Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Andrew Brandt

πŸ‘€ Speaker
451 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
174: Pacific Rim

They kludged together something that got around that hotfix.

Darknet Diaries
174: Pacific Rim

The team starts to realize, okay, we need to give these things names because if we're going to be having these

Darknet Diaries
174: Pacific Rim

Attacks happen in sequence, in short order.

Darknet Diaries
174: Pacific Rim

To just keep straight, we need to come up with names.

Darknet Diaries
174: Pacific Rim

So they decide to use the names of locations around the Pacific Rim as the code names for these internal attacks.

Darknet Diaries
174: Pacific Rim

So they give this attack a nickname Baja.

Darknet Diaries
174: Pacific Rim

It doesn't have anything to do with Mexico.

Darknet Diaries
174: Pacific Rim

It's just they just decided that they want to talk about it in the sense of, you know, it's on the Pacific Rim.

Darknet Diaries
174: Pacific Rim

which is a region of the world where volcanoes and earthquakes happen, right?

Darknet Diaries
174: Pacific Rim

So it's a place of turmoil.

Darknet Diaries
174: Pacific Rim

So what the threat actors figured out when they were doing the development of this Baja attack is they watched Sophos and they watched how the hotfix mechanism worked.

Darknet Diaries
174: Pacific Rim

And they learned how to...

Darknet Diaries
174: Pacific Rim

develop a new exploit, but also they started to develop technology and technique to get around hotfixes.

Darknet Diaries
174: Pacific Rim

So they figured out how hotfixes were being deployed on firewalls, and they were slowly starting to turn off features inside the firewall that allow the hotfixes to launch and run and do their fixing.

Darknet Diaries
174: Pacific Rim

Now, this time they're putting just regular old web shells on the firewalls.

Darknet Diaries
174: Pacific Rim

They start looking back in time at the telemetry that they collected and they discover that this was another bug that someone had submitted a bug bounty for and gotten payout on.

Darknet Diaries
174: Pacific Rim

And here it is being used in the wild, like just days after the payout happens.

Darknet Diaries
174: Pacific Rim

So this is starting to get to be a pattern.

Darknet Diaries
174: Pacific Rim

And the attacks are, you know, widespread.

Darknet Diaries
174: Pacific Rim

People are, you know, getting noticed about it.