Exploring the Labyrinth of Macos Intrusions - ATT&CKcon 4.0 Day 1

แชร์
ฝัง
  • เผยแพร่เมื่อ 10 ธ.ค. 2023
  • ATT&CKcon 4.0 Day 1
    LABYRINTH CHOLLIMA is a prolific Democratic People's Republic of Korea (DPRK) nexus adversary focused on cyber espionage. They have been recently observed targeting FinTech (financial technology) companies in cryptocurrency revenue generation efforts. LABYRINTH CHOLLIMA has been associated with many high profile attacks, including the Sony Pictures Entertainment (SPE) breach, the WannaCry 2.0 global surge, and most recently, the 3CX supply chain compromise. Increasingly versed in cross-platform intrusions, LABYRINTH CHOLLIMA has been observed targeting macOS operating systems, and evolving their tactics, techniques, and tooling to keep in lockstep with the evolving security landscape.
    This talk will deep dive into the interactive macOS intrusions Crowdstrike has attributed to LABYRINTH CHOLLIMA. We will delve into the adversary's macOS tradecraft, techniques to circumvent existing OS protections, and social engineering tactics, while showcasing how their mechanisms and tooling map to the MITRE ATT&CK kill chain, featuring some newly proposed MITRE techniques related to the Transparency, Consent, and Control (TCC) database.
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 1

  • @alexandercasian4904
    @alexandercasian4904 3 หลายเดือนก่อน

    This video is so underrated. Good and very informative presentation!