False Face: Unit 42 Demonstrates the Alarming Ease of Synthetic Identity...
North Korean IT workers are reportedly using real-time deepfakes to secure remote work, raising serious security concerns. We explore the implications. The post False Face: Unit 42 Demonstrates the...
View ArticleUnit 42 Looks Toward the Threat Frontier: Preparing for Emerging AI Risks
The Unit 42 Threat Frontier report discusses GenAI's impact on cybersecurity, emphasizing the need for AI-specific defenses and proactive security. The post Unit 42 Looks Toward the Threat Frontier:...
View ArticleUnit 42 Attack Surface Threat Research: Over 23% of Internet-Connected...
Find out which industries have the most rapidly expanding attack surfaces from a survey of 260+ orgs in Unit 42’s 2024 Attack Surface Threat Report. The post Unit 42 Attack Surface Threat Research:...
View ArticleThe Contrastive Credibility Propagation Algorithm in Action: Improving...
Our novel contrastive credibility propagation algorithm improves on data loss prevention and has unique applications to sensitive material. The post The Contrastive Credibility Propagation Algorithm in...
View ArticleLeveraging DNS Tunneling for Tracking and Scanning
We provide a walkthrough of how attackers leverage DNS tunneling for tracking and scanning, an expansion of the way this technique is usually exploited. The post Leveraging DNS Tunneling for Tracking...
View ArticleNavigating the Cloud: Exploring Lateral Movement Techniques
We illuminate lateral movement techniques observed in the wild within cloud environments, including Amazon Web Services (AWS), Google Cloud Platform (GCP) and Microsoft Azure. The post Navigating the...
View ArticleIntruders in the Library: Exploring DLL Hijacking
Dynamic-link library (DLL) hijacking remains a popular technique to run malware. We address its evolution using examples from the realm of cybercrime and more. The post Intruders in the Library:...
View ArticleLogit-Gap Steering: A New Frontier in Understanding and Probing LLM Safety
New research from Unit 42 on logit-gap steering reveals how internal alignment measures can be bypassed, making external AI security vital. The post Logit-Gap Steering: A New Frontier in Understanding...
View ArticleA Mega Malware Analysis Tutorial Featuring Donut-Generated Shellcode
A beginner-friendly tutorial on analyzing .NET malware teaches you how to use common tools, recognize techniques and understand infection chains. The post A Mega Malware Analysis Tutorial Featuring...
View ArticleMuddled Libra’s Strike Teams: Amalgamated Evil
A look at the variance within Muddled Libra (aka Scattered Spider, Octo Tempest). Its lack of structure creates multiple teams with distinct skill sets. The post Muddled Libra’s Strike Teams:...
View ArticleMuddled Libra: Why Are We So Obsessed With You?
Muddled Libra gets media attention due to its consistent playbook and unique use of vishing. The group's English fluency is another major factor. The post Muddled Libra: Why Are We So Obsessed With...
View ArticleWireshark Tutorial: Exporting Objects From a Pcap
This Wireshark tutorial guides the reader in exporting different packet capture objects. It builds on a foundation of malware traffic analysis skills. The post Wireshark Tutorial: Exporting Objects...
View ArticleExploring the Latest Mispadu Stealer Variant
Evaluation of a new variant of Mispadu, a banking Trojan, highlights how infostealers evolve over time and can be hard to pin to past campaigns. The post Exploring the Latest Mispadu Stealer Variant...
View ArticleThreat Vector Podcast
About Threat Vector Threat Vector is the Palo Alto Networks podcast hosted by David Moulton, Unit 42's Director of Thought Leadership. The podcast features in-depth discussions with industry leaders,...
View ArticleWireshark Tutorial: Identifying Hosts and Users
When a host is infected or otherwise compromised, security professionals need to quickly review packet captures of suspicious network traffic to identify affected hosts and users. This tutorial offers...
View ArticleWireshark Tutorial: Display Filter Expressions
This is a tutorial about using Wireshark, a follow-up to "Customizing Wireshark – Changing Your Column Display." It offers guidelines for using Wireshark filters to review and better understand pcaps...
View ArticleCrossing the Line: Unit 42 Wireshark Quiz for RedLine Stealer
RedLine stealer harvests credentials and other data from a Windows host. Part one of this Wireshark tutorial analyzes RedLine traffic to determine what data was stolen. The post Crossing the Line: Unit...
View ArticleCobalt Strike Analysis and Tutorial: Identifying Beacon Team Servers in the Wild
We present new techniques that leverage active probing and network fingerprint technology to help you detect Cobalt Strike’s Team Servers. The post Cobalt Strike Analysis and Tutorial: Identifying...
View ArticleTor 101: How Tor Works and its Risks to the Enterprise
People use Tor for both benign and malicious reasons, but allowing Tor traffic on enterprise networks opens the door to security risks. The post Tor 101: How Tor Works and its Risks to the Enterprise...
View Articledotnetfile Open Source Python Library: Parsing .NET PE Files Has Never Been...
The dotnetfile library extracts useful information from .NET PE files and can overcome common techniques malware authors use to break parsing. The post dotnetfile Open Source Python Library: Parsing...
View Article