Ransomware Economy Players, Pentest War Stories, & Ransomware Groups Working Together - ESW #329

Published: Aug. 25, 2023, 9 p.m.

b'

During this segment, Jon will explore today\\u2019s ransomware economy players from IABS to RaaS affiliates, to money launders and now C2Ps. For the discussion, Jon will leverage Halcyon\\u2019s latest research, which demonstrates a new technique to uncover how C2Ps, like Cloudzy, are used to identify upcoming ransomware campaigns and other advanced attacks. The research revealed that Cloudzy, knowingly or not, provided services to attackers while assuming a legitimate business profile. Threat actors that leveraged Cloudzy include APT groups tied to the Chinese, Iranian, North Korean, Russian, Indian, Pakistani, and Vietnamese governments; a sanctioned Israeli spyware vendor whose tools are known to target civilians; several criminal syndicates and ransomware affiliates whose campaigns have spurred international headlines.

This segment is sponsored by Halcyon. Visit https://securityweekly.com/halcyonbh\\xa0to learn more about them!

\\xa0

In this session, Snehal will discuss several real-world examples of what autonomous pentesting discovered in networks just like yours. You\\u2019ll hear more about how fast and easy it was to safely compromise some of the biggest (and smallest) networks in the world - with full domain takeover in a little more than a few hours. Learn how you can safely do the same in your own network today!

This segment is sponsored by Horizon3.ai. Visit https://securityweekly.com/horizon3aibh\\xa0to learn more about them!

\\xa0

In this Black Hat 2023 interview, CRA\\u2019s Bill Brenner and Sophos\\u2019 John Shier discuss the company\\u2019s latest research on the Royal ransomware gang. Though Royal is a notoriously closed off group that doesn\\u2019t openly solicit affiliates from underground forums, granular similarities in the forensics of the attacks suggest all three groups are sharing either affiliates or highly specific technical details of their activities.

This segment is sponsored by Sophos. Visit https://securityweekly.com/sophosbh\\xa0to learn more about them!

Visit https://www.securityweekly.com/esw\\xa0for all the latest episodes!

Show Notes: https://securityweekly.com/esw-329\\xa0

'