Mlw #41: a new sophisticated loader by APT group TA505 | Alexey Vishnyakov | NULLCON Goa 2020

46:00 · 06 Mar 2020 – 07 Mar 2020 · YouTube

About this talk

This talk focuses on the sophisticated cybercriminal group TA505, recognized for their development of malware families such as Dridex, ServHelper, and FlawedGrace. The speaker, Alexey Vishnyakov, delves into the techniques used by the group to maintain persistent implants that are hard to detect and discusses their evolving toolset. Key topics include the new loader utilized by TA505, the usage of the KUSER_SHARED_DATA structure, and methods for circumventing standard security techniques through on-the-fly JScript and PowerShell scripts. The session also covers their persistence methods, configuration data storage, and stealthy network interactions with command and control servers via DNS tunneling. Alexey brings extensive experience in threat analysis, having worked with prominent cybersecurity firms and investigated numerous malicious actors.

From event

NULLCON Goa 2020

06 Mar 2020 – 07 Mar 2020

All event videos
Back to Watch