• Credential harvesters in the cloud.

  • Nov 16 2024
  • Length: 19 mins
  • Podcast

Credential harvesters in the cloud.

  • Summary

  • This week we are joined by, Blake Darché, Head of Cloudforce One at Cloudflare, to discuss their work on "Unraveling SloppyLemming’s Operations Across South Asia." Cloudforce One's investigation into the advanced threat actor "SloppyLemming" reveals an extensive espionage campaign targeting South and East Asia, with a focus on Pakistan's government, defense, telecommunications, and energy sectors. Leveraging multiple cloud service providers, SloppyLemming employs tactics like credential harvesting, malware delivery, and command-and-control (C2) operations, often relying on open-source adversary emulation tools like Cobalt Strike. Despite its activities, the actor's poor operational security (OPSEC) has allowed investigators to gain valuable insights into its infrastructure and tooling. The research can be found here: Unraveling SloppyLemming’s operations across South Asia Learn more about your ad choices. Visit megaphone.fm/adchoices
    Show more Show less
activate_Holiday_promo_in_buybox_DT_T2

What listeners say about Credential harvesters in the cloud.

Average customer ratings

Reviews - Please select the tabs below to change the source of reviews.