State of the Hack: Recent Episodes

Mandiant

State of the Hack discusses the latest in information security, digital forensics, incident response, cyber espionage, APT attack trends, and tales from the front lines of significant targeted intrusions.

View Details

If you are here looking for State of the Hack, we invite you to visit the feed of Mandiant’s new podcast, The Defender’s Advantage Podcast: https://www.buzzsprout.com/1762840

The new show launches this week with the same great content you've come to expect from us and even more.

Host Luke McNamara anchors our Threat Trends series, chatting with Mandiant intel analysts, consultants, and researchers, as well as external practitioners and leaders in cyber security, all through a threat-focused lens.

 And Mandiant's Kerry Matre joins to host monthly conversations with Mandiant customers and industry experts who will share their experiences and stories from the frontline of cyber security as part of our new Frontline Stories series.

Stay tuned for our inaugural Threat Trends episode later this week.

View Details

Zero Days got you down? There sure has been a lot of high impact zero days impacting edge appliances in 2021, from Microsoft Exchange, Pulse Secure, and SonicWall. In this episode, we're joined by Josh Fleischer, the Managed Defense investigator who uncovered three zero days in SonicWall Email Security, to discuss detection and investigation of a zero day, as well as what vendors and customers can do to better to prepare for zero day attacks.

View Details

In today's threat landscape, data theft and extortion go hand in hand
with ransomware. In this episode of State of the Hack, we'll talk
about how data theft plays a role in modern day ransomware incidents,
how attackers carry out data theft, and how we simulate data theft
during our Red Team assessments so clients can test their detective
capabilities.

View Details

An oft-undiscussed tactic, web shells are a popular way for threat
actors of all flavors to gain initial footholds, move laterally, and
maintain persistence in a stealthy manner. Austin and Doug discuss a
popular exploit that has been observed in the wild leading to web
shells and what infosec practitioners can do to protect against this
class of malware.

View Details

This episode discusses the idea of operational security ("OPSEC") from
an attacker's perspective. OPSEC relates to how an attacker or red
team might try to make their activities stealthier to avoid detection.
During this episode, Evan Pena and Julian Pileggi talk about the
various ways the Mandiant Red Team carries out their operational
security during an adversary simulation exercise, and interesting
techniques they see attackers using that have a high level of
operational security.

View Details

Join us for our holiday episode as we search for silver bells and
silver linings in our move to The Cloud! The cast sits down with
Dirk-Jan Mollema to talk Azure AD and Primary Refresh Tokens; and what
savvy defenders can do to secure their own cloud credentials.

View Details

Malicious Office document’s module streams that contain source code,
but no P-code are more likely to evade YARA rules and AV detection.
This evasion technique is called VBA purging; which is different than
the observed VBA stomping technique. In this episode we will discuss
what VBA purging is, the difference between purging and stomping, the
consequences of this technique, and a new tool created by Mandiant’s
Red Team called OfficePurge.

View Details

State of the Hack is back! Featuring new hosts Doug Bienstock
(@doughsec), Austin Baker (@bakedsec), Julian Pileggi (@x64_Julian),
and Evan Pena (@evan_pena2003) and new content. Doug and Austin kick
things off and dive into a recent flood of phishing campaigns
associated with KEGTAP aka BazaaLoader. They discuss some interesting
toolmarks of the KEGTAP attack chain and why it is so dangerous.

View Details

On today's show, Nick Carr and Christopher Glyer break down the
anatomy of a really cool pre-attack technique - tracking pixels - and
how it can inform more restrictive & evasive payloads in the next
stage of an intrusion. We're joined by Rick Cole (@a_tweeter_user) to
explore one such evasive method seen in-the-wild: Macro Stomping. And
we close the show by deep-diving with Matt Bromiley (@_bromiley) on
critical vulnerability we've been responding to most in 2020 - and
what we've seen several attackers do post-compromise.

Just as a targeted intruder might, we start our operation with email
tracking pixels. We break down how these legitimate marketing tools
are leveraged by attackers looking to learn more about their planned
victim's behavior and system - prior to sending any first stage
malware.
We break down the different variations on these trackers for both
benign and malicious uses. For examples of each style of tracking
pixel, see Glyer's recent tweet thread
(https://twitter.com/cglyer/status/1222255759687372801). We talk
through additional red team operators' responses to how they use this
technique in their campaigns today - discussion sparked from this
great offensive security discussion
(https://twitter.com/malcomvetter/status/1222539003565694985). This
trend of professional target profiling - drawing both inspiration and
specific tracking tools from the marketing industry - is highly
effective and a trend we expect to continue.

Next on the episode, we explain how document profiling accomplishes
the same end goal as email pixels - and how it can share information
about the current version of Microsoft Office on the potential
victim's system. Similar to execution guardrails, this Office version
information for Microsoft Word or Excel could be used to deliver
malware that is highly evasive and only runs on that profile.

We also pivot into some potential use cases for fingerprinting Office
versions. We discuss VBA macro stomping and file format intricacies
that require attackers to understand the version of office a target
may be using, in order to create evasive spear phishing lures that may
bypass both static and dynamic detections. Rick Cole joins us to talk
through an active attacker using macro stomping for evasion - both
p-code compiling and PROJECT stream manipulation. Rick walks through a
brief overview of the technique and a particular financial threat
actor who loves macro stomping as much as they love Onyx. Rick
co-authored a blog on the topic
(https://www.fireeye.com/blog/threat-research/2020/01/stomp-2-dis-bril
liance-in-the-visual-basics.html) and has an excellent tweet thread
linking to other research
(https://twitter.com/a_tweeter_user/status/1225062617632428033).

Finally, we're joined by a surprise second guest! Matt Bromiley drops
in to discuss FireEye's efforts to respond to the critical Citrix
vulnerability, CVE-2019-19781, that went public on January 10, 2020.
Matt helps us break down some of the activity we've seen since then,
including distinct uncategorized clusters of activity for NOTROBIN,
coin-mining, and attempted ETERNALBLUE-laced ransomware.

In addition to securing his customers in Managed Defense, Matt's been
working with the team to release several blogs, defender tips, and
tools on the vulnerability:
• Matt and Nick published an initial blog on the topic – detailing
exploit timelines, evasive attackers, and resilient approaches to
detection
(https://www.fireeye.com/blog/products-and-services/2020/01/rough-patc
h-promise-it-will-be-200-ok.html)
• Our colleagues Willi Ballenthin and Josh Madeley unveiled NOTROBIN
and the concept of exploit squatter's rights in the blog with the
titl

View Details

In response to increased U.S.-Iran tensions stemming from the recent
death of Quds Force leader Qasem Soleimani by U.S. forces and concerns
of potential retaliatory cyber attacks, we're bringing the latest from
our front-line experts on all things Iran. Christopher Glyer and Nick
Carr are joined by Sarah Jones (@sj94356) and Andrew Thompson
(@QW5kcmV3) to provide a glimpse into Iran-nexus threat groups -
including APT33, APT34, APT35, APT39, and TEMP.Zagros - as well as the
freshest actionable information on suspected Iranian uncategorized
(UNC) groups that are active right now.

We get right into it with a picture of Iranian compromise activity
from just a few years ago - what we observed and the basic,
cookie-cutter approach to their intrusions - and then begin to walk
through the stark contrast to their TTPs today. We discuss how and why
their Computer Network Operations (CNO) has evolved quickly and
provide a detailed walk through all of the graduated Iranian APT
groups.

Our experts share their experiences with each group, moments in time
that surprised or impressed us from Iranian threat actors, and notable
shifts in behavior - as well as our standing questions. Iranian
intrusion operators have come a long way from DDoS & defacement, basic
scanning, Cain & Abel and ASPXspy... to DNS hijacking, social
engineering via LinkedIn, information operations, and backdoors like
QUADAGENT, SANDSPY, TANKSHELL - then filling in the gaps with the
quick adoption of offensive security post-compromise tools and
techniques.

We close this first episode of season 3 with an overview of actionable
mitigations to secure against both Iranian intrusions and several
other threats, including disruptive and destructive ransomware
attacks. For more information on these mitigations as well as our
public source material supporting the discussion from the show, please
check out:
• APT33 graduation:
https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-in
to-iranian-cyber-espionage.html
https://www.brighttalk.com/webcast/10703/275683
• APT33 webinar & examples:
https://www.fireeye.com/blog/threat-research/2017/12/targeted-attack-i
n-middle-east-by-apt34.html
• An example TEMP.Zagros phishing campaign:
https://www.fireeye.com/blog/threat-research/2018/03/iranian-threat-gr
oup-updates-ttps-in-spear-phishing-campaign.html
• APT35 highlights in MTrends 2018:
https://www.fireeye.com/content/dam/collateral/en/mtrends-2018.pdf
• Iranian information operations:
https://www.fireeye.com/blog/threat-research/2018/08/suspected-iranian
-influence-operation.html
• RULER home page usage by Iranian groups & mitigations:
https://www.fireeye.com/blog/threat-research/2018/12/overruled-contain
ing-a-potentially-destructive-adversary.html
• APT39 graduation:
https://www.fireeye.com/blog/threat-research/2019/01/apt39-iranian-cyb
er-espionage-group-focused-on-personal-information.html
• Iranian DNS Hijacking (DNSpionage):
https://www.fireeye.com/blog/threat-research/2019/01/global-dns-hijack
ing-campaign-dns-record-manipulation-at-scale.html
• More Iranian influence operations:
https://www.fireeye.com/blog/threat-research/2019/05/social-media-netw
ork-impersonates-us-political-candidates-supports-iranian-interests.ht
ml
• APT34 social engineering via LinkedIn:
http://www.fireeye.com/blog/threat-research/2019/07/hard-pass-declinin
g-apt34-invite-to-join-their-professional-network.html
• FireEye response to mounting U.S.-Iran tensions:
https://www.fireeye.com/blog/products-and-services/2020/01/fireeye-res
ponse-to-mounting-us-iran-tensions.html
• U.S.-Iran tensions webinar & mitigations overview:
https://www.brighttalk.com/webcast/7451/382779

View Details

Ho ho homepage! Christopher Glyer and Nick Carr are back for the last
episode of 2019. They’re closing the year with a look at this month’s
front-line espionage activity and a whole bunch of FIN intrusions! In
addition to the threat round-up, they highlight some of our Mandiant
consultants doing that work and a few DFIR tricks they included in a
recent blog:
https://www.fireeye.com/blog/threat-research/2019/12/tips-and-tricks-t
o-analyze-data-with-microsoft-excel.html. As a special bonus, Santa
dropped off a slide clicker for the show so Nick and Christopher
decide to go deep on their recent presentation at #CYBERWARCON on “red
sourcing.” An episode sure to make them friends on infosec twitter for
sure! The presentation was a 10 minute #threatintel lightning talk,
but embracing the Christmas spirit, the gang tries to navigate a
sensitive area of current debate by spending more time on red sourcing
& providing some evidence and observations on APT groups moving to
publicly released post-compromise tooling; some potential motivations;
and then question whether any tool can ever be fully controlled (e.g.
Delpy/MIMIKATZ evil maid scenario, recent Turla coopting APT34 access
& tools). Because RULER.HOMEPAGE was touched on in the talk, they
expand a bit further on this and highlight the recent blog that Nick
co-authored on how attackers (like UNC1194) can conduct intrusions
from just a single registry key. They also question whether the
technique’s usage via Outlook installed Office 365’s Click-to-Run is
technically CVE-2017-11774 or not. I guess we need another episode
with MSRC! They end the year with some spicy predictions for 2020.
You’ll see. Thanks for watching and listening this year!

This episode was sponsored by bad decisions and office holiday parties
- and especially both.

View Details

Christopher Glyer and Nick Carr are back with an extremely offensive
episode with red teamers Evan Pena (@evan_pena2003) and Casey Erikson
(@EriksocSecurity). They get right into why they use shellcode (any
piece of self-contained executable code) and some of the latest
shellcode execution & injection techniques that are working
in-the-wild.

In previous episodes, the gang has discussed attackers - both
authorized and unauthorized - shift away from PowerShell and
scripting-based tooling to C# and shellcode due to improved
visibility, detection, and prevention provided by more logging, AMSI,
and endpoint security tooling. In this episode, they explore how
FireEye's Mandiant Red Team has responded to this pressure and the
techniques they've used to continue to operate.

Casey and Evan share their research around the benefits & drawbacks of
the three primary techniques for running shellcode and a project they
just released - DueDLLigence - to enable conversion of any shellcode
into flexible DLLs for sideloading or LOLbin'ing:
https://github.com/fireeye/DueDLLigence

If you want to learn more, check out their blog and #DailyToolDrop at:
https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on
-the-endpoint-evading-detection-with-shellcode.html

Shellabrate good times come on!

View Details

Christopher Glyer and Nick Carr sit down with the top two Steves from
Advanced Practices: Steve Stone (@stonepwn3000) and Steve Miller
(@stvemillertime) to talk about the front-line technical stories and
research presented at the 2019 #FireEyeSummit.

With team members embedded on every investigation, they dissect the
key takeaways from the past year’s responses and trends in tracking
the groups and techniques that matter. They cover the
behind-the-scenes of recent FIN7 events and put that in perspective
against Steve’s PDB research
and other research presented at the
summit, including talks from Advanced Practices team members on
proactive identification of C2, deep code signing research, and rich
header hunting at scale. We quickly highlight a favorite talk “Living
off the Orchard”
** revealing TTPs and artifacts left behind from the
million mac engagement. There’s double the chance you’ll enjoy Steve
as a guest – and we were pleased to finally have them on.

NOTE: Glyer live-tweeted the technical track**** throughout the summit
until additional blogs and videos are expected to release.

  • https://www.fireeye.com/blog/threat-research/2019/10/mahalo-fin7-respo
    nding-to-new-tools-and-techniques.html
    **
    https://www.fireeye.com/blog/threat-research/2019/08/definitive-dossie
    r-of-devilish-debug-details-part-one-pdb-paths-malware.html

https://www.fireeye.com/blog/threat-research/2019/10/leveraging-apple-
remote-desktop-for-good-and-evil.html
**** https://twitter.com/cglyer/status/1181978827028873221

View Details

Christopher Glyer and Nick Carr interview Matt Berninger (@secbern)
about his journey from Incident Responder to Data Scientist and how
that has shaped his perspective on ML applications and issues in the
industry today.

This discussion provides a brief overview of Data Science fundamentals
and how they apply to common cybersecurity problems. They also discuss
how to navigate the deluge of ML marketing and what considerations to
make before including ML in your security stack. Finally, they dive
into some recent Data Science projects and explain how the FireEye
Data Science team works with practitioners around the company to solve
complex problems.

View Details

Christopher Glyer and Nick Carr interview Dave Kennedy (@HackingDave)
on his experience running DerbyCon over the years, what conferences he
plans to attend next, and future plans to build and support DerbyCon
Communities (DerbyCom). Red teaming in the last few years has started
to get harder due to improvements in security visibility, improved
security tools, and better SOC teams. They discussed how Dave's red
team's @TrustedSec use security tools to baseline what their activity
looks like so they can try and blend in with legitimate activity. The
trend of red teams shifting away from PowerShell to C-based
tools/backdoors. Finally, they discussed both new and old (but still
effective) techniques recently seen in the wild that can evade
detection including using py2exe and pyinstaller based
backdoors/tools.

View Details

Christopher Glyer and Nick Carr interview Nate Warfield (@n0x08) on
his experience working at Microsoft's Security Response Center (MSRC).
They discuss how Nate's team manages the vulnerability reporting and
fix/remediation process across Microsoft's range of products/services.
And debated what makes the BlueKeep and DejaBlue vulnerabilities
different from previous vulnerabilities and why this particular set of
vulns took so long to have public exploit code available. Nate also
shared his first-hand experience with responding to the Shadow Brokers
release of exploits and thoughts on the release of the WannaCry worm.

View Details

In this episode, Christopher Glyer and Nick Carr interview the
Darkoperator (@Carlos_Perez) and Benjamin Delpy (@gentilkiwi) on all
things related to Mimikatz and Kekeo. They discuss Carlos' new class
on Mimikatz, the background on why he started it, how red teamers can
use the features in unique/creative ways, and how blue teamers can
detect the activity. Benjamin shared the background on how he
developed the tools (hint - he didn't read the kerberos RFC), some of
its lesser known capabilities, like cloning near field communication
(NFC) proximity badges, how kerberos golden tickets got their default
10 year lifetime, why you only really need to set the expiration to 20
minutes, and his "creative" documentation (e.g. animated GIF posted to
Twitter).

View Details

This is our APT group graduation party for APT41: Double Dragon,
conducting both Chinese state-sponsored espionage activity and
personal financially-motivated activity. You've read the report* and
on this episode, Christopher Glyer and Nick Carr go behind-the-scenes
with two technical experts, Jackie O'Leary and Ray Leong, who worked
for months to produce the report. We answer viewer questions and
discuss sifting years of incident response data, peppered with Glyer's
IR war stories, and fascinating malware and techniques analyzed by our
reverse engineers in FLARE. Ray and Jackie share their experiences
with the threat group and challenges in the graduation process. We
cover what makes them sophisticated and deep-dive on their supply
chain attacks & guardrails, passive & cross-platform backdoors,
rootkits & bootkits, legit services usage, and third party access via
TeamViewer.

View Details

We are kicking-off a new segment on State of the Hack - an audio-only
deep dive discussion with authors from popular technical blogs. On
this episode, Christopher Glyer and Nick Carr spoke with FireEye's
Blaine Stancill (@MalwareMechanic) and Omar Sardar (@osardar1) on
their recent blog post, "Finding Evil in Windows 10 Compressed
Memory." You can read the full post here: https://feye.io/33dzIQD

View Details

We interviewed one of our most tenured analysts Barry Vengerik
(@barryv) on a range of viewer requested topics including: FIN7
retrospective, recent surge of Iranian threat activity, APT34
targeting organizations via LinkedIn messaging, FSB contractor leaks,
APT36 USB drop attacks and some tails of recent investigations
involving insider threats.

This episode brought to you by Combi Security: "Creative Red Teaming
with Flexible payment options"

View Details

Christopher and Nick kicked-off the latest episode with recent updates
to the MITRE ATT&CK framework, including several techniques that they
submitted. During the episode they discuss Outlook add-in persistence,
renamed binaries, and the high-level increase in execution guardrails
observed - all of which were added in the May update to ATT&CK. They
then spoke about CARBANAK Week; including how FireEye found the
CARBANAK source code and the process behind releasing it. They also
give a few new details on FIN7's on-going operations, post-indictment
to include the new front company and tactics used in their latest
round of phishing. And based on viewer request they chat about the
groups that deployed Robbinhood and other targeted ransomware
(extortionware) initial infection vectors and lateral movement
techniques. They broke down the possible offensive foreign
counterintelligence operation (OFCO) that is the new APT34 "leaks" and
separate the quality of the information from the stories around why
it's being shared. They also quickly spoke on the latest in the trend
of U.S. government indictments against Chinese individual operators
and their experience leading the investigations behind many of these
indictments and how they could be improved. And lastly, they give a
threat research blog round-up; including research from FireEye,
Chronicle, Kaspersky, and ESET.

View Details

On this episode, we got right into a bunch of new in-the-wild
activity! We discussed FIN6's shift to deploying enterprise
ransomware, including their recent LOCKERGOGA campaigns. The recent
DAYJOB/ShadowHammer supply chain compromises prompted some discussion
around this trend and several hunting techniques. We covered our
newly-released blog on the techniques that the attackers used to
deliver the TRITON malware framework and how to hunt for them - as
well as some background on our on-going response to that group at
another critical infrastructure client. We wanted to learn more about
attacker creativity and their mindset by inviting a real-life
adversary onto our show: Alyssa Rahman (@ramen0x3f) from our Red Team.
She walks us through a comprehensive red team case study at a
financial client that include compromising multi-factor systems,
KeePass, and eventually ATMs. She chats about why our red team prefers
phone-based social engineering as well as our Mandiant Red Team's
release of CommandoVM and ADFSDump/ADFSpoof.

View Details

In this latest episode, we featured FireEye, Principal Threat Analyst
and M-Trends contributor, Regina Elwell to take us on a deep dive of
our annual M-Trends report. We discussed how key metrics from our
incident response investigations changed including dwell times, source
of notification, and what industries were impacted. Additionally, we
broke down some of the highlights of four threat actors we upgraded in
2018 including APT37, APT38, APT39, and APT40. Finally we discussed
the M-trends red team case study, and common remediation
recommendations that organizations can implement prior to a breach
(pre-mediation).

View Details

We're back for season 2 and discussed reports of
destructive/disruptive attacks by APT33 and DNS hijacking. We also
spoke with Matthew Dunwoody and Alex Orleans about one of our favorite
topics: APT29.

View Details

In their final episode of 2018, Christopher Glyer and Nick Carr
brought the holiday cheer by providing a wrap-up on interesting
targeted attacker activity from the past 90 days, including CNIIHM
links to TRITON ICS attacks, suspected APT29 spearphishing campaign,
several recent DOJ indictments. They also highlighted some interesting
techniques including DNS over HTTPS and profiling victims pre-attack
using both compromised websites and Office documents.

View Details

In this episode, Christopher Glyer and Nick Carr spoke with Steven
Booth, Chief Security Officer at FireEye, to discuss what’s to come in
2019, including attackers and nations attempting to emulate other
threat groups, increased leveraging of legitimate services for command
and control, machine learning and artificial intelligence, a decreased
and more selective use of PowerShell in attacks, and much more. If you
want to get into the nitty gritty of cyber security in 2019, you won’t
want to miss this episode.

View Details

In this segment, we sit down with two Staff Reverse Engineers on the
FLARE team, Michael Bailey (@mykill) and James “Tom” Bennett
(@jtbennettjr), who were at CDS this year to discuss the results of
nearly 500 total hours of analysis of the Carbanak source code we
acquired. This included 100,000 lines of Carbanak source code and
dozens of binaries. We deep dive into how FLARE conducts that kind of
analysis and what it’s taught us about FIN7 and the other groups that
use Carbanak. Among other takeaways, they share how they modified the
Carbanak video player source to play FIN7 videos, covered in our
recent FIN7 blog.

View Details

FireEye recently released details on a particularly aggressive threat
group that we believe is responsible for conducting financial crime on
behalf of the North Korean regime, stealing millions of dollars from
banks worldwide. We refer to this group as APT38.
In this segment, we welcome two core contributors to the APT38 report:
Nalani Fraser, Manager of the Advanced Analysis Team, and Jackie
O’Leary, Senior Analyst on the Advanced Analysis Team. As soon as
Nalani and Jackie joined us, we wasted no time getting into the
specifics about their research into APT38, including how long they’d
been tracking them, what makes the group unique, what are the group’s
tactics, techniques and procedures, and what it means to be upgraded
to an APT group. Unlike all of our other show guests, they aren’t on
Twitter – which makes us sad.

View Details

We had the chance to pick the brains of John Hultquist
(@JohnHultquist), Director of Threat Intelligence, and Ben Read
(@bread08), Senior Manager of Cyber-espionage Analysis. John and Ben
provide a lot of media color and discuss geopolitical ramifications of
complex technical reports by translating the news into lay terms. In
this segment, we start with the recently announced indictments
charging Russian GRU officers with international hacking and related
influence and disinformation operations, then bounce to APT28, and the
conversation keeps going from there.

View Details

Christopher Glyer and Nick Carr spoke with FireEye Intel Analyst, Lee
Foster on how FireEye identified a suspected influence operation that
appears to originate from Iran aimed at audiences in the U.S., U.K.,
Latin America, and the Middle East.

During their conversation they spoke about how the operation is
leveraging a network of inauthentic news sites and clusters of
associated accounts across multiple social media platforms to promote
political narratives in line with Iranian interests. These narratives
include anti-Saudi, anti-Israeli, and pro-Palestinian themes, as well
as support for specific U.S. policies favorable to Iran, such as the
U.S.-Iran nuclear deal (JCPOA). The activity we have uncovered is
significant, and demonstrates that actors beyond Russia continue to
engage in and experiment with online, social media-driven influence
operations to shape political discourse.

View Details

“Special Guest Sean Metcalf (@Pyrotek)”: Sean Metcalf is a trailblazer
in the InfoSec field who is most well-known for his expertise in
Active Directory security. He’s given talks on the topic at several
security conferences, including Black Hat USA, DEF CON, DerbyCon and
BSides. Fun fact about Sean: he is one of roughly 100 Microsoft
Certified Masters (MCMs) in Directory Services in the world. Active
Directory security plays a huge part in his current role as Founder
and Chief Technology Officer of Trimarc Security. Trimarc is a company
that protects organizations primarily through the security of Active
Directory, Microsoft Exchange, and VMware virtual infrastructure.
During our chat, Sean explained how he got started in the world of
Active Directory security about a decade and a half ago when he was as
an Active Directory engineer. He discussed some of the challenges he
faced between then and now while traversing relatively uncharted
territory. He also provided a brief overview of the talk he gave at
Black Hat USA 2018 on why secure administration isn’t so secure.

View Details

“Special Guest Matt Graeber (@mattifestation)”: Early in Matt
Graeber’s professional life he was a rock climbing instructor, but
then he joined the Navy and that decision kicked off his journey into
the wonderful world of InfoSec. Matt is now a security Researcher at
SpecterOps, a company that provides adversary-focused solutions to
help organizations better defend themselves against the types of
attacks we see every day. At SpecterOps, Matt specializes in reverse
engineering and advancement of attacker tradecraft and detection.
Prior to SpecterOps, Matt did a stint with FireEye on a team that
would go on to become our FLARE unit, so of course we took a moment to
go down memory lane. Some of the other topics we covered include
PowerShell, Matt’s “Subverting Sysmon” Black Hat USA 2018 talk, and
the things that Matt will do in the name of a good cause.

View Details

“Special Guest Katie Nickels (@likethecoins)”: Katie Nickels attended
a liberal arts school and intended to get into journalism, but instead
she took on a researcher role and the rest is history. Now Katie is
the Lead Cyber Security Engineer at MITRE. MITRE is a not-for-profit
that operates federally funded research and development centers
(FFRDC) responsible for R&D that helps the U.S. government. Katie
specializes in cyber threat intelligence and how it can improve
network defenses. Part of that involves applying threat intelligence
to ATT&CK, a knowledge base of real-world attacker tactics, techniques
and procedures (TTPs) that is used to assist analysts. Very cool
stuff! During our chat, Katie talked about how her team processes new
intel as it’s made public (she said she was really excited about our
latest FIN7 blog post – thanks Katie!), and about a new ATT&CK
philosophy paper MITRE recently released that describes the
collaborative process of incorporating new TTPs. We also talked about
PRE-ATT&CK, which focuses on what threat actors do to prepare for an
attack, such as reconnaissance and weaponizing.

View Details

“FIN7”: It’s a matter of “when, not if” for organizations and
breaches, and the same goes for criminals and getting caught. The U.S.
District Attorney’s Office for the Western District of Washington
recently unsealed indictments and announced the arrests of three
leaders in a criminal organization we have tracked since 2015 as FIN7.
Referred to by many vendors as “Carbanak Group” (although we don’t
attribute all usage of the CARBANAK backdoor with the group), FIN7 is
well-known for the technical innovation, social engineering ingenuity,
and other creativity that has fueled their success. We open up this
episode by talking about all things FIN7, including their tools, their
tactics, techniques and procedures (TTPs), and some of the ways FIN7
activity changed following arrests made as far back as January.

• On the Hunt for FIN7: Pursuing an Enigmatic and Evasive Global
Criminal Operation
• To SDB, Or Not To SDB: FIN7 Leveraging Shim Databases for
Persistence
• FIN7 Evolution and the Phishing LNK
• FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC
Filings
• Tracking a Cyber Crime Group: FIN7 at a Glance

“Special Guest Katie Nickels (@likethecoins)”: Katie Nickels attended
a liberal arts school and intended to get into journalism, but instead
she took on a researcher role and the rest is history. Now Katie is
the Lead Cyber Security Engineer at MITRE. MITRE is a not-for-profit
that operates federally funded research and development centers
(FFRDC) responsible for R&D that helps the U.S. government. Katie
specializes in cyber threat intelligence and how it can improve
network defenses. Part of that involves applying threat intelligence
to ATT&CK, a knowledge base of real-world attacker tactics, techniques
and procedures (TTPs) that is used to assist analysts. Very cool
stuff! During our chat, Katie talked about how her team processes new
intel as it’s made public (she said she was really excited about our
latest FIN7 blog post – thanks Katie!), and about a new ATT&CK
philosophy paper MITRE recently released that describes the
collaborative process of incorporating new TTPs. We also talked about
PRE-ATT&CK, which focuses on what threat actors do to prepare for an
attack, such as reconnaissance and weaponizing.

“Special Guest Matt Graeber (@mattifestation)”: Early in Matt
Graeber’s professional life he was a rock climbing instructor, but
then he joined the Navy and that decision kicked off his journey into
the wonderful world of InfoSec. Matt is now a security Researcher at
SpecterOps, a company that provides adversary-focused solutions to
help organizations better defend themselves against the types of
attacks we see every day. At SpecterOps, Matt specializes in reverse
engineering and advancement of attacker tradecraft and detection.
Prior to SpecterOps, Matt did a stint with FireEye on a team that
would go on to become our FLARE unit, so of course we took a moment to
go down memory lane. Some of the other topics we covered include
PowerShell, Matt’s “Subverting Sysmon” Black Hat USA 2018 talk, and
the things that Matt will do in the name of a good cause.

“Special Guest Sean Metcalf (@Pyrotek)”: Sean Metcalf is a trailblazer
in the InfoSec field who is most well-known for his expertise in
Active Directory security. He’s given talks on the topic at several
security conferences, including Black Hat USA, DEF CON, DerbyCon and
BSides. Fun fact about Sean: he is one of roughly 100 Microsoft
Certified Masters (MCMs) in Directory Services in the world. Active
Directory security plays a huge part in his current role as Founder
and Chief Technology Officer of Trimarc Security. Trimarc is a company
that protects organizations primarily through the security of Active
Director

View Details

In this episode we were joined by Dan Perez (@MrDanPerez) of FireEye’s
Adversary Pursuit team. We discussed our experiences from FireEye's
Congressional roundtable on artificial intelligence, providing insight
into the analysis leading up to our report on TEMP.Periscope targeting
Cambodian election operations, and broke down several notable
adversary methods observed during the past few weeks of responding to
intrusions that matter.

View Details

In May we were joined by Andrew Thompson (@QW5kcmV3) of FireEye’s
Adversary Pursuit team. We explore the evolution and current state of
cloud services OAuth abuse, how we do technical intelligence &
attribution, and some war stories from the past few weeks of
responding to intrusions that matter.

“Shining a Light on OAuth Abuse”: we explore the history of OAuth
abuse in-the-wild and the uptick in third-party applications with
full, offline access to cloud service user data without the need for
credentials and bypassing two-factor authentication for 90 days. We
discuss APT28’s 2016 campaign, the May 2017 “Eugene Popov” worm, and
our red team’s use of the methods – tracing the origins back to a 2014
blog post by Andrew Cantino (@tectonic). There is an interesting
history of cloud service providers responding to this activity. Our
own Doug Bienstock (@doughsec) released the PwnAuth tool to allow
organizations to test their user awareness and ability to monitor for
this activity.
-- Shining a Light on OAuth Abuse with PwnAuth:
https://www.fireeye.com/blog/threat-research/2018/05/shining-a-light-o
n-oauth-abuse-with-pwnauth.html
-- History of OAuth social engineering attacks:
https://twitter.com/ItsReallyNick/status/926086495450095617
-- OAuth Hunting Scripts: https://github.com/dmb2168/OAuthHunting

“How FireEye Tracks Threats”: we get to know Andrew Thompson and chat
with him about how his team clusters, merges, and graduates threat
groups. We discuss modeling in the graph database and our preference
for primary source data – from Mandiant responses, Managed Defense
events, and our product telemetry data – with examples like APT10 and
how collections feed the intel picture. We discuss the tension between
IR and intelligence team members working together on engagements.
Andrew gives a few cool recent examples of illuminating adversary
infrastructure. He also says “unc groups” a few times which is new
public ground for FireEye…

“Threat Activity Round-up”: We chat about #VPNfilter and the uptick in
network device (and critical infrastructure) targeting. We give
insight into our on-going Community Protection Event for VPNfilter and
some in-the-wild intrusions. Glyer drops some knowledge on 2016
telemetry on this activity. We chat about WMI activity – WMIEXEC being
used by APT10 & APT20, WMI persistence by some targeted groups, and
the downstream push of previously sophisticated methods like
SystemUptime in WMI. We chat quickly about public reporting on the
same threat actors behind the ICS attack framework Triton now
targeting multiple safety instrumentation systems (SIS). We close with
Andrew talking about how his team finds attacker infrastructure before
it’s used.
-- VPNfilter techniques in-the-wild:
https://twitter.com/stvemillertime/status/1001114757280256001
-- History of the WMI SystemUptime method:
https://twitter.com/ItsReallyNick/status/995468901495566336
-- QUADAGENT Iranian infrastructure prior to use:
https://twitter.com/QW5kcmV3/status/999809240314376192

State of the Hack is FireEye’s monthly broadcast series, hosted by
Christopher Glyer (@cglyer) and Nick Carr (@itsreallynick), that
discusses the latest in information security, cyber espionage, attack
trends, and tales from the front lines of responding to targeted
intrusions.

View Details

In episode 3, we were joined by Alex Lanstein (@alex_lanstein) - one
of the first employees at FireEye who hunts through product telemetry
data to identify new targeted campaigns. During the RSA conference,
and with so many others referencing breaches and hunting from the
periphery, we thought it would be good to chat about primary source
data from our on-going APT and FIN attack investigations and how to
identify anomalies the way Alex does.

We live streamed this episode from the RSA Conference 2018 expo floor.
In an unforeseen twist of events, the sheer number of cyber threat
maps on the conference floor degraded the bandwidth and video quality.
We re-recorded the episode the next day from an undisclosed location
with a better connection.

“Community Protection: Southeast Asian Campaign”: We discuss our
on-going Community Protection Event (CPE) where we’ve pulled together
teams within the company to identify and protect against a suspected
Chinese attack group using new methods to compromise Southeast Asian
entities. We explore how it was found with custom passwords to decrypt
phishing docs as well as the unique PowerShell-laden shortcut (.LNK)
builder that was last seen with APT29 campaign around the 2016 U.S.
election.

“APT19 and RepeaTTPs”: We chat about APT19 resuming their targeting of
law firms this month using many of the exact same techniques as our
2017 blog post on the activity. Alex shares some insight into
interesting APT19 phishing lure choices.
• 2017 TTPs: https://www.fireeye.com/blog/threat-r...

“RO-BORAT Kazakhstani Attribution”: #ThreatIntel attribution can be
difficult, but not always. We chat about the level of rigor we applied
to analyzing some recent activity that we attributed to Kazakhstan.
Very nice!
• Related reading - https://www.eff.org/press/releases/ma...

“What’s M-Trending”: We close out the show by some round-robin
discussion of evolving attacker methods and what we found most
interesting within our M-Trends 2018 report released in April, which
compiled technical intelligence and #DFIR breach data from our 500+
Mandiant investigations in 2017.
• https://www.fireeye.com/content/dam/c...

State of the Hack is FireEye’s monthly live broadcast series, hosted
by Christopher Glyer (@cglyer) and Nick Carr (@itsreallynick), that
discusses the latest in information security, cyber espionage, attack
trends, and tales from the front lines of responding to targeted
intrusions. You can catch it live each month on FireEye's Twitter
account: https://twitter.com/fireeye

View Details

“Activity Round-up”: This week, we talk about new techniques being
used by Iran's "MuddyWater" (TEMP.Zagros) and Vietnam's APT32. We
discuss our Mandiant response efforts into large Chinese espionage
campaigns that have picked up in the past year, highlighting both
APT20 targeting of service providers and some fresh TEMP.Periscope
activity at many clients.

“What to Expect When You’re Resetting”: We describe several approaches
and challenges with mid-breach enterprise password resets - and the
results of Christopher’s polls on your experiences.

“Cafe Bohannon”: We close with a chat with Daniel Bohannon
(@danielhbohannon) about good coffee, "tasteful obfuscation," and
preview of DBO's upcoming Black Hat Asia 2018 research & tool
releasing next week.

Referenced material:
• MuddyWater blog post:
https://www.fireeye.com/blog/threat-research/2018/03/iranian-threat-gr
oup-updates-ttps-in-spear-phishing-campaign.html
• One of the APT32 backdoors, using DLL sideloading (from ESET):
https://www.welivesecurity.com/2018/03/13/oceanlotus-ships-new-backdoo
r/
• Chinese aligned cyber espionage activity from TEMP.Periscope:
https://www.fireeye.com/blog/threat-research/2018/03/suspected-chinese
-espionage-group-targeting-maritime-and-engineering-industries.html

State of the Hack is FireEye’s monthly live broadcast series, hosted
by Christopher Glyer (@cglyer) and Nick Carr (@itsreallynick), that
discusses the latest in information security, cyber espionage, attack
trends, and tales from the front lines of responding to targeted
intrusions.

View Details

FireEye Chief Security Architect, Christopher Glyer and Senior
Manager, Security Consulting and Incident Response, Nick Carr share
their thoughts on the Olympics, APT37 and FireEye's latest freeware
offerings.

You can catch the web series live each month on @FireEye:
https://twitter.com/fireeye