Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Andrew Brandt

πŸ‘€ Speaker
451 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
174: Pacific Rim

So I get called in and have to, you know, decode how the whole attack works and do another flowchart similar to what we did with Asnarok to do the Baja attack.

Darknet Diaries
174: Pacific Rim

Well, you know, one of the things that we can do, so you've got this telemetry tool that you can do basically wide-scale threat hunting within the firewalls themselves.

Darknet Diaries
174: Pacific Rim

And so you can do things like, okay, well, we recovered a piece of malware off of the very first machine that belonged to a customer,

Darknet Diaries
174: Pacific Rim

let's see where else this malware exists on the universe of firewalls that are out there.

Darknet Diaries
174: Pacific Rim

And that was how they found T-Stark.

Darknet Diaries
174: Pacific Rim

So T-Stark's firewall was the first one where they

Darknet Diaries
174: Pacific Rim

they found a copy of not just the same malware, but like the binary identical, like the actual same file on this guy's firewall.

Darknet Diaries
174: Pacific Rim

And he had been there for two months.

Darknet Diaries
174: Pacific Rim

So he'd been experimenting with this piece of malware.

Darknet Diaries
174: Pacific Rim

While the Azeroth attack was happening, he was basically planning the next one.

Darknet Diaries
174: Pacific Rim

Like in the middle of us dealing with the aftermath, they were already developing the exploit and building out the payload for that attack.

Darknet Diaries
174: Pacific Rim

And then the other thing that was really interesting was that we found a bunch of other stuff on this T-Star guy's firewall.

Darknet Diaries
174: Pacific Rim

His firewall had a bunch of malware on it that was designed to run on the Mac and on iOS, on iPads and iPhones.

Darknet Diaries
174: Pacific Rim

And there is no conceivable reason why there would be like a Mac executable on a inside of a Sophos firewall.

Darknet Diaries
174: Pacific Rim

There's no reason for that.

Darknet Diaries
174: Pacific Rim

So that was an interesting find.

Darknet Diaries
174: Pacific Rim

And we didn't really understand what that was being used for, why that was there, until much later.

Darknet Diaries
174: Pacific Rim

Yeah, what was that?

Darknet Diaries
174: Pacific Rim

So this all happened in June.

Darknet Diaries
174: Pacific Rim

Starting around August, September, Sophos had started to communicate with other companies in the field, some of whom did...