server and it gives you the fresh cookies so it never expires. Uh, it means that the attackers always have the access to the user's uh, Google accounts and still adopted that Steeler, like adopted with that one after another. Like it's um, kind of became a competition between the Steelers you'd say, because like once you have this feature like the others, you're like I want to have this feature too, you know. So they started implementing that. So that was pretty interesting to see. Um, you can see how competitive the steel market is actually. So that's uh, also like another point to bring about the proliferation of Steelers, how they compete between each other. Right. Um, like for example, like Rice Pro Stealer, uh, that uh, recently appeared some of the developers behind Rise Pro where like they are people who work uh, on Private Loader. Private Loader is a paper installed downloader, so malware downloader which uh, you know, you pay them and they distribute your stealers so through like all different kind of services like YouTube traffic, uh, you know, like Google Ads traffic and you know like Rice Pro, uh, those Rice Pro developers, like they saw the um, flaws that were implemented, uh, like in Raccoon, Steeler, Vitar, Steeler or any other Steelers that were all mashed up in the traffic and they decided to develop their own stealer. Like we try to be better than any other stealers so we're going to make our own. And they advertise it as like our stealer is like better than the other ones because we've seen mistakes from all the other stealers based on our like private loader service that we provided. So that's um, yeah, that's pretty interesting to see that competition going on. Sorry I went on the rant here.
Speaker A: No no, that's what you want. That's fantastic. Um, I think we would be remiss, not to mention initial access brokers or IABs. So for anyone who's not familiar, there's a, a sector, I guess, of the, uh, the threat actor genre, whatever word I want to use there, that, uh, they specifically try to get into networks. And there's a link on the screen there, right there, a shortened link. It's, uh, for528.com IAB and there's just a wonderful, and I mean fantastic, um, graphic or image that you can check out there.
Speaker B: It's pretty large.
Speaker A: You'll have to, like, zoom in and scroll around. And it essentially just shows you the IAB landscape and essentially how they do their thing. So many ransomware actors are purchasing access to their victim environments via these IABs. So the initial access brokers, that's what they do. They get in and then they broker that access to others. They say, hey, what do you want to get into? I have a number of environments. Do you want to get in via the VPN or RDP or whatever it might be? And then they sell that, and then that access oftentimes is facilitated through stealers and stealer logs. For anyone wondering, as Anne was talking about the logs, when you go into some of these Darknet marketplaces, which is just connecting to a Tor circuit, typically via the Tor browser, right? And then just going to one of the forums, when you go to some of those and you look at some of the stealer logs that they have for sale, they will often sell them from the individual victims. As in, like, they won't sell this big, massive list of stolen log that they call them Steeler logs. But it's just basically like a web address, username and a password and just a list of them down the line. Basically, they sell them individually. And you'll see in there, sometimes it'll be like, VPN company name, and you're like, ooh, wait a minute, that's not good. Um, and other times you'll see just like, oh, it's just their medical provider. Or you'll see social media sites or what have you. And these IABs are utilizing Steelers. And it's actually in the image. If you go check it out at the iab, um, site. And are you seeing an increase in IEB activity related to Steelers? Do you think there's more people that outside the IEB landscape who are getting their hands on them? What are your thoughts on that?
Speaker D: Definitely, um, the good point you brought up about, like, um, Market selling the locks, right? So uh, when you even go to like exploit forums or any other hacking forums, you see sometimes posts about like uh, people posting, hey, there are like VPN logs for sale, RDP logs for sale. And they're usually ranging up from like from $3,000 up to like $10,000. It depends on the list, like the revenue of the company, the list, like how many people are working in the company, the list location of the company. And you would see like within a day or like a week those locks are getting sold completely. Right. Uh, some people definitely have the resources to buy those locks because they're quite expensive and usually it's initial access brokers or even ransomware threat actors. Right? Because they have the resources, they have the capabilities uh, to purchase that. Um, and definitely uh, like for example you go on the Russian market, you see like tons of, tons of locks are getting sold and you can always like you know, search for specific locks that you want. And usually when we have the compromise within our clients environment, whether it's like an exploit, whether it's like VPN RDP access, we always look for like if the client's logs has been exposed anywhere online, if the loss was sold anywhere. Right. So you probably have heard about the lapses case with uber breach in 2022 and uh, um actually uh, group IB did some research on it. Right. By looking at the screenshots they took, uh, they saw like uh, the zip files that have like these specific markers and they look into those markers like for example 1, 2, 3, 4, like slash, not zip. Right. They could identify uh, that it was whether like uh, it was whether like Vidar Stealer or Raccoon Stealer. So they found that and the logs that uh, were posted contain okta websites for Uber um, employees. And um, so they were speculating that maybe the lapses threat actors use those logs to further pivot into uh, the compromised uh system to get higher privileges. Or it might be the initial access because those locks were sold around the time when the attack happened. It was pretty crazy.
Speaker A: That's extremely interesting. Speaking of interesting, this episode has been very interesting. There are a ton of questions that I'll have to fill some of those bad boys outside of the episode. We're coming to a conclusion of our feature segment. So Ann, do you have anything you'd like folks to check out? Do you have anything coming up that you're you know, you're really excited about? Do you want folks to contact you in any certain way? Like what do you, what do you have as your final, final thoughts here,
Speaker D: um, I just want to say um, uh, um, try to regularly educate the users, do the users trainings. Uh, because we actually ah, really need to rely on users not to get infected with the stealers because it's always good to prevent rather than remediate. So that's uh, the advice I want to give to people or working industries. User awareness training is very important. Uh, yeah. And uh, just follow me on Twitter. Uh, I've been uh, trying to have some free time to work on my research like my personal blog. So I'll be definitely posting more malware analysis content. Especially like working on loaders because nowadays we've been seeing a lot of like loaders, you know, getting uh, published, um, like they're getting really popular. So I'll be working on that.
Speaker A: Oh good, I'm looking forward to that. It was awesome having you on Mary. Do you have anything you want to
Speaker B: leave with, uh, CactusCon. We gotta mention CactusCon, right? Yeah, that's what I'm gonna be up to in February, teaching over in Amsterdam. And then right from there I'm headed to CactusCon to talk a great free conference to go to in the industry. So uh, that's on my plate the next month or so.
Speaker A: Awesome. I love that. For folks who are unaware, Mary and I met through CactusCon many years ago. Um, I ran it for three years. I no longer do. It was, it was too much. I died, back off. So it's uh, near and dear to our hearts. It's right there on the screen. Cactuscon.com check that out. All right, thank both of you, Mary of course for co hosting with me as usual and it was fantastic episode. Thank you so much for hanging out.
Speaker D: Thank you for having me guys. A wonderful day.
Speaker A: All right, much appreciated. So up next we're going to be sharing part two of a four part miniseries from Brian Ventura. Today Brian will be talking with Phil Hagan. I love Phil. On reporting that has come out from the NSA and CISA on red and blue team engagements. Hello.
Speaker E: Uh, my name is Brian Ventura and you may remember me from last week where I talked about the uh, NSA and cisa. Ah, red and blue team sharing the top ten cybersecurity misconfigurations. And I'm continuing that conversation today. So a little bit about me. My name is Brian Ventura and I'm a Sans instructor. I've been in uh, I've been working with Sans for about eight or eight years now and I've been in cybersecurity for about a Decade and it for, ah, well, way too long. You can see the gray hair. Uh, and I, last week I talked about some of the interesting things that are in this document, why you should be interested in it. But today I want to deep dive with Phil, uh, Hagan, another SANS instructor, where he's going to talk about it from his perspective more on the network side. So, Phil, would you like to join me?
Speaker C: Yeah, absolutely. Thanks very much for the opportunity to, uh, chat over this with you, Brian. Um, as you said, my name is Phil Hagan. Uh, I am a SANS instructor and the course author for our network forensic course, uh, forensics 572. And I'm also on the community team at Red Canary, which is an, uh, general EDR type provider with a whole bunch of added cybersecurity capabilities around that. Um, the network forensic side of what I do is actually, I think, really interesting when it comes to some of these points in the NSA CISA doc that you've been talking about. Uh, there's really two that are primarily, I'd say, uniquely suited to network visibility. Uh, the first is their third point, which is that a lot of organizations don't have sufficient network monitoring in place. And this is something that we've been seeing for as long as I've been doing this, which is certainly, uh, quite, uh, some time in terms of incident response work and working with clients that have unfortunately suffered various breaches. Because if we don't have the evidence, if we don't have the data to work from, there's really, it's a lot harder. I won't say there's nothing we can do, but it's a lot harder for us to tell the story about what happened, and especially when it comes to network monitoring on a proactive basis. It brings up this cool concept that I've always been talking about for, uh, quite some time, which builds upon the common theme we're mostly familiar with being that we want to build a defensible network. That's a fairly common phrase that's been around. I think this comment in the CISA document about the internal network security monitoring really brings it into the idea that we need to build what I like to call a forensically ready network. We needed a network environment that's providing us with evidence that we need before we even know that we're going to require it, so that when and if a breach or other incident does occur, we have the evidence to go back on. And I think this really speaks well toward network forensics, because we're talking about an inherently retrospective look at what's in the environment already. This is going to not only aid in the reactive incident response type work, but it's also going to feed into proactive threat hunting. And when we look at the CSA document, they talk about the types of information that would be useful in the types of data points. It's really any kind of artifact of those communications, whether it be protocol artifacts, whether it be netflow data. That's going to just give us a very high level idea of who the main communicators are in a given environment. It's going to give us this excellent baseline that we can use to go back with specific threat intelligence to search for incidents of uh, concern that maybe we didn't know we were looking for at the time or we didn't know we should be looking for at the time because they're informed by that new intelligence. So that opens up the threat hunting opportunity. And then of course we're dealing with incident response work and looking back into the past, it gives us this great, very uh, useful collection of evidence that we can use to kind of shore up our hypotheses that we're getting from our traditional endpoint, uh, based evidence. It's just going to open up the post possibility for uh, for us to kind of tell those stories in a more detailed sense. So I think that's a really important aspect to consider for um, for, for their various points that they put into the, the document. The other one that I think is an interesting one, it actually isn't evidence based, it's more architectural. Um, they talk about the lack of network segmentation and this is something that's been, and we've been beating this drum for decades now where having a flat network is going to afford your adversaries. There's a wonderful opportunity to just run rampant throughout your network because there's no opportunity for controls. This is also one where we've always said, hey, segment your network based on the types of um, business data or mission data that each individual client's going to need to access based on their roles and responsibilities, the sensitivity of the data they're using or the work they're performing. And those are all still very valid points. But what's been really interesting to see is, especially over the past couple of years when we've moved to a more cloud centric or cloud only type environment, obviously our network architectures have changed. How do you, how do you segment a remote workforce? How do you segment a decentralized operation, uh, or a company or an organization and that becomes an interesting challenge too. So whether that's, um, segmentation based on individual access to a physical environment or their virtual remote environment, those same concepts still do apply. And I think having that segmentation is super important because it gives you the opportunity to adjust controls through what I know you're going to be talking about with some of the other guests, uh, later in the series about access controls and configurations. Or I can say, hey, this section of the network is the engineering section. They need access to certain resources or maybe the finance department doesn't. So that's another interesting thing that's long been told. And it's great to see that Cease is kind of continuing to tell these stories and maybe giving a little bit more oomph behind them, whatever the term is you want to use for that, um, to kind of show that, yeah, these really are important. They're things we should be spending our time on.
Speaker B: Yeah.
Speaker E: All right, well, thank you for that. And, um, I do, um, you brought up a good point that I didn't mention. Last, um, section is, uh, this is really tied to threat data out there with the mitre, ATT and CK and such. So, um, no longer is it just a bunch of, uh, people like us saying this is a good idea. I've seen this in the past. This will save you. It's actually backed by actual threat data as well.
Speaker C: Yeah. And the fact that they included that, that those um, uh, techniques in their reporting, I think is going to help everybody to kind of set that common baseline. Whether you're consuming your own information and categorizing it against the, uh, attck, or whether you're using other reporting and such. That's going to help you to kind of see which of those are the most commonly used vectors. Great, great stuff.
Speaker E: All right, well, thank you very much for, uh, having a conversation with us about this. I really appreciate your input. And uh, for the rest of us out there, please stay tuned because our next, um, episode, we're going to talk with Andrew Lehman about, uh, more of this. So how does this apply in a slightly different, uh, aspect? So, uh, stay tuned. Thank you.
Speaker A: Shout out to Brian and Phil for joining us. Much appreciated, fellas. So thank you to everyone, the behind the scenes crew, who I love to work with. Thank you for letting me host another episode. I had a blast. There were a ton of comments on this. Really excited to see that. Looks like we've got some strong numbers and strong participation. So, um, everyone remain vigilant for ransomware. You know, the top three infection vectors are RDP email and software vulnerabilities. Make sure you don't have RDP exposed to the Internet, especially when MFA is not enabled for your email. Make sure you're blocking different attachment types that should not be allowed into your email environment like a ISO file should not be allowed. Why is that happening? Check your email security gateways. Ensure that they are doing what they're designed to do, securing your email. And then for software vulnerabilities, just make sure your patch cycles are as minimal as they can possibly be. If you're not patching for 30 to 60 days out, you're going the wrong way. You want to try to shorten that as much as possible. And I highly implore folks to engage in threat hunting hunt throughout your organizations and if you don't have the ability to do so, look into MDR MTH teams. Says the person who works on an MTH team looking to us, you know, and um, I want to leave everyone with uh, a little. It may not be a surprise at this point, but it's something I'm very excited about and it's that we're releasing the brand new and it took a while to make this bad boy. The Sans ransomware and cyber extortion poster. Ah yes, Cat Headley and myself put that together over a number of months and it is releasing in person at the CTI summit. So if you happen to be going to the CTI summit or if maybe you were wondering if you should go, you should go, then check that out. Um, otherwise when it is released you'll be able to go to sans.org posters, it's right, right there and check that out. Thank you everyone for participating. Thank you to Thomas for doing the news bite segment and of course thank you to Mary and to Ann for joining us. And uh, this is Ryan signing off Once again. Thank you all for joining and make sure to join next week and check us out.
Speaker D: Thank you for listening to the Wait Justin Infosec podcast. Remember to join us live every Tuesday
Speaker B: at uh, 10am Eastern for a new episode of Wait Justin Infosec.
Speaker D: You can watch@sans.org WJA or go to
Speaker B: the SANS LinkedIn or YouTube channels.
Speaker D: The wait Justin Infosec podcast will be released every Wednesday at noon. Thanks for listening, see you next week.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.