VB2016 paper: APT reports and OPSEC evolution, or: these are not the APT reports you are looking for

Posted by   Martijn Grooten on   Feb 17, 2017

Ever since Mandiant released its APT1 report four years ago, reports on advanced attack groups have been an important fixture in the security industry. These reports are great for gaining an understanding of how such groups operate and, as a not insignificant aside, a nice PR exercise for the companies that publish them.

However, one aspect may be overlooked: they also provide free QA for the threat actors, who often respond quickly and stop making the mistakes that led to their activities being discovered. This is what worried industry veterans Gadi Evron (Cymmetria) and Inbar Raz (Perimeter X), so they got together and wrote a paper on the subject, which they presented at VB2016 in Denver.

Today, we publish that paper, "APT reports and OPSEC evolution, or: these are not the APT reports you are looking for", in both HTML and PDF format. We have also uploaded the video to our YouTube channel.

Has your organization been attacked by an APT group? Of have you noticed how APT groups evolve because of reports detailing their activity? We'd like to hear from you. Submit an abstract for VB2017 (CFP deadline: 19 March) for a chance to present your research in Madrid, 4-6 October.

 

twitter.png
fb.png
linkedin.png
googleplus.png
reddit.png

 

Latest posts:

Consumer spyware: a serious threat with a different threat model

Consumer spyware is a growing issue and one that can have serious consequences: its use is increasingly common in domestic violence. But do our threat models consider the attacker with physical access to, and inside knowledge of the victim?

VB2016 paper: Debugging and monitoring malware network activities with Haka

In their VB2016 paper, Stormshield researchers Benoît Ancel and Mehdi Talbi introduced Haka, an open-source language to monitor, debug and control malicious network traffic. Both their paper and the video recording of their presentation are now…

VB2017: a wide ranging and international conference programme

We are proud to announce a very broad and very international programme for VB2017, which will take place in Madrid, 4-6 October 2017.

John Graham-Cumming and Brian Honan to deliver keynote addresses at VB2017

Virus Bulletin is excited to announce John-Graham Cumming and Brian Honan as the two keynote speakers for VB2017 in Madrid.

Virus Bulletin says a fond farewell to John Hawes

As VB's COO John Hawes moves on to new challenges, the team wish him a fond farewell and good luck in his future endeavours.