Mike Ritland

speaker
855 appearances 6 recordings 1 series first heard Nov 2024 last heard Feb 2025

Mike Ritland’s voice in public audio — every appearance, attributed to the second.

Trend

recordings per month · last 12 months
No recordings in the last 12 months.Older appearances are listed below; set an alert to hear about the next one.

Appearances

newest first · ▶ plays the moment
There's so many ways because in a red team scenario, you don't know what you're up against and you're going to need some options to circumvent a problem. But yeah, still, what does it even do? You're connected to it. But it primarily emulates a keyboard. It says, I'm a keyboard, and it types really fast. So what does that do? Literally anything I could do sitting at the computer at the keyboard.
So whether that's implanting malware or whatever it may be, right? That's kind of the basic functionality of it. But, I mean, it's not it. USB cables can often connect a keyboard to a computer when you're sitting at a desk. Swap out that cable, and this can now intercept the keystrokes, which is really good.
Just like one classic use case is if the machine is locked, I mean, you can type all you want, but you're at a lock screen. You need to get past the lock screen. What do you need to get past the lock screen? You need the password, right? How do you get the password? There's a lot of ways. I mean, you could call up the person and effectively ask them for it by saying, I'm IT or something like that.
But if you're deployed between a keyboard, you can just... pull it right off the lines. They're going to type that password every single time they log into the computer.
You remotely see that, you rebuild a new payload that maybe when they go to lunch in the evening, when you know they're not at the machine anymore, it's just going to type in that password, automatically unlock the machine, and then do all the nefarious things you wanted to at that point.
Yeah, not so much seeing. There's a lot of, it depends, right?
Not at this stage. So at this stage, we're just blindly sending keystrokes in, right? So as long as you know what OS it is or something like that, that's all you need on a desktop. I know if I hit Command Space, it's going to open up Spotlight on a Mac. And then I can open up Chrome and then go to the address bar, do some things, right? For example.
Like that's a very repeatable series of keystrokes. And you can do them really fast once you know it. Just for an example. Okay. All right. So that's the basics of the very core functionality. And then you combine that with keylogging and suddenly... You're getting a bigger picture here.
Oh, yeah, so you see a little window blink, right? That's basically your terminal. In that case, there's a lot of things I could do.
And then if you detect the Trojan on there and you remove it, and the cable's still in play, which it's designed to be, just put it right back on. No shit. Which is absolutely a thing that has happened with a bunch of my customers. They have told me that they did an engagement with a very high-profile client.
We can go into these types of things, but that reinfection vector is exactly what they used.
Either or. So all about flexibility. So you can program this a couple different ways. So what I showed was me remotely connecting to it and I hit go. But this can be configured that when it powers up, when it gets plugged in, it powers up. It can immediately run a payload. It can wait a series, however long you want, and then run a payload.
Yeah, exactly. So when I say payload, it's the series of keystrokes that gets run.
You can. There's ways of typing out. If you've got a small executable, that you want to transfer over, there's a couple ways to do that. Like, you just use the keystrokes to download it, right? You can download stuff from, like, the terminal, for instance. Or I could use Chrome and download it there and go to the downloads folder and open it up there. Through keystrokes. Yep.
I can navigate everything with keystrokes.
Yep, that's one way. I mean, I probably wouldn't email it to them because if I was going to email it, I'd probably include an email that convinces them to just run it for me. But if I'm up against a hardened target where they're not susceptible to that, they're unlikely to do it, I'm like, okay, well, let's get a cable that'll do it for me.
um as as an example right this can also do mouse movements too if we need um lots of control there and yeah it's that you can also yeah so the the malware right you can download that you can also type it back out um it's called base64 it's just a whole bunch of it looks like random garbage characters if you open like if you open up a an executable with a notepad roughly
stay in high level here, you're going to see a bunch of garbage text, right? But when you type that same text out in a notepad and save it, it's that executable. So I can type that back into the computer And boom, there's the executable, which is something we've done quite a bit in environments where they're checking what is being downloaded from the internet.
Okay, you're looking at the internet. Cool. I'm going to just type this little piece of malware back into the computer. Lots of cool tricks you can do like that. Wow. It's fun. And so there's other aspects of this too. So, you know, keystroke injection, mouse injection. I showed you the key logging. Oh, you were asking about the ways of triggering it. So I showed you remotely I can click go.
We can have it boot up and go. There's also... what I refer to as geofencing. Basically, it's got wireless in there, so it can just look at the nearby networks and figure out where it is and where it isn't. And you can trigger or block things on that. And there's a self-destruct function where it'll erase everything on it. Now, it sounds super nefarious, but it's actually prompted by legal.
Showing 641–660 of 855 · page 33 of 43 ← Previous Next →