{"id":16918,"date":"2019-11-18T10:52:16","date_gmt":"2019-11-18T18:52:16","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/11\/18\/news-10655\/"},"modified":"2019-11-18T10:52:16","modified_gmt":"2019-11-18T18:52:16","slug":"news-10655","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/11\/18\/news-10655\/","title":{"rendered":"VB2019 video: Discretion in APT: recent APT attack on crypto exchange employees"},"content":{"rendered":"<p>In June, employees at cryptocurrency exchange\u00a0<em>Coinbase<\/em>\u00a0were targeted by emails linking to a website that used two zero-day vulnerabilities in the <em>Firefox<\/em> browser to deliver <em>macOS<\/em> malware. The malware, dubbed &#8216;NetWire&#8217;, had previously been known but the exploit allowed it to bypass built-in protections against it. The NetWire sample was analysed by regular VB conference speaker Patrick Wardle in three parts (<a href=\"https:\/\/objective-see.com\/blog\/blog_0x43.html\" target=\"_blank\">1<\/a>, <a href=\"https:\/\/objective-see.com\/blog\/blog_0x44.html\" target=\"_blank\">2<\/a>, <a href=\"https:\/\/objective-see.com\/blog\/blog_0x45.html\" target=\"_blank\">3<\/a>) on his blog.<\/p>\n<p><em>Coinbase<\/em> wasn&#8217;t the only exchange targeted though. In a presentation at VB2019 in London, <em>LINE<\/em>&#8216;s\u00a0HeungSoo (David) Kang disclosed that\u00a0<em>LINE<\/em>, which also operates cryptocurrency exchanges, had been targeted in the same campaign.<\/p>\n<p>In his talk,\u00a0HeungSoo explained both how the attack works and what it looked like from both the defender&#8217;s and the adversary&#8217;s point of view. Though attacks using zero-days are rare, when they happen they provide an excellent opportunity to highlight the pain points for a blue team.<\/p>\n<p>Today, we published the video of\u00a0HeungSoo&#8217;s presentation in London.<\/p>\n<p style=\"text-align: center;\" width=\"100%\" height=\"420\"><iframe loading=\"lazy\" src=\"https:\/\/www.youtube.com\/embed\/QXIJTK0Zsmw\" frameborder=\"0\" width=\"100%\" height=\"420\" style=\"\"> <\/iframe><\/p>\n<p>\u00a0<\/p>\n<p>outertext<br \/><a href=\"https:\/\/www.virusbulletin.com\/blog\/2019\/11\/vb2019-video-discretion-apt-recent-apt-attack-crypto-exchange-employees\/\" target=\"bwo\" >https:\/\/www.virusbulletin.com\/rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>                                 At VB2019 in London, LINE&#8217;s HeungSoo Kang explained how cryptocurrency exchanges had been attacked using Firefox zero-days. Today, we publish the video of his presentation.                <\/p>\n<p>                 <a href=\"https:\/\/www.virusbulletin.com\/blog\/2019\/11\/vb2019-video-discretion-apt-recent-apt-attack-crypto-exchange-employees\/\">Read more<\/a>                                <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[23177,10378,23176],"tags":[],"class_list":["post-16918","post","type-post","status-publish","format-standard","hentry","category-magazine","category-security","category-virusbulletin"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16918","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=16918"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16918\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=16918"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=16918"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=16918"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}