Royal Road-related attacks observed during 2020 » https://nao-sec.org/2021/01/royal-road-redive.html
nao-sec.org
Royal Road! Re:Dive - @nao_sec
Retrohunting APT37: North Korean APT used VBA self decode technique to inject RokRat https://blog.malwarebytes.com/threat-analysis/2021/01/retrohunting-apt37-north-korean-apt-used-vba-self-decode-technique-to-inject-rokrat/
A Deep Dive into Lokibot Infection Chain https://blog.talosintelligence.com/2021/01/a-deep-dive-into-lokibot-infection-chain.html
Cisco Talos
A Deep Dive into Lokibot Infection Chain
Lokibot is one of the most well-known information stealers on the malware landscape. In this post, we'll provide a technical breakdown of one of the latest Lokibot campaigns. Talos also has a new script to unpack the dropper's third stage. The actors behind…
Using Windows Disposable VMs for test and research https://rolando.anton.sh/blog/2021/01/01/using-windows-disposable-vms-for-test-and-research/
Finding Targeted SUNBURST Victims with pDNS https://www.netresec.com/?page=Blog&month=2021-01&post=Finding-Targeted-SUNBURST-Victims-with-pDNS
Netresec
Finding Targeted SUNBURST Victims with pDNS
Our SunburstDomainDecoder tool can now be used to identify SUNBURST victims that have been explicitly targeted by the attackers. The only input needed is passive DNS (pDNS) data for avsvmcloud.com subdomains. Companies and organizations that have installed…
Nice vuln analysis » NTFS Remote Code Execution (CVE-2020-17096) Analysis https://blog.zecops.com/vulnerabilities/ntfs-remote-code-execution-cve-2020-17096-analysis/
Jamf
Jamf Threat Labs | Blog
From a small BAT file to Mass Logger infostealer https://isc.sans.edu/forums/diary/From+a+small+BAT+file+to+Mass+Logger+infostealer/26946/
Tying It All Together - Pwning To Own on LG phones https://douevenknow.us/post/639414006930702336/tying-it-all-together-pwning-to-own-on-lg-phones
Tumblr
Tying It All Together - Pwning To Own on LG phones
Last year I detailed a secure EL3 vulnerability which affected (and still affects, for devices with discontinued updates) LG Android devices. However, this vulnerability alone isn't actually all that...
Reverse Engineering The Saboteur game for Xbox360 with Linux https://daniele.tech/2020/12/reverse-engineering-the-saboteur-game-for-xbox360-with-linux/
Daniele Mte90 Scasciafratte
Reverse Engineering The Saboteur game for Xbox360 with Linux - Daniele Mte90 Scasciafratte
I spent my Christmas hoildays on reverse engineering some files of this Xbox 360 game version just for fun with not an happy conclusion...
THE EVOLUTION OF THE FIN7 JSSLOADER https://www.morphisec.com/hubfs/eBooks_and_Whitepapers/FIN7%20JSSLOADER%20FINAL%20WEB.pdf
Cobalt Strike and Metasploit accounted for a quarter of all malware C&C servers in 2020 https://www.zdnet.com/google-amp/article/cobalt-strike-and-metasploit-accounted-for-a-quarter-of-all-malware-c-c-servers-in-2020/
ZDNet
Cobalt Strike and Metasploit accounted for a quarter of all malware C&C servers in 2020
Security firm Recorded Future said it tracked more than 10,000 malware command and control servers last year, used across more than 80 malware families.
Analyzing CVE-2020-16040 https://faraz.faith/2021-01-07-cve-2020-16040-analysis/
faraz.faith
Analyzing CVE-2020-16040
We have continued the post series on methods for unrelocating Windows modules, enjoy the reading! » https://reversea.me/index.php/unrelocating-windows-modules-ii/
Bug discovery diaries: uncovering sngrep overflow issues with blackbox fuzzing https://www.rtcsec.com/post/2021/01/bug-discovery-diaries-uncovering-sngrep-overflow-issues-with-blackbox-fuzzing/
Parent Process vs. Creator Process https://scorpiosoftware.net/2021/01/10/parent-process-vs-creator-process/
Pavel Yosifovich
Parent Process vs. Creator Process
Normally, a process created by another process in Windows establishes a parent-child relationship between them. This relationship can be viewed in tools such as Process Explorer. Here is an example…
Chrome 1-Day Hunting - Uncovering and Exploiting CVE-2020-15999 https://starlabs.sg/blog/2021/01/chrome-1-day-hunting-uncovering-and-exploiting-cve-2020-15999/
starlabs.sg
Chrome 1-Day Hunting - Uncovering and Exploiting CVE-2020-15999
Introduction This blog post details the exploitation process for the vulnerability CVE 2020-15999 in Google Chrome 86.0.4222.0 on Linux. While CVE 2020-15999 is a heap-based buffer overflow in the font-loading library Freetype rather than Chrome proper, its…
Evaluating Cookies to Hide Backdoors https://securityboulevard.com/2021/01/evaluating-cookies-to-hide-backdoors
A journey into IoT Forensics - Episode 5 - Analysis of the Apple HomePod and the Apple Home Kit Environment (aka thanks RN Team!) https://blog.digital-forensics.it/2021/01/a-journey-into-iot-forensics-episode-5.html
blog.digital-forensics.it
A journey into IoT Forensics - Episode 5 - Analysis of the Apple HomePod and the Apple Home Kit Environment (aka thanks RN Team!)
DFIR research
Research Paper: Understanding and Exploiting Zerologon https://sidb.in/2021/01/06/Zerologon-Paper.html
sidb.in
Research Paper: Understanding and Exploiting Zerologon - computer insecurities
Zerologon? What’s that? Zerologon is the cool new vulnerability in town with a CVSS score of 10. It has intrigued me ever since it came out. I have read Secu...
Mitigations and Best Practices for ExAllocatePoolZero Security Vulnerabilities https://www.osr.com/blog/2021/01/07/mitigations-exallocatepoolzero-security-vulnerability/
OSR
Mitigations and Best Practices for ExAllocatePoolZero Security Vulnerabilities
tl;dr The Windows V2004 WDK/EWDK had a serious security vulnerability. It has been updated to mitigate that vulnerability, and you should update all of your machines that have the WDK/EWDK installe…