/* ---- Google Analytics Code Below */
Showing posts with label Insikt Group. Show all posts
Showing posts with label Insikt Group. Show all posts

Monday, August 09, 2021

Protect Against BlackMatter Ransomware Before It’s Offered

 Somewhat unclear the breadth of what is being offered, but interesting. 

Protect Against BlackMatter Ransomware Before It’s Offered

Insikt Group

Editor’s Note: The following post is an excerpt of a full report. To read the entire analysis, click here to download the report as a PDF. 

Insikt Group reverse-engineered the Linux and Windows variants of BlackMatter ransomware and provided a high-level overview of the functionality in addition to IOCs, utilities, and detections. The intended audience of this research is threat intelligence professionals and those interested in a technical overview of the new ransomware variant.

Executive Summary

Insikt Group analyzed Windows and Linux variants of BlackMatter ransomware, a new ransomware-as-a-service (RaaS) affiliate program founded in July 2021. During our technical analysis, we found that both variants accomplish similar goals of encrypting a victim’s files and appear to have been developed by a relatively sophisticated group. The Windows version of the ransomware employs several obfuscation and anti-reverse engineering techniques, suggesting that it was created by an experienced ransomware developer. BlackMatter’s Linux variant is another example of an emerging trend of malware targeting Linux-based systems, including ESXi and network-attached storage (NAS) devices. Recorded Future has provided reverse-engineering utilities, a YARA rule, and IOCs that organizations can use to hunt or detect the ransomware.

Editor’s Note: This post was an excerpt of a full report. To read the entire analysis, click here to download the report as a PDF.  https://go.recordedfuture.com/hubfs/reports/MTP-2021-0804.pdf

Friday, November 20, 2020

Insikt Group to Reduce Risk

Like the idea of risk reduction being specifically included, rarely done well enough, and especially  useful ly and measurably.   Just brought to my attention.

How Insikt Group’s Operational Outcomes Team Drives Action to Reduce Risk  By Lindsay Kaye

I’m Lindsay Kaye, the director of operational outcomes for Insikt Group®. Insikt Group as a whole produces analyst-generated insights to generate validated intelligence sources within the Recorded Future® Platform. Insikt Group also performs novel security intelligence research in a variety of different areas, including nation-state threat actor groups, threat actors operating in the criminal underground, and all manner of technical topics.

Simply put, the operational outcomes team creates insights that drive action that can be taken to reduce the risk associated with an identified threat. Our team also specializes in technical research, supporting our own focus area and other specialized teams within Insikt Group.  ... " 


Monday, November 09, 2020

Podcast from Recorded Future on Trickbot

Been following the security implications.  Here a podcast by former security connections at Recorded Future on the topic: 

Trickbot is Down But Not Out    By Caitlin Mattingly

On today’s podcast episode we welcome back Recorded Future’s senior intelligence analyst Greg Lesnewich.

He shares his insights on what goes on behind the scenes with the Recorded Future’s Insikt Group   , and why he finds the work challenging and rewarding. Then, we discuss the latest on the Trickbot global botnet, how they operate, who they target, and the efforts by the intelligence community and private industry to take them down, or at the very least hinder their efforts.  ... "