Mlw #41: a new sophisticated loader by APT group TA505 | Alexey Vishnyakov | NULLCON Goa 2020
About this talk
This talk focuses on the sophisticated cybercriminal group TA505, recognized for their development of malware families such as Dridex, ServHelper, and FlawedGrace. The speaker, Alexey Vishnyakov, delves into the techniques used by the group to maintain persistent implants that are hard to detect and discusses their evolving toolset. Key topics include the new loader utilized by TA505, the usage of the KUSER_SHARED_DATA structure, and methods for circumventing standard security techniques through on-the-fly JScript and PowerShell scripts. The session also covers their persistence methods, configuration data storage, and stealthy network interactions with command and control servers via DNS tunneling. Alexey brings extensive experience in threat analysis, having worked with prominent cybersecurity firms and investigated numerous malicious actors.
More from this event
See all 39 talks →
ML for security and security for ML | Training Tidbits | Nikhil Joshi | NULLCON Goa | March 2020
0:30
Practical IoT Hacking | Training Tidbits | Aseem Jakhar | NULLCON Goa | March 2020
0:54
Hacking iOS Applications, Like A Pro | Training Tidbits | Abhinav Mishra | NULLCON Goa | March 2020
1:14
Windows Kernel Exploitation - Foundation & Advanced | Training Tidbits | Ashfaq Ansari #NULLCON2020
0:36