Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Andrew Brandt

πŸ‘€ Speaker
451 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
174: Pacific Rim

and process lists and they're trying to build out the capabilities to be stealthy.

Darknet Diaries
174: Pacific Rim

It's maybe distracting them from building custom malware or developing new exploits, but they have to spend a little bit of energy on, you know, it puts them on the back foot.

Darknet Diaries
174: Pacific Rim

And for the first time, I think this is like one of the cases where you can say, yeah, there were some challenges and we had some bad days early on, but we're forcing the threat actors to have to make moves to counter us.

Darknet Diaries
174: Pacific Rim

And actually, that feels pretty good.

Darknet Diaries
174: Pacific Rim

So libsofos was the very custom...

Darknet Diaries
174: Pacific Rim

Rootkit, it was able to, and again, deleting logs, hiding its presence on the machine, trying to do everything as stealthy as possible, low volume of outbound communication, and persistence.

Darknet Diaries
174: Pacific Rim

They're experimenting with everything.

Darknet Diaries
174: Pacific Rim

And the

Darknet Diaries
174: Pacific Rim

It seems to me that the threat actors have been given carte blanche to just try and experiment with all sorts of different things.

Darknet Diaries
174: Pacific Rim

So during this period from late 2020 to the end of 2022, we're seeing a huge variety of different payloads, of exploits.

Darknet Diaries
174: Pacific Rim

It's bad.

Darknet Diaries
174: Pacific Rim

It's bad out there.

Darknet Diaries
174: Pacific Rim

It's kind of like the Wild West and you never know where something's going to come from.

Darknet Diaries
174: Pacific Rim

You know, if you can get a boot kit into the Eufy BIOS of a device, there's nothing that you can do in the user land of the operating system

Darknet Diaries
174: Pacific Rim

to remove it because it's running at a level beyond which the operating system cannot reach.

Darknet Diaries
174: Pacific Rim

This was actually kind of scary to find this experimentation happening on one of the Threat Actor devices.

Darknet Diaries
174: Pacific Rim

They were really trying to figure out if they could

Darknet Diaries
174: Pacific Rim

get this boot kit to run on a firewall.

Darknet Diaries
174: Pacific Rim

And they ended up bricking the firewall.

Darknet Diaries
174: Pacific Rim

It didn't work.