Cisco Talos Intelligence Blog

September 29, 2020 12:09

LodaRAT Update: Alive and Well

By Chris Neal. * During our continuous monitoring of LodaRAT, Cisco Talos observed changes in the threat that add new functionality. * Multiple new versions of LodaRAT have been spotted being used in the wild. * These new versions of LodaRAT abandoned their previous obfuscat

March 31, 2020 13:03

Trickbot: A primer

By Chris Neal Executive Summary * Trickbot remains one of the most sophisticated banking trojans in the landscape while constantly evolving. * Highly modular, Trickbot can adapt to different environments with the help of its various modules. * The group behind Trickbot has

February 25, 2020 16:02

New Research Paper: Prevalence and impact of low-entropy packing schemes in the malware ecosystem

Detection of malware is a constant battle between the technologies designed to detect and prevent malware and the authors creating them. One common technique adversaries leverage is packing binaries. Packing an executable is similar to applying compression or encryption and can i

February 12, 2020 14:02

Loda RAT Grows Up

By Chris Neal. * Over the past several months, Cisco Talos has observed a malware campaign that utilizes websites hosting a new version of Loda, a remote access trojan (RAT) written in AutoIT. * These websites also host malicious documents that begin a multi-stage infection c

July 31, 2019 11:07

Malvertising: Online advertising's darker side

Executive summary One of the trickiest challenges enterprises face is managing the balance between aggressively blocking malicious advertisements (aka malvertising) and allowing content to remain online, accessible for the average user. The days of installing a basic ad blocker