VB2016 paper: APT reports and OPSEC evolution, or: these are not the APT reports you are looking for

Posted by   Martijn Grooten on   Feb 17, 2017

Ever since Mandiant released its APT1 report four years ago, reports on advanced attack groups have been an important fixture in the security industry. These reports are great for gaining an understanding of how such groups operate and, as a not insignificant aside, a nice PR exercise for the companies that publish them.

However, one aspect may be overlooked: they also provide free QA for the threat actors, who often respond quickly and stop making the mistakes that led to their activities being discovered. This is what worried industry veterans Gadi Evron (Cymmetria) and Inbar Raz (Perimeter X), so they got together and wrote a paper on the subject, which they presented at VB2016 in Denver.

Today, we publish that paper, "APT reports and OPSEC evolution, or: these are not the APT reports you are looking for", in both HTML and PDF format. We have also uploaded the video to our YouTube channel.

Has your organization been attacked by an APT group? Of have you noticed how APT groups evolve because of reports detailing their activity? We'd like to hear from you. Submit an abstract for VB2017 (CFP deadline: 19 March) for a chance to present your research in Madrid, 4-6 October.

 

twitter.png
fb.png
linkedin.png
googleplus.png
reddit.png

 

Latest posts:

VB2016 paper: Steam stealers: it's all fun and games until someone's account gets hijacked

Last year, Kaspersky Lab researcher Santiago Pontiroli and PwC's Bart Parys presented a VB2016 paper analysing the malicious threats faced by users of the Steam online gaming platform, and highlighting how organized criminals are making money with…

Research paper shows it may be possible to distinguish malware traffic using TLS

Researchers at Cisco have published a paper describing how it may be possible to use machine learning to distinguish malware command-and-control traffic using TLS from regular enterprise traffic, and to classify malware families based on their…

Is CVE-2017-0199 the new CVE-2012-0158?

After five years of exploitation in a wide variety of attacks, CVE-2012-0158 may have found a successor in CVE-2017-0199, which is taking the Office exploit scene by storm.

Review: BSides London 2017

Virus Bulletin was a proud sponsor of BSides London 2017 - Martijn Grooten reports on a great event.

VB2017: one of the most international security conferences

It is well known that the problem of cybersecurity is a global one that affects users worldwide - but it's also one that has some unique local flavours. With speakers representing at least 24 countries, VB2017 is one of the most international…