Meta tags:
description= News and opinions from Fox-IT;
Headings (most frequently used words):
the, for, in, of, lazarus, memory, through, malware, identifying, http, fox, it, international, blog, remotepe, rat, that, lives, three, rats, coming, your, cheese, decrypting, full, disk, encryption, with, dissect, red, teaming, age, edr, evasion, endpoint, detection, virtualisation, sifting, spines, potential, cactus, ransomware, victims, android, vultur, expands, its, wingspan, scanning, masses, reverse, reveal, recover, windows, defender, quarantine, forensics, spelling, police, searching, malicious, servers, by, typos, responses, popping, blisters, research, an, overview, past, payloads, and, exploring, recent, developments, posts, navigation,
Text of the page (most frequently used words):
the (28), and (20), that (14), blog (13), for (13), fox (12), minutes (10), continue (10), reading (10), this (9), with (8), 2024 (8), lazarus (8), #malware (7), memory (7), servers (6), malicious (6), incident (6), response (6), international (5), 2023 (5), uncategorized (5), overview (5), identifying (5), http (5), detection (5), windows (5), authors (5), its (5), have (4), authored (4), payloads (4), from (4), past (4), activity (4), group (4), responses (4), december (4), defender (4), quarantine (4), scanning (4), vultur (4), through (4), dissect (4), subgroup (4), november (3), mick (3), koomen (3), summary (3), blister (3), one (3), recent (3), threat (3), intelligence (3), reverse (3), forensics (3), will (3), android (3), multiple (3), are (3), yun (3), zheng (3), cactus (3), ransomware (3), may (3), 2026 (3), disk (3), endpoint (3), edr (3), required (2), view (2), content (2), log (2), sign (2), subscribed (2), subscribe (2), now (2), posts (2), payload (2), years (2), popping (2), blisters (2), research (2), exploring (2), developments (2), part (2), ncc (2), host (2), evade (2), spelling (2), police (2), searching (2), typos (2), erik (2), schamper (2), antivirus (2), files (2), into (2), reveal (2), recover (2), january (2), post (2), library (2), more (2), during (2), masses (2), been (2), which (2), has (2), expands (2), wingspan (2), april (2), dutch (2), security (2), sifting (2), spines (2), potential (2), victims (2), september (2), introduction (2), attackers (2), their (2), known (2), red (2), teaming (2), age (2), evasion (2), virtualisation (2), back (2), engagements (2), decrypting (2), full (2), encryption (2), organizations (2), financial (2), cryptocurrency (2), overlaps (2), linked (2), citrine (2), gleaming (2), actor (2), three (2), rats (2), coming (2), your (2), cheese (2), remotepe (2), rat (2), lives (2), news (2), opinions (2), website, name, email, write, comment, loading, comments, collapse, bar, manage, subscriptions, site, reader, report, privacy, already, wordpress, com, account, join, 329, other, subscribers, older, navigation, piece, loads, embedded, inside, provide, dropped, loader, based, 137, unpacked, samples, half, take, look, shows, margit, hazenbroek, nefarious, activities, critical, aspect, our, approach, involves, looking, anomalies, sometimes, cybercriminals, employ, tactics, involve, mimicking, legitimate, software, however, max, groot, shipped, standard, installations, places, upon, engineering, mpengine, dll, resulted, finding, previously, undocumented, metadata, folder, can, used, digital, existing, scripts, extract, quarantined, axel, boesenach, user, friendly, python, was, created, out, necessity, having, control, give, how, works, share, thought, process, why, march, joshua, kamp, executive, behind, banking, spotted, adding, new, technical, features, allow, operator, further, remotely, interact, victim, mobile, device, also, started, masquerading, encrypting, communication, using, encrypted, willem, zeeman, series, written, various, cyber, firms, collaborated, exploits, qlik, sense, initial, access, all, them, please, check, central, special, interest, cyberveilig, nederland, boudewijn, meijer, rick, veldhoven, defensive, products, improve, must, refine, craft, gone, days, executing, binaries, especially, ones, well, reponse, vendors, focus, execution, both, native, managed, applications, author, guus, beckers, 2022, decided, open, source, proprietary, tooling, since, then, adopted, many, different, companies, regular, workflow, those, you, who, not, yet, familiar, framework, built, any, 2025, few, conducted, cases, involving, specifically, targets, sector, applejeus1, sleet2, unc47363, pisces4, uses, srt, last, year, published, research1, about, north, korean, targeting, encountered, applejeus2, sleet3, unc47364, pisces5, investigation, observed, had, replaced, archive, home, menu, skip,
Text of the page (random words):
fox it international blog news and opinions from fox it skip to content fox it international blog news and opinions from fox it menu home archive back to fox it remotepe the lazarus rat that lives in memory authors yun zheng hu and mick koomen summary last year we published research1 about a north korean lazarus subgroup targeting financial and cryptocurrency organizations encountered during multiple incident response engagements this lazarus subgroup overlaps with activity linked to applejeus2 citrine sleet3 unc47364 and gleaming pisces5 in one investigation we observed that the actor had replaced continue reading remotepe the lazarus rat that lives in memory fox srt blog threat intelligence may 22 2026 17 minutes three lazarus rats coming for your cheese authors yun zheng hu and mick koomen introduction in the past few years fox it and ncc group have conducted multiple incident response cases involving a lazarus subgroup that specifically targets organizations in the financial and cryptocurrency sector this lazarus subgroup overlaps with activity linked to applejeus1 citrine sleet2 unc47363 and gleaming pisces4 this actor uses continue reading three lazarus rats coming for your cheese threat intelligence september 1 2025 may 21 2026 22 minutes decrypting full disk encryption with dissect author guus beckers back in 2022 fox it decided to open source its proprietary incident response tooling known as dissect since then it has been adopted by many different companies in their regular workflow for those of you who are not yet familiar with dissect it is an incident response framework built with incident response engagements of any continue reading decrypting full disk encryption with dissect blog december 11 2024 december 5 2024 7 minutes red teaming in the age of edr evasion of endpoint detection through malware virtualisation authors boudewijn meijer rick veldhoven introduction as defensive security products improve attackers must refine their craft gone are the days of executing malicious binaries from disk especially ones well known to antivirus and endpoint detection and reponse edr vendors now attackers focus on in memory payload execution for both native and managed applications to evade continue reading red teaming in the age of edr evasion of endpoint detection through malware virtualisation blog september 25 2024 may 21 2026 21 minutes sifting through the spines identifying potential cactus ransomware victims authored by willem zeeman and yun zheng hu this blog is part of a series written by various dutch cyber security firms that have collaborated on the cactus ransomware group which exploits qlik sense servers for initial access to view all of them please check the central blog by dutch special interest group cyberveilig nederland continue reading sifting through the spines identifying potential cactus ransomware victims blog april 25 2024 april 25 2024 7 minutes android malware vultur expands its wingspan authored by joshua kamp executive summary the authors behind android banking malware vultur have been spotted adding new technical features which allow the malware operator to further remotely interact with the victim s mobile device vultur has also started masquerading more of its malicious activity by encrypting its c2 communication using multiple encrypted payloads that are continue reading android malware vultur expands its wingspan uncategorized march 28 2024 23 minutes memory scanning for the masses authors axel boesenach and erik schamper in this blog post we will go into a user friendly memory scanning python library that was created out of the necessity of having more control during memory scanning we will give an overview of how this library works share the thought process and the why s this blog post will continue reading memory scanning for the masses uncategorized january 25 2024 january 26 2024 3 minutes reverse reveal recover windows defender quarantine forensics max groot erik schamper tl dr windows defender the antivirus shipped with standard installations of windows places malicious files into quarantine upon detection reverse engineering mpengine dll resulted in finding previously undocumented metadata in the windows defender quarantine folder that can be used for digital forensics and incident response existing scripts that extract quarantined files do continue reading reverse reveal recover windows defender quarantine forensics uncategorized december 14 2023 december 14 2023 15 minutes the spelling police searching for malicious http servers by identifying typos in http responses authored by margit hazenbroek at fox it part of ncc group identifying servers that host nefarious activities is a critical aspect of our threat intelligence one approach involves looking for anomalies in responses of http servers sometimes cybercriminals that host malicious servers employ tactics that involve mimicking the responses of legitimate software to evade detection however continue reading the spelling police searching for malicious http servers by identifying typos in http responses uncategorized november 15 2023 8 minutes popping blisters for research an overview of past payloads and exploring recent developments authored by mick koomen summary blister is a piece of malware that loads a payload embedded inside it we provide an overview of payloads dropped by the blister loader based on 137 unpacked samples from the past one and a half years and take a look at recent activity of blister the overview shows that continue reading popping blisters for research an overview of past payloads and exploring recent developments uncategorized november 1 2023 november 1 2023 35 minutes posts navigation older posts fox it international blog subscribe subscribed fox it international blog join 329 other subscribers sign me up already have a wordpress com account log in now privacy fox it international blog subscribe subscribed sign up log in report this content view site in reader manage subscriptions collapse this bar loading comments write a comment email required name required website
|