
Threat Hunting Case Study: FileFix
FileFix bypasses Mark of the Web (MotW) protections by hijacking the Windows File Explorer address bar. Here is how to hunt for it.

At a state level, Russia is a top-tier cyber power, with capable advanced persistent threat groups. It is also the source of a significant amount of underground cybercriminal activity. That activity is a product of its strong educational systems but poor economic opportunity for IT professionals and low penalties for cybercrime, according to U.S. Department of Defense Analyst Alec Jackson who recently wrote a paper, “How the Collapse of the Soviet Union Made Russia a Great Cyber Power.” In this Studio 471, Jackson discusses how deep, institutional corruption ties Russian IT professionals, organized criminal groups and the state together and how Russia leverages this to its advantage.
Participants:
Alec Jackson, Analyst, U.S. Department of Defense
Jeremy Kirk, Executive Editor, Cyber Threat Intelligence, Intel 471

FileFix bypasses Mark of the Web (MotW) protections by hijacking the Windows File Explorer address bar. Here is how to hunt for it.

Gentlemen ransomware uses credential abuse, defense evasion, and double extortion tactics to compromise enterprise environments and increase pressure on victims.

TeamPCP is exploiting trusted npm and PyPI packages to compromise developer environments, steal credentials, and extend attacks across software supply chains.
Stay informed with our weekly executive update, sending you the latest news and timely data on the threats, risks, and regulations affecting your organization.