Log in

goodpods headphones icon

To access all our features

Open the Goodpods app
Close icon
headphones
CYFIRMA Research

CYFIRMA Research

CYFIRMA

Cyber defenders, listen up! The CYFIRMA Research podcast has some juicy intel on the latest cyber threats that are lurking in the shadows. Tune in to this security briefing to stay on top of emerging threats and be ready to tackle digital risk like never before.

Share icon

All episodes

Best episodes

Top 10 CYFIRMA Research Episodes

Goodpods has curated a list of the 10 best CYFIRMA Research episodes, ranked by the number of listens and likes each episode have garnered from our listeners. If you are listening to CYFIRMA Research for the first time, there's no better place to start than with one of these standout episodes. If you are a fan of the show, vote for your favorite CYFIRMA Research episode by adding your comments to the episode page.

ARES, is a new threat actor group identified by CYFIRMA Research. ARES is involved in selling corporate and government authority databases. CYFIRMA Research has observed cartel-like behaviour, affiliations with other threat actors, and connections with established hacking groups like RANSOMHOUSE ransomware group, KelvinSecurity, and Adrastea hacker group. ARES Leaks is potentially becoming an alternative to BreachedForum, intensifying its efforts to add more threat actors and leaks to its platform. The ARES group comprises expert penetration testers, malware developers, and other resources, offering not only data leaks but also Botnet and DDoS services. The OSINT search reveals that the group's admin is involved in selling Zero-day vulnerabilities, indicating that the group is leveraging such vulnerabilities to compromise systems. Overall, ARES Leaks' activities present a serious threat to organizations' cybersecurity.

https://www.cyfirma.com/

bookmark
plus icon
share episode

CYFIRMA’s research team has discovered a new Remote Access Trojan named Xeno-RAT, featuring sophisticated capabilities. Through comprehensive analysis, our report explores the various evasion techniques utilized by threat actors to circumvent detection, as well as elucidates the methods employed in creating robust malware payloads.
Xeno RAT, a potent malware written in C# with advanced capabilities, demonstrates an alarming trend as it continuously evolves to enhance its features. It exploits the DLL search order functionality in Windows to load malicious DLLs into trusted executable processes and employs process injection to inject malicious code into legitimate Windows processes. Employing a multi-stage infection process, it meticulously avoids detection by scrutinizing for debuggers, monitoring tools, and analysis software before executing its final stage. Equipped with anti-debugging techniques, it operates stealthily and ensures persistence by adding itself to scheduled tasks. Continuously monitoring compromised systems, it communicates with command-and-control servers for status updates and instructions at regular intervals. Extensive obfuscation techniques are utilized both within files/code and in network traffic to effectively evade detection.
To mitigate the risks associated with Xeno RAT malware, users are advised to exercise caution when accessing files from untrustworthy sources or clicking on unfamiliar links. Implementing robust cybersecurity measures, including reputable antivirus software, regular software updates, and awareness of social engineering tactics, is crucial in fortifying protection against such threats.
Link to the Research Report: Xeno RAT: A New Remote Access Trojan with Advance Capabilities - CYFIRMA
#Cyfirma #CyberSecurity #ThreatIntelligence #Xeno-RAT #InfoSec #MalwareAnalysis #CyfirmaResearch #ExternalThreatLandscapeManagement #ETLM #Malware

https://www.cyfirma.com/

bookmark
plus icon
share episode

Cyfirma’s latest report concerning a new malware, Nova, being offered by MaaSoperators Sordeal who have been actively distributing it since early 2023. This information stealer exhibits advanced capabilities, leveraging sophisticated techniques for anti-forensics and defense evasion.
Nova targets most of the commonly used browsers, exfiltrating autofills, bookmarks, payment cards, cookies, download lists, history and passwords. We have observed heightened activity by Sordeal since September 2023. Recent developments highlight alarming upcoming features, including Discord hijacking, credit card theft, and crypto wallet injection. Security measures should prioritize detection similar evolving tactics to safeguard against such threats.
Link to the Research Report: Emerging MaaS Operator Sordeal Releases Nova Infostealer - CYFIRMA
#etlm #cyberintelligence #cybersecurity #infostealer #informationstealer #Cyfirmaresearch #malvertising #Malicord

https://www.cyfirma.com/

bookmark
plus icon
share episode

The geopolitical landscape in 2024 is at a critical juncture! As we begin the year, explore five key events may shape the course of global affairs and have profound effect on the Cyber Threat Landscape through this Cyfirma blog! Covering the below key events:

· World Goes to the Polls: Over four billion people in nearly 80 countries will participate in elections, with Taiwan's recent election raising tensions in the Taiwan Strait.

· Stalemate in Ukraine: The conflict between Russia and Ukraine remains in an attritional phase, with cyber warfare becoming a pivotal element in the ongoing struggle.

· Globalization Retreats: The fragility of the global trading system intensifies, driven by tensions over Chinese overproduction and investment, potentially leading to a resurgence of trade wars.

· China's Economic Crossroads: China faces challenges including over-indebtedness, demographic concerns, and global pushback against its economic strategies, with cyber espionage posing a significant threat.

· Middle East Suspended: Ongoing conflicts in the Middle East, especially the Israel-Hamas situation, raise concerns about cyber activities and potential wider hostilities involving Iran and its proxies.

The decisions made in the coming days and months will have profound consequences, shaping the course of history. Remain Informed and engaged in understanding the evolving dynamics.

Link to the Research Report: LOOKING INTO THE CRYSTAL BALL : WHAT WILL 2024 BRING IN GEOPOLITICS - CYFIRMA

#Cyfirma #CyfirmaResearch #GlobalAffairs #Geopolitics2024 #Cyberfallout #IsraelGaza #Taiwan #RussiaUkraineWar #SupplyChain #China #Election #Trump #Biden

https://www.cyfirma.com/

bookmark
plus icon
share episode

CYFIRMA’s Research team embarked on a mission to uncover a targeted attack on Indian defense personnel via WhatsApp Messenger. Suspected to originate from Pakistan, the threat actor deployed malicious Android apps disguised as "MNS NH Contact" and "Posted out off," aiming to gain unauthorized access to sensitive information.
Our Investigation revealed the use of sophisticated social engineering tactics, with malicious apps designed to exploit vulnerabilities and evade detection. Notably, the attacker employed a Spynote Android remote administration tool or possibly a modified version known as 'Craxs Rat', showcasing their advanced evasion tactics.
This incident serves as a stark reminder of the ongoing cyber conflicts between nations and underscores the importance of robust cybersecurity measures. Stay informed, stay vigilant.

Link to Research Report: New Pakistan-based Cyber Espionage Group’s Year-Long Campaign Targeting Indian Defense Forces with Android Malware - CYFIRMA
#CyberSecurity #DigitalThreats #Geopolitics #maliciousAndroid #Indiandefense #socialengineering #espionage #cyberespionage #IndiaPakistan #threatintel #advancedpersistent #CYFIRMA #CyfirmaRsearch #ExteralThreatLandscapeManagement #ETLM

https://www.cyfirma.com/

bookmark
plus icon
share episode
CYFIRMA Research - CYFIRMA Research - The End of Pax Americana
play

12/07/23 • 5 min

The world has witnessed an unprecedented surge in conflicts over the past two years, surpassing any period since the end of World War II. Amidst a fracturing world order and the waning Pax Americana, simmering tensions threaten to erupt suddenly, or at the very least, escalate into major crises with significant cyber repercussions.

Link to the Research Report: THE END OF PAX AMERICANA - CYFIRMA

#Geopolitics #Cyfirmaresearch #ThreatIntelligence #Cybersecurity #ETLM #CurrentAffairs #PaxAmericana

https://www.cyfirma.com/

bookmark
plus icon
share episode

CYFIRMA observed a new European threat actor group known as FusionCore. Running Malware-as-a-service, along with the hacker-for-hire operation, they have a wide variety of tools and services that are being offered on their website, making it a one-stop-shop for threat actors looking to purchase cost-effective yet customizable malware. The operators have started a ransomware affiliate program that equips the attackers with the ransomware and affiliate software to manage victims. FusionCore typically provides sellers with a detailed set of instructions for any service or product being sold, enabling individuals with minimal experience to carry out complex attacks.

https://www.cyfirma.com/

bookmark
plus icon
share episode

#Russia pulled out of the #BlackSeaGrainDeal this summer and started bombing Ukraine’s #grain export terminals with the goal of damaging Ukrainian economy and political cohesion of the #EU, after Ukrainian grain is forced towards EU #markets instead of its customers in #GlobalSouth.
We assess that Russia will also use #cybertools to go after #European #agriculturallogistics to keep pressure on the Western alliance supporting #Ukraine in its defence against Russia. Potential repercussions of this policy are enormous. Read the full report below!
Link to the Research Report: BLACK SEA GRAIN DEAL : A GEOPOLITICAL ETLM PERSPECTIVE - CYFIRMA
#Geopolitics #Cyfirmaresearch #ThreatIntelligence #cybersecurity #ETLM #currentaffairs

https://www.cyfirma.com/

bookmark
plus icon
share episode

India's Loksabha Elections 2024 hold immense significance, not only for the nation but also for the global democratic landscape. The scale and complexity of the electoral process make it susceptible to cyberattacks, especially with the proliferation of generative AI and deepfake technologies.
Link to the Research Report: The Indian Election : The Grandest Spectacle of Democracy under AI Threat - CYFIRMA
#Geopolitics #Cyfirmaresearch #ThreatIntelligence #cybersecurity #ETLM #currentaffairs #GeneralElections #LokSabha #cyberattacks #generativeAI #deepfake

https://www.cyfirma.com/

bookmark
plus icon
share episode

Stay informed on the evolving cybersecurity landscape with CYFIRMA's February 2024 Monthly Ransomware Report. LockBit leads the charts despite a takedown by law enforcement, showcasing resilience and technical prowess. Manufacturing takes the hit, recording a 40% rise in attacks. The USA remains a prime target, followed by the UK, Canada, France, and Spain.

The evolution of ransomware tactics becomes apparent as LockBit aggressively returns, and RansomHouse introduces 'MrAgent' for automated attacks.

Emerging threats include Alpha's sophistication and the mysterious Blackout group.

February witnessed significant events: Knight ransomware's source code for sale, Hyundai Motor hit by Black Basta, and warnings on BlackCat's healthcare attacks. Arrests of SugarLocker members highlight the urgent need for enhanced cybersecurity measures. Stay protected, stay informed. Fortify your defenses against evolving cyber threats.
Link to the Research Report: TRACKING RANSOMWARE February 2024 - CYFIRMA
#Cybersecurity #RansomwareReport #SecurityInsights#CybersecurityInsights #ThreatLandscape#StaySecure #CyberSecurity #RansomwareReport #ThreatIntelligence #Ransomware #DigitalDefense #Cyfirma #ETLM #lockbit #RansomHouse #BlackBasta #Alpha#Blackout #Alphv #Blackcat #Knight #USA #Manufacturing #CyfirmaResearch #ExternalThreatLandscapeManagement

https://www.cyfirma.com/

bookmark
plus icon
share episode

Show more best episodes

Toggle view more icon

FAQ

How many episodes does CYFIRMA Research have?

CYFIRMA Research currently has 217 episodes available.

What topics does CYFIRMA Research cover?

The podcast is about News, Tech News, Podcasts and Cybersecurity.

What is the most popular episode on CYFIRMA Research?

The episode title 'CYFIRMA Research - Episode 004:DoNot APT Targets Individuals in South Asia using Android Malware' is the most popular.

What is the average episode length on CYFIRMA Research?

The average episode length on CYFIRMA Research is 5 minutes.

How often are episodes of CYFIRMA Research released?

Episodes of CYFIRMA Research are typically released every 3 days.

When was the first episode of CYFIRMA Research?

The first episode of CYFIRMA Research was released on Apr 28, 2023.

Show more FAQ

Toggle view more icon

Comments