Damus

Recent Notes

Josh Bressers · 4w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqnyqeg55nq5eudx30py8fgff82ensxt9j063w6chkzu4leyfjygwsfcp9u9 nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq8w7uk4cll226wlw4ukykpu9xlxlvcdwfz7vcdx3k0rg47ynyg7lsnec808 I think I remember windows NT having this, but it’s been a while 2000...
Marcus Hutchins :verified: profile picture
Found an interesting new malware loader which creates a fake Windows lock screen to phish the user's system login password. The fully-modular loader also bridges multitude different programming languages, including: Python, C#, C++, and PowerShell.

This extensive use of cross-language components, along with shipping an entire runtime environment, lead to us dubbing it SynkLoader (Sink Loader), because it brings everything but the kitchen sink.

While the original loader runs all of its modules in memory only, we were able to collect them by reverse engineering the command-and-control protocol, then building our own version of the loader which logs everything to disk.

Additionally, we were able to to lure the operator into thinking they had a reverse shell on our honeypot system. This allowed us to watch as they attempted to execute PowerShell commands, which were being printed to our system's console instead of being run.

Full analysis: https://expel.com/blog/synkloader-when-you-throw-in-everything-but-the-kitchen-sink/

3
Lesley Carhart :unverified: · 4w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqnyqeg55nq5eudx30py8fgff82ensxt9j063w6chkzu4leyfjygwsfcp9u9 I’m kind of pissed I didn’t think of that, honestly
Eleanor Saitta · 4w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqnyqeg55nq5eudx30py8fgff82ensxt9j063w6chkzu4leyfjygwsfcp9u9 It's like there was a reason for the secure attention key
SomeVeganCheeseIsOk · 4w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqnyqeg55nq5eudx30py8fgff82ensxt9j063w6chkzu4leyfjygwsfcp9u9 dude that is amazing work.
Will Harris · 19w
Try out the early alpha of Process Isolation in Chrome 138. chrome://flags/#enable-process-isolation-ui then chrome://settings/system for the switch. Read known issues https://issues.chromium.org/issu...
Marcus Hutchins :verified: profile picture
@nprofile1q... Nice work dude! I assume this locks down the ABE bypasses that work via injecting into the broker and hijacking the COM session?

Does it also apply to Chrome processes launched via CreateProcess suspended for process hollowing purposes?
1
Will Harris · 18w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqnyqeg55nq5eudx30py8fgff82ensxt9j063w6chkzu4leyfjygwsfcp9u9 yes it prevents that, and hollowing, and debugging. But the security properties are not yet fully hardened so right now I'm really looking for any feedback on App-Compat issues. Try it o...
Marcus Hutchins :verified: profile picture
I spent nearly 4 months investigating the inner workings of a North Korean state-sponsored hacking group. Here's what I found:

- The group used generative AI tools to aid in almost every part of their operations.

- They exfiltrated 26,584 cryptocurrency wallets from victim systems, with a combined value totaling as much $12 million dollars.

- In several cases, the threat actors set up entire front companies to lure in developers via fake job posting, then infected them with malware.

- The threat actors successfully pulled off a supply-chain attack by compromising a VS Code extension developer's system.

🔗 Full article: https://expel.com/blog/inside-lazarus-how-north-korea-uses-ai-to-industrialize-attacks-on-developers/

2
Lee Holmes :donor: · 21w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqnyqeg55nq5eudx30py8fgff82ensxt9j063w6chkzu4leyfjygwsfcp9u9 One of the things I love about this investigation is that it actually imposed cost: - Found malware: reported to AV vendors - Saw abuse of Cursor: reported to Cursor, got the accounts s...
johnbrown · 21w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqnyqeg55nq5eudx30py8fgff82ensxt9j063w6chkzu4leyfjygwsfcp9u9 do you have any first hand evidence of this I can peruse? You know, you hear SO MUCH about that little impoverished, low tech communist country basically being super hackers, behind mo...
~w00p~ · 27w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqnyqeg55nq5eudx30py8fgff82ensxt9j063w6chkzu4leyfjygwsfcp9u9 😂
James Cridland · 27w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqnyqeg55nq5eudx30py8fgff82ensxt9j063w6chkzu4leyfjygwsfcp9u9 Not sure that Proton’s 100% true statement - that they only respond to requests fr...
Marcus Hutchins :verified: profile picture
@nprofile1q... Each sentence of your comment is increasingly dumber than the last. "We’re all aware that international treaties exist" yeah, your average internet user definitely understands international legal assistance processes.

There's nothing "FUD" about my statement. It contains only facts which enable users to better inform their decisions.

"breaking US tax law is unlikely to have any impact on Swiss authorities" Is an extremely funny statement given it was the US who forced Switzerland to roll back some of it's bank secrecy laws so the US could go after tax evaders.

If you're gonna accuse me of spreading FUD, at least put in a modicum of effort.
1
James Cridland · 27w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqnyqeg55nq5eudx30py8fgff82ensxt9j063w6chkzu4leyfjygwsfcp9u9 Oh, you’re someone who responds to feedback by giving personal insults. That’s a shame.
Marcus Hutchins :verified: profile picture
It feels like Proton are being intentionally misleading in their statements. They know that most of their customers aren't familiar with how legal process actually works, so are happy to spread half-truths.

Under US law, a US law enforcement agency (LEA) typically has to apply for a subpoena or search warrant with a US court. The court is then responsible for deciding if the legal bar for search a request has been met, then either grants or denies it.

The problem is, if a company has no real US footprint (no US corporate entity, offices, servers, etc.), then a US court typically doesn't have the jurisdiction to compel the company to hand over customer data (except in some rare circumstances). Even if the court approved the warrant anyway, it wouldn't really be legally binding.

Which is why the Mutual Legal Assistance Treaty (MLAT) exists. MLAT enables law enforcement agencies in one company to send requests for information to law enforcement agencies in another. Switzerland has such a treaty with the US. This means that the FBI can request that Swiss authorities hand over a Swiss company's data on their behalf.

Any country requesting information held by a company in a foreign jurisdiction would typically do so via MLAT. Which means from Proton's perspective, the legal request would appear to originate from their local law enforcement, not the FBI. Which they clearly understand based on their Reddit post.

Saying "we don't respond to legal requests from anywhere other than Swiss authorities" seems very intentionally worded to give the impression that the company does not cooperate with foreign law enforcement. But since it'd be the Swiss authorities handling any such requests, they'd have to comply, since as they admitted, they have to comply with local laws.

There is, however, some useful (but more nuanced) information here:

Firstly, MLAT requests are handled by local law enforcement according to local law. So if there is a difference between the law of the sending and recipient country, that might mean the MLAT request is denied. That probably doesn't mean much, because if you're on the FBI's radar, the chances are you did something that is also massively illegal in Switzerland too.

Secondly, they are 100% correct in saying that no other service provider is going to do any better. They're all beholden to local laws, and the ones that think they're not tend to get their doors blown off by SWAT like CyberBunker did. The only exception is if the company resides in a country which does not cooperate with US law enforcement (which Proton does not).

But the part that's extremely disingenuous is that the "we only respond to requests from the Swiss authorities". That statement is likely intended to imply they don't cooperate with law enforcement in any other countries, which is simply not true. Switzerland has MLAT agreements with over 30 counties.

People really need to understand that no company is going to shield you from the FBI (or any reputable law enforcement agency). They'll use misleading statements to make it sounds like they don't cooperate with law enforcement, but they do. They have to.

3
James Cridland · 27w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqnyqeg55nq5eudx30py8fgff82ensxt9j063w6chkzu4leyfjygwsfcp9u9 Not sure that Proton’s 100% true statement - that they only respond to requests from the Swiss authorities - is “intentionally misleading”. As you have outlined, it is literally ...
Diogo Constantino · 27w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqnyqeg55nq5eudx30py8fgff82ensxt9j063w6chkzu4leyfjygwsfcp9u9 that's not misleading it's actual thruth. Italia the Switz authoroties that are collaborating with the foreign authorities under the MLAT.
Tobin Baker · 27w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqnyqeg55nq5eudx30py8fgff82ensxt9j063w6chkzu4leyfjygwsfcp9u9 also the screenshotted response reads like AI
~w00p~ · 28w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqnyqeg55nq5eudx30py8fgff82ensxt9j063w6chkzu4leyfjygwsfcp9u9 No more WFH for you peasants!
Mike Sheward · 28w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqnyqeg55nq5eudx30py8fgff82ensxt9j063w6chkzu4leyfjygwsfcp9u9 nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqc8n47hczxyykam2c3ndtyxa3amtfrr8n94cmll879s6fn60cuztsrqnt3x The Willow Ballroom - Daily Schedule: 12pm - 1pm: Jazzercise with Jean...