Discover this podcast and so much more

Podcasts are free to enjoy without a subscription. We also offer ebooks, audiobooks, and so much more for just $11.99/month.

PoetRAT: a complete lack of operational security. [Research Saturday]

PoetRAT: a complete lack of operational security. [Research Saturday]

FromCyberWire Daily


PoetRAT: a complete lack of operational security. [Research Saturday]

FromCyberWire Daily

ratings:
Length:
21 minutes
Released:
Nov 7, 2020
Format:
Podcast episode

Description

Cisco Talos discovered PoetRAT earlier this year. Since then, they observed multiple new campaigns indicating a change in the actor's capabilities and showing their maturity toward better operational security. They assess with medium confidence this actor continues to use spear-phishing attacks to lure a user to download a malicious document from temporary hosting providers. They currently believe the malware comes from malicious URLs included in the email, resulting in the user clicking and downloading a malicious document. These Word documents continue to contain malicious macros, which in turn download additional payloads once the attacker sets their sites on a particular victim. As the geopolitical tensions grow in Azerbaijan with neighboring countries, this is no doubt a stage of espionage with national security implications being deployed by a malicious actor with a specific interest in various Azerbajiani government departments.
Joining us in this week's Research Saturday to discuss the research from Cisco's Talos Outreach is Craig Williams.
The research can be found here: 
PoetRAT: Malware targeting public and private sector in Azerbaijan evolves
Released:
Nov 7, 2020
Format:
Podcast episode