00:00:03.759 --> 00:00:10.640
You're listening to Discarded: Tales from the Threat Research Trenches, a podcast by Proofpoint for security practitioners.
00:00:10.880 --> 00:00:22.480
Each episode you'll hear from security researchers, malware analysts, threat hunters, and more as we dive into what's going on in the world of cyber attacks and how defenders safeguard us from threats.
00:00:22.640 --> 00:00:24.320
Let's get into the show.
00:00:25.359 --> 00:00:34.320
Well, we're starting off with a rooster crow here on the Discarded Podcast because I am joined today by my colleague and collaborator, Sarah Sabotka.
00:00:34.399 --> 00:00:35.359
Sarah, how's it going?
00:00:35.520 --> 00:00:36.399
How are your roosters?
00:00:36.640 --> 00:00:37.039
It's good.
00:00:37.119 --> 00:00:39.359
The roosters are very busy today.
00:00:39.679 --> 00:00:40.719
Hey, you know what?
00:00:40.880 --> 00:00:44.719
They are enjoying a hot rooster summer.
00:00:45.039 --> 00:00:46.640
So they are, yes.
00:00:46.960 --> 00:00:48.159
Can't fault them for that.
00:00:48.399 --> 00:00:52.320
I am your host, Selena Larson, and today we are here with a very special guest.
00:00:52.560 --> 00:00:55.520
I almost said a special Greg, but you are special Greg.
00:00:55.679 --> 00:01:00.719
Our very special guest is Greg Lesniwich, principal threat researcher here on the Proof Point Threat Research team.
00:01:00.880 --> 00:01:01.840
Greg, how are you doing?
00:01:01.920 --> 00:01:02.640
How's it going?
00:01:02.960 --> 00:01:14.000
I am above average today, but it is delightful to be here with both of you today to riff andor raff and say hello to all of our cyber roosters.
00:01:14.879 --> 00:01:15.359
Yes.
00:01:15.599 --> 00:01:17.280
Hello to all our cyber roosters.
00:01:17.439 --> 00:01:20.959
Thank you for that intro, Greg, because I forgot to say that earlier.
00:01:21.120 --> 00:01:21.439
Wow.
00:01:21.680 --> 00:01:22.719
The first time I ever did.
00:01:22.879 --> 00:01:24.400
But the roosters will be heard.
00:01:24.480 --> 00:01:36.560
And you will also be heard because today we are talking about some really fun research, actually, that you recently published in collaboration with some very cool people and government entities, which is very exciting.
00:01:36.719 --> 00:01:38.239
And we're going to dive into that today.
00:01:38.400 --> 00:01:52.400
So can you give us an overview of the two reports that you recently released on Russian espionage actors using something called half-click exploits, which I wasn't super familiar with before these reports, so we will dive into what that actually means.
00:01:52.480 --> 00:01:53.760
But what's the TLDR?
00:01:53.840 --> 00:01:54.400
What happened?
00:01:54.719 --> 00:01:54.879
Yeah.
00:01:54.959 --> 00:01:56.159
So thank you guys for having me.
00:01:56.319 --> 00:02:00.879
The TLDR is we had two blogs out, and everybody listening to this should go read them.
00:02:01.120 --> 00:02:11.439
One of them was in collaboration with a number of government entities, which was kind of a cool thing to kind of collaborate on, like an actor discovery level.
00:02:11.599 --> 00:02:17.919
You know, it's old hat for threat research to be involved in collaborating with law enforcement on takedowns and disruptions.
00:02:18.000 --> 00:02:24.560
And so it was cool for this one to be on the discovery and front end of disclosing that some activity is happening.
00:02:24.800 --> 00:02:28.240
So both of them are Russian espionage actors.
00:02:28.400 --> 00:02:31.120
One we are highly convinced is GRU.
00:02:31.280 --> 00:02:35.120
The other we know is a contractor that we suspect operates for the GRU.
00:02:35.280 --> 00:02:53.280
And yeah, they use a subtle method of targeting their respective entities and their targets with a thing that we call half-click exploits to uh compromise the webmail viewer and then the back-end mail server for various open and closed source uh email providers.
00:02:53.360 --> 00:02:56.719
So we can get into the nitty-gritty details of that a little bit later.
00:02:56.879 --> 00:03:08.240
But yeah, it's kind of the one of the pieces of new hotness with or current hotness with uh Russian espionage actors, kind of the yin to device code phishings yang, if you will.
00:03:09.759 --> 00:03:10.400
Amazing.
00:03:10.639 --> 00:03:14.719
So the collaboration with public partners on this research was pretty incredible, Greg.
00:03:14.800 --> 00:03:21.280
I think that proof point threat research is definitely on a definite winning streak with collaborations globally.
00:03:21.360 --> 00:03:25.759
You know, we that's the being an official part of the Europol's advisory group lately.
00:03:25.919 --> 00:03:33.199
Can you just tell us, talk a little bit about what that collaboration looks like, how you how you did it and how it all kind of came to fruition?
00:03:33.599 --> 00:03:41.520
Yeah, I think that unlike most people, when a government agency calls a threat researcher, at least in our team, it's like usually a positive thing.
00:03:41.680 --> 00:03:46.319
Unlike with the average person, if you thought that the FBI was calling you, you might freak out a little bit.
00:03:46.479 --> 00:03:58.000
And yeah, it was just a pretty like enticing thing to not only share information, but also just kind of get their take on um on what was happening.
00:03:58.159 --> 00:04:22.160
And I think that the thing that was most satisfying or gratifying or whatever you'd want to call it is that this little cluster that became TA48 that was kind of a passion project of mine, bubbled up and hit hit enough of the wrong targets, I guess, that a bunch of the big boys in US government said that they wanted to out them and dance on their heads a little bit with what was going on.
00:04:22.240 --> 00:04:29.040
So I think the fact that like something that we had worked on that was relatively exclusive to proof point visibility.
00:04:29.199 --> 00:04:37.839
Some others have blogged about things related to this actor on stuff that was on VT, but not to the holistic level of what we were able to observe.
00:04:38.079 --> 00:04:46.319
And so the fact that like my little baby cluster got picked up enough to gather enough steam to be on this kind of level of blast was gratifying.
00:04:46.480 --> 00:04:50.720
And yeah, the people that we interact with are analysts just like everybody else that we talk to.
00:04:50.879 --> 00:04:58.639
Um, so it was kind of, you know, there was no peak behind the curtain necessarily as much as, oh, you're the analyst that works this on this side, here's what we're seeing.
00:04:58.879 --> 00:05:16.399
And yeah, I I think that the fact that we could help them do some stuff in quotes, that I am not privy to what that stuff actually is, but I think that the dear listener can infer and use their imagination as much as they want, even though we won't corroborate it, was kind of cool.
00:05:16.560 --> 00:05:22.720
And it, of course, is things for better or for worse move at government speed, which for those that don't know is incredibly slow.
00:05:23.040 --> 00:05:30.560
But yeah, it started out with sort of exchanging some information about some domains in like December of 2025.
00:05:31.439 --> 00:05:36.959
And now here we are in July with coordinated release on TA488.
00:05:37.279 --> 00:05:38.000
Awesome.
00:05:38.319 --> 00:05:44.079
So the reports highlight two different distinct Russian espionage threat actors.
00:05:44.319 --> 00:05:49.199
One is TA458, and the other is TA488.
00:05:49.600 --> 00:05:53.680
They do have some AKAs for those who might be a little bit more familiar.
00:05:53.839 --> 00:05:59.839
For example, TA488 is Void Blizzard and open source and a couple of other AKAs.
00:06:00.160 --> 00:06:18.480
If you're interested in what some of the activity overlaps with in our blog, because I know we're saying a lot of acronyms and numbers and AKAs throughout this conversation, as well as various CVE numbers that we will be referring to, definitely check out the blog posts and I will, of course, link to those in the show notes.
00:06:18.720 --> 00:06:32.079
So you track these two groups, again, TA458 and TA488, as two distinct threat actors, despite being both Russia aligned, specifically GRU aligned, and using similar tactics.
00:06:32.319 --> 00:06:36.879
So, what are the key behavioral or technical differences that keep them separated?
00:06:37.040 --> 00:06:39.279
How essentially in how you track them?
00:06:39.439 --> 00:06:43.680
And what's the easiest way for listeners to understand the difference between these two groups?
00:06:44.079 --> 00:06:46.639
Yeah, so I actually want to take a step back first.
00:06:46.800 --> 00:07:07.680
These originally had unk names that I know that Selena isn't the biggest fan of, but in in my personal view of our taxonomy, anything that is using one of these kind of half-click style exploits gets an unk name that refers to a piece of like F1 or car racing technology or a word pairing.
00:07:07.759 --> 00:07:11.199
So they used to be unk pit stop and unk heatsink.
00:07:11.519 --> 00:07:19.680
And upon graduation, there were two numbers in the 400s that were both Ferrari models, 458 and 488.
00:07:20.160 --> 00:07:24.879
And I just kind of had to stick with the bit and say, like, these numbers are available and I'm claiming them.
00:07:24.959 --> 00:07:30.720
Um, and so it was this kind of like full full circle thing to keep them kind of in like the automotive space.
00:07:30.959 --> 00:07:35.759
I didn't I didn't know you had a naming convention for the half-click exploit cinematic universe.
00:07:35.920 --> 00:07:36.319
Yeah.
00:07:36.639 --> 00:07:41.519
There's a lot of them, which mass traction is another one of them that we blogged about recently.
00:07:41.759 --> 00:07:52.000
But yeah, the main difference is I think, and the reason we keep them distinct is 458 is kind of the heavyweight in the space.
00:07:52.160 --> 00:07:59.439
Our kind of view into this exploit class was really a guy named Matthew Fow from ESET.
00:07:59.600 --> 00:08:08.800
Um, he put out a blog about Winter Vivern and then about what eventually for us became TA 458, I think in 2024 and 2025, respectively.
00:08:09.120 --> 00:08:15.600
And we saw these kind of class of vulnerability and said, well, if we're proof point, we should be the ones detecting and kind of finding these.
00:08:15.680 --> 00:08:27.839
And so 458 is the heavyweight in the space because they've been doing not only this style of exploitation, but they're doing it across multiple types of technology for I think like two or three years now.
00:08:28.079 --> 00:08:38.559
So they it's definitely something that they were early adopters on, and they definitely have just a broader arsenal in terms of what they are able to bring to bear.
00:08:38.799 --> 00:08:54.159
We know that they can operationalize end day exploits at a pretty rapid pace, and they are also regular users of Zero Day, which, as we're going to discuss in a little bit, these things are inherently cross-site scripting vulnerabilities in webmail providers.
00:08:54.320 --> 00:09:00.799
So we call them half-click because you don't have to click a link in an email, you don't have to open an attachment.
00:09:00.960 --> 00:09:12.399
If you're running one of these vulnerable webmail systems and you just open it in the normal webmail viewer, JavaScript gets mistakenly executed by the webmail provider, and then boom, you're compromised.
00:09:12.559 --> 00:09:17.759
So it kind of goes against all of the normal training that, including us at Proof Point, provide to people about it.
00:09:17.919 --> 00:09:23.440
And half-click just kind of fit because you do have to open the email, but you don't have to interact with it any further.
00:09:23.679 --> 00:09:26.080
So it was as close to accurate without feeling gimmicky.
00:09:26.240 --> 00:09:28.960
I would have felt disingenuous if we'd called them zero click.
00:09:29.440 --> 00:09:40.320
And so 458 has used a ton of these before, and they are primarily active in Ukraine as well as around kind of Western Asia and Eastern Europe.
00:09:40.559 --> 00:09:46.399
So uh with kind of your typical like, what would you think spy guys would target?
00:09:46.639 --> 00:09:50.480
Militaries, ministries of foreign affairs, um, and kind of the like.
00:09:50.639 --> 00:10:00.639
I wouldn't call TA 488 a tourist, but they are kind of like dipping their toe into this space, whereas uh 458 is like neck deep.
00:10:00.960 --> 00:10:30.000
And so 488 we've seen previously using things like evil jinx for sort of traditional credential harvest, and then eventually moving to this vector of using a half-click exploit against Zimbra Collaboration Suite to steal not only credentials, which we think are kind of like their main bread and butter, but also things like stealing the full email, all the creds, the last 90 days worth of emails that that targeted user has accessed, and then um installing persistent access to that mail server.
00:10:30.159 --> 00:10:41.440
So one of the reasons that for both of these actors, we we wanted to discuss them is unlike many of the other ones, this isn't sort of like a smash and grab, like we're gonna grab your emails and creds and get out of here.
00:10:41.519 --> 00:10:52.159
They both establish some amount of like long-term access and persistence that is kind of troubling in in like a you know, you don't want an adversary sitting there on your email server.
00:10:52.480 --> 00:11:01.279
That was kind of one of the difference makers that made them notable compared to the other 13 or 14 unks that we track using this stuff.
00:11:01.679 --> 00:11:13.919
So to TLDR this, TA488, which is the aka Void Blizzard, aka Laundry Bear, which was the collaborative report that you guys put out with uh some various public partners.
00:11:14.240 --> 00:11:23.759
They are using a we're using a zero day in Zimbra, um specifically targeting Zimbra mail servers with this half-click exploit.
00:11:24.000 --> 00:11:32.000
And their targeting was a little bit more broad compared to TA458, which you guys have observed targeting five different webmail platforms.
00:11:32.080 --> 00:11:37.519
So of course there was Zimbra, but also M Damon, RoundCube, Sogo, and Kiro.
00:11:38.000 --> 00:11:39.919
Am I pronouncing that correctly?
00:11:40.320 --> 00:11:40.879
Okay, great.
00:11:41.039 --> 00:11:42.639
I wasn't sure if that was correct or not.
00:11:42.799 --> 00:11:47.039
But so they have a wider variety of exploits that they use against their targets.
00:11:47.200 --> 00:11:51.200
And at least in the reporting that you're talking about, the targeting was a lot more narrow.
00:11:51.279 --> 00:11:58.559
So it was mostly the Ukrainian government with some additional Eastern European military and government chemical telco and tech companies.
00:11:58.639 --> 00:12:03.120
So it was a little bit smaller targeting, but with broader amount of exploits.
00:12:03.279 --> 00:12:03.679
Is that right?
00:12:03.919 --> 00:12:08.399
Yeah, and and I think that some of that could totally be visibility bias on our part.
00:12:08.639 --> 00:12:21.679
Like we see more of TA 488 because they did a lot more targeting of things in the US, which hint hint that's where most of our visibility is compared to Eastern Europe and Ukraine.
00:12:22.000 --> 00:12:43.360
So yeah, I I I think that, and you can kind of read in the report on the TA 488 Laundry Bear Void Blizzard reporting, that just some of the US-based targeting, I think, was just egregious enough that the US government and partners just cared about it and wanted to to kind of uh make sure that those actors knew that they were they had eyes on them.
00:12:43.600 --> 00:13:12.000
And so, yeah, the the American targeting, I think, is really the big distinguisher between the two of them, as well as kind of the like tooling maturity where TA458 has been using kind of this class and this style of exploit and and the JavaScript that backs that runs after the exploit that ESET calls spy press is just kind of more mature and battle tested and scalable across each target, whereas ZimReaper has a couple of bugs in it.
00:13:12.159 --> 00:13:18.240
It is very probably LLM, uh if not written, like helped, helped in the writing.
00:13:18.480 --> 00:13:31.440
Anywhere you kind of look, I have a a take about why they're different, but this has sort of been these two actors have been kind of the the two main focuses of uh what feels like an 18-month long obsession.
00:13:31.679 --> 00:13:36.159
So if you're wondering why I have I have so many opinions about them, that is that is why.
00:13:36.639 --> 00:13:37.360
Understandable.
00:13:37.519 --> 00:13:38.480
Understandable, Greg.
00:13:38.879 --> 00:14:02.240
So Greg, you kind of already did go through what the technique is, this half-click exploit, but I just want to take a couple steps back and have you reiterate all of the aspects of it because to me this is like a nightmare type of thing, just simply being able to open open an email and have kind of an exploit launched and and tunnel of terror happen.
00:14:03.519 --> 00:14:12.159
Can you just explain half the half-click exploit just in like as if you're explaining it to my mom or your neighbor or something like that?
00:14:12.320 --> 00:14:16.639
And then how does it differ from like traditional fishing?
00:14:16.720 --> 00:14:19.519
I think that's kind of gonna be obvious with your explanation.
00:14:19.679 --> 00:14:26.000
And then clarify with this exploit, do these things happen automatically?
00:14:26.080 --> 00:14:33.360
And what I mean things, is it the the login passwords change and then the email context exfiltrated, the 90 days worth of emails extrated, all of it?
00:14:33.440 --> 00:14:34.960
Does that happen all at the same time?
00:14:35.039 --> 00:14:40.080
Or is there more of a little bit of nuance to to all of this?
00:14:40.240 --> 00:14:44.720
So and last part of the question is is this a brand new technique or have you seen it before?
00:14:44.799 --> 00:14:48.639
Maybe not with exploits targeting webmail servers, but otherwise.
00:14:48.960 --> 00:14:49.600
Good question.
00:14:49.679 --> 00:14:51.759
I I'm gonna count it just as one.
00:14:52.000 --> 00:14:57.039
Yeah, so I I think I think the easiest way to describe it is describe what it isn't.
00:14:57.279 --> 00:15:07.679
So to your point about explaining it to our parents, my mom understands that if she gets an email from someone she doesn't know and has an attachment, don't open the attachment.
00:15:07.919 --> 00:15:09.679
If there's a link in there, don't click it.
00:15:09.840 --> 00:15:16.080
If they're trying to get for her to contact them back, and it feels at all kind of like a what do you want from me?
00:15:16.240 --> 00:15:23.120
Like I'm a normal person, I don't need like nobody none of my friends are contacting me over email.
00:15:23.360 --> 00:15:31.919
Like there's some amount of impetus for an action to happen, whether it's opening the link, the attachment, or engaging back with the person who sent the email.
00:15:32.080 --> 00:15:54.399
Where this gets flipped on its head with the half-click exploit style is the easiest way to think about it is that you know, most webmail providers, including the the biggest ones that we know, support HTML or similar things um in the webmail viewer, so you can make your emails look pretty and have like your your branding in them and and nice formatting and stuff like that, so it's not just plain text.
00:15:54.559 --> 00:16:00.159
And the easiest way to kind of explain it is that the actors can then put JavaScript in there that shouldn't be there.
00:16:00.399 --> 00:16:09.759
If you ever see a screenshot that that I hope that we provide enough of those in our report, where it's like, why is there their JavaScript inside of the message body of an email?
00:16:09.919 --> 00:16:10.480
That's weird.
00:16:10.639 --> 00:16:11.519
Should that be there?
00:16:11.759 --> 00:16:14.000
The answer is almost definitively no every time.
00:16:14.240 --> 00:16:18.000
That's kind of like the impetus with which we work off like hunting for these things.
00:16:18.240 --> 00:16:24.159
To your question, there is JavaScript inside of the message body of the message body's HTML.
00:16:24.320 --> 00:16:32.399
And so inside of the HTML, there will typically be what's called an exploit trigger, which is something that the webmail provider is mishandling.
00:16:32.639 --> 00:16:35.279
Some of those things will be what are called event handlers.
00:16:35.440 --> 00:16:44.480
So it'll say something like on error, on click, on load, which are things that you see sort of normally in JavaScript and on web pages.
00:16:44.559 --> 00:16:59.120
So if you click inside of the, if you click download external images, that could be considered kind of like an on click, or if you click inside of the HTML anywhere inside the email, that creates what's called a click event, which is just inside of the JavaScript.
00:16:59.279 --> 00:17:10.960
And what ends up happening is that these webmail providers don't have perfect sanitization, and nobody does, of the HTML and making sure that JavaScript, if it's present in those places, can't run.
00:17:11.279 --> 00:17:26.000
And so the actors can throw what is effectively a um stored cross-site scripting bit, which is send them an email where the webmail provider will mishandle the JavaScript sanitization and then run that JavaScript.
00:17:26.160 --> 00:17:32.640
And so, Sarah, to your point about do all of those actions happen at once, they happen at kind of machine speed.
00:17:32.720 --> 00:17:40.720
There is a cascade of things that have to happen, you know, before or after these events happen, but it is typically in real time.
00:17:40.880 --> 00:17:42.720
It doesn't require operator interdiction.
00:17:42.880 --> 00:17:47.599
It doesn't require a user to hit, like, oh yes, grant this permissions for this to work.
00:17:47.759 --> 00:17:50.559
What we will see sometimes is like timeouts.
00:17:50.880 --> 00:17:55.039
So it'll run in the background while user is still on the webmail page.
00:17:55.279 --> 00:18:10.960
Ironically, one of the ways that some of these can get foiled if they don't interact with the browser window in sort of a proper way to escape it, is that if you leave the webmail viewer page and like click the X button to get out of it, the JavaScript just stops running wherever it is.
00:18:11.119 --> 00:18:16.799
And granted, this is happening at machine speed, so it's very likely that most or if not all of it is already run.
00:18:17.039 --> 00:18:22.400
But so yeah, that's kind of for better or for worse, that's one of the more notable defenses for it.
00:18:22.559 --> 00:18:36.319
But again, that's something that, especially for some of these, like the damage is already done, the data has already been exfiltrated at machine speed instead of at you know, by the time the user maybe realizes, like, I don't care about reading this email, and they go on to another one, the JavaScript is still able to run.
00:18:36.400 --> 00:18:40.640
Um, and so however long they leave their webmail viewer open, it could theoretically continue to run.
00:18:40.960 --> 00:18:53.920
This makes me think of if you get a doorbell, like someone rings your doorbell and you go and look through the peephole to see who it is, and then the person just like bangs down your door and like runs over you and goes and steals all your stuff.
00:18:54.160 --> 00:18:54.559
Yeah.
00:18:55.119 --> 00:18:57.440
Except you don't see them enter your house.
00:18:57.680 --> 00:19:03.839
Unless you are watching every piece of JavaScript that your browser does, which would be a lot pretty enviable.
00:19:04.079 --> 00:19:08.240
Yeah, that would that if if you're doing that, um, I have other questions.
00:19:08.640 --> 00:19:11.599
So, Greg, is this is this a new technique or no?
00:19:11.759 --> 00:19:16.000
Or is this uh similar to has this kind of thing ever been used?
00:19:16.079 --> 00:19:25.359
I know like the embedded pixels and messages is like an old school uh China APT type of technique where you just have to open the email and it sends a heartbeat back.
00:19:25.519 --> 00:19:36.240
But what what I'm getting at here is how long until e-crime uh threat actors start using this to you know execute other things on victim systems and so on and so forth.
00:19:36.640 --> 00:19:42.640
So, yeah, I think we've already seen some indications of like smaller time Russian e-crime using it.
00:19:42.720 --> 00:19:50.400
I say smaller time because it still has like kind of generic targeting, but it's not a big explosion of of stuff.
00:19:50.640 --> 00:20:03.680
At least not enough that I would tap you or Selene and be like, hey, like maybe someone in your crew should look at this because this is like beyond the scope of it's still kind of blurry if it's espionage or not, but it just kind of feels crimey based on the targeting.
00:20:04.000 --> 00:20:18.400
I think that particularly like in the to not to speak necessarily out of turn about crime, but in the initial access broker space, having access to email providers, like email servers that you can send malicious email from is probably a good thing to have in their back pocket.
00:20:18.640 --> 00:20:47.200
So I think that if some of these can be chained together, like the round cube exploits that we talk about in the TA458 blog, where you can get access to the entirety of the mail server to then use to send additional email, I think that those will be appealing in the same way that like what I would call other network-based exploits, um, like RCEs for mail servers, would also be abused by crime, not necessarily to pillage them for information, but to use them as spam things to send malicious emails from.
00:20:47.279 --> 00:20:49.279
Selena, would you kind of agree with that?
00:20:49.599 --> 00:20:51.440
Yeah, I think that makes sense.
00:20:51.759 --> 00:21:02.559
I do think though, that there are a lot of lower hanging fruit things that can be very effective, that we're seeing a lot more use in terms of like identity-focused targeting.
00:21:02.720 --> 00:21:12.799
I think when you're talking about the sort of end goal objective of this is like data theft and information gathering and and things like that, it's so like the objectives are a bit different.
00:21:12.960 --> 00:21:15.359
But I do think that it would, of course, be of interest.
00:21:15.519 --> 00:21:22.799
And I think that if something's effective, it will be used by any adversary, regardless of who's doing it.
00:21:23.039 --> 00:21:32.079
But I do want to point out though that you mentioned multiple times in the reporting was like, well, you have T488 that just uses one, whereas T458 uses multiple.
00:21:32.160 --> 00:21:36.880
They're using a lot more zero days, they're investing their resources, they're investing time and effort.
00:21:37.039 --> 00:21:49.680
So it does sound like this type of um technique is very effective for them if they're putting the time and effort to investigate not just the potential Zimber exploits, but all of the other um webmail servers that they're targeting.
00:21:49.759 --> 00:21:59.839
So, do you think that this is an ongoing process where they're just gonna keep investigating O Day against webmail to achieve this ultimate half click objective?
00:22:00.240 --> 00:22:00.400
Yes.
00:22:00.559 --> 00:22:05.599
And to Sarah's earlier question, I I think that this is probably one of those things that's been going around forever.
00:22:05.759 --> 00:22:07.599
And it just kind of comes back into vogue.
00:22:07.759 --> 00:22:15.119
There's an element of this that feels very like late 90s, early 2000s hacker that I can't quite put my finger on.
00:22:15.359 --> 00:22:19.680
And granted, I was like in elementary school when I'm talking about these things.
00:22:19.759 --> 00:22:23.519
So I'm not exactly like the person to be like giving a history lesson on it.
00:22:24.640 --> 00:22:30.480
But it's current kind of like trend run, probably starting like 2023, maybe 2022.
00:22:30.559 --> 00:22:33.359
Um, a lot of it was around Russia's invasion of Ukraine.
00:22:33.440 --> 00:22:43.359
I think just kind of taking any measure that they could get to get Russian actors to get into those networks or gain information about anything going on in country was probably a priority.
00:22:43.599 --> 00:22:50.319
And yeah, so the interior question, I think that it definitely is something that is getting investment, particularly from the 458 side.
00:22:50.480 --> 00:23:05.519
I'm not sure if they are benefiting from like an exploit broker situation, or if they are developing things in-house, or if they are bringing things like getting things handed out to them from like their GRU taskmasters.
00:23:05.680 --> 00:23:13.279
I think it could be a combination of any of those things, or if there are other groups using them that we don't see inside of our visibility that then get handed to 458.
00:23:13.920 --> 00:23:23.519
But yeah, I definitely see it as kind of a for the next like two to three years, I definitely think that we are going to continue to see it because I think of the subtle nature of it.
00:23:23.759 --> 00:23:37.359
Where if you have like a, no matter kind of the origin of the malware, if you see like a cred phishing page or a malware gets deployed onto um a user's device, there are actions that you can take to neutralize that in a lot of ways.
00:23:37.599 --> 00:23:48.960
Like you can rotate the creds, you can quarantine the device, because most of the time, like at least in the espionage space, there isn't a ton of value of getting access to like a generic person's device.
00:23:49.039 --> 00:23:55.759
Whereas, you know, a lot of these APTs that we've kind of fanboyed over the years, you know, they want to have kind of a network-level compromise.
00:23:56.000 --> 00:24:04.640
And so I think that this provides one of those end goals, which is you compromise a network's visibility into the emails, right?
00:24:04.720 --> 00:24:11.279
That's kind of how they're interacting with these external parties that you might have interest in collecting on and all those sorts of things.
00:24:11.359 --> 00:24:17.119
And it's a really subtle way to steal that information without a ton of a forensic footprint.
00:24:17.279 --> 00:24:22.319
You know, you have an email and then you have the sort of outbound logs in the mail server, and that's kind of it.
00:24:22.640 --> 00:24:28.799
Because doing forensics in kind of the browser can could be pretty difficult for detecting and finding these things.
00:24:29.039 --> 00:24:50.160
So yeah, I think that there's going to be kind of continued investment in this space, both probably accelerated by LLM usage, but that's one one of the things where this will be somewhat contentious, I think, is where the providers start to benefit downstream from their use of like the big frontier labs.
00:24:50.319 --> 00:24:55.680
And hey, maybe we can do our own kind of code review to make sure that these vectors don't work, work in-house.
00:24:55.839 --> 00:25:00.160
And you know, especially kind of the bigger ones like Round Cube and Zimbra are patching all the time.
00:25:00.240 --> 00:25:04.000
So it's not like they are asleep at the wheel for their users by any means.
00:25:04.079 --> 00:25:14.720
And I think they're actually very good kind of partners to the industry for people that don't want to run, say, Outlook or sort of any of these other kind of like bigger paid providers.
00:25:15.039 --> 00:25:22.640
So yeah, I think the investment's gonna continue, especially just because that's what these entities of interest are going to keep running.
00:25:22.799 --> 00:25:25.039
The magnet of threats concept exists for a reason.
00:25:25.119 --> 00:25:32.960
So they're gonna kind of be re-targeted over and over again, probably just with a different focus on whatever is in vogue for exploitation at the moment.
00:25:34.160 --> 00:25:38.559
So I have a question on the actual activity of TA488.
00:25:38.720 --> 00:25:44.880
So I thought it was kind of interesting that they will exfil data for just the last 90 days.
00:25:45.119 --> 00:25:54.480
Is that because they're only interested in that timing, or is that a setting from a uh Zimbra side that only allows them to access that much data?
00:25:54.640 --> 00:25:59.440
Like, why are they time binding their exfiltration like this?
00:25:59.920 --> 00:26:00.720
That's a great question.
00:26:00.799 --> 00:26:16.079
I'm gonna pull up one of the samples to one of the reasons I think for sure, given how kind of skittish this actor can be, is you know, I think that they want to kind of create as little footprint as they can.
00:26:16.319 --> 00:26:20.799
And I think that some of that is like, well, we can steal 90 days to stay under the radar.
00:26:21.039 --> 00:26:26.000
That is something that they set manually in the the Bauer payload.
00:26:26.079 --> 00:26:30.559
It's not like sort of a Zimbra-based setting, at least as far as I can tell.
00:26:30.720 --> 00:26:35.440
So I think that's just kind of a choice of like, hey, the last 90 days is probably gonna be enough.
00:26:35.680 --> 00:26:42.160
And maybe if they need to get retargeted with the same exploit, they can have an extended look back view.
00:26:42.640 --> 00:26:51.359
I have gotten the sense that they will use the last 90 days worth of emails that they steal to inform future targeting.
00:26:51.440 --> 00:26:57.759
So we have seen previously targeted entities be used to send follow-on emails to additional targets.
00:26:57.920 --> 00:27:04.960
And so I think that some of that email gathering is to process on their back end to develop maybe lures.
00:27:05.200 --> 00:27:22.240
We've only seen them really kind of use generic ones before, but maybe in cases where they want to do more specific targeting to a user or to a network, they could derive that from if they compromise a partner of theirs or something like that and have really precise language coming from that entity.
00:27:22.480 --> 00:27:25.839
But that, you know, that that's kind of me just speculating, not really knowing.
00:27:26.160 --> 00:27:28.799
And talking again on the evolve, the evolution.
00:27:28.880 --> 00:27:40.640
So you mentioned that this is like in process and they're kind of just developing things with the goal of potentially using them over and over, or continuing to have the half-click be something of interest to them.
00:27:40.880 --> 00:27:49.200
In the Zim Reaper analysis for T488, you mentioned that the naming convention had ZMB underscore PL underscore V3.
00:27:49.839 --> 00:27:53.759
So that kind of implies that earlier versions might actually exist.
00:27:53.920 --> 00:27:57.920
Have you found any evidence of a V1 or V2 for a different vulnerability?
00:27:58.000 --> 00:28:00.000
Or do you think that this is kind of just them?
00:28:00.400 --> 00:28:03.359
This is the one exploit that they've done, just had multiple versions of?
00:28:03.680 --> 00:28:06.319
I think that it's though for the one exploit that they've done.
00:28:06.400 --> 00:28:12.720
I think that the versioning is for variants of the JavaScript that runs after exploitation.
00:28:12.960 --> 00:28:28.559
We have seen them do like some minor feature adding, like adding data for collecting like the 2FA scratch codes and things like that, or installing the long-term access to the Zimbra server, but not like I don't think it's an evolution of the pay of the exploit.
00:28:28.720 --> 00:28:31.440
I think it's just kind of an evolution of the payload that comes after it.
00:28:31.759 --> 00:28:42.079
I want to talk a little bit about the actors, because I'm, you know, getting them confused a little bit, but your explanation on the difference between the two, it was very, very helpful.
00:28:42.240 --> 00:28:58.640
So you suggest that T458 might be linked to GRU unit 20728 rather than the well-known 26165, which is APT28 for those who read the news or follow anything.
00:28:58.960 --> 00:29:03.440
What evidence would you need to confirm the hypothesis?
00:29:03.680 --> 00:29:07.680
What further evidence for us a stronger assessment?
00:29:09.759 --> 00:29:14.319
We included that in there from kind of tea leaf reading.
00:29:14.880 --> 00:29:28.079
So things that we have linked to 458 have kind of generally been linked to APT-28, Fancy Bear, Sofacy, Forest Blizzard, there are a gazillion more names.
00:29:28.559 --> 00:29:31.599
But in our view, the targeting has always been distinct.
00:29:31.759 --> 00:29:45.440
Um we kind of have a set of entities that we see regularly targeted by what we call our name for APT-28, which is TA422, that very much align with public information about unit 26165.
00:29:46.160 --> 00:29:58.640
This other unit, however, got mentioned in sort of a French intelligence advisory that went public last year about sort of APT 28 general targeting of entities in France.
00:29:58.799 --> 00:30:00.960
And it included both of those unit numbers.
00:30:01.519 --> 00:30:10.960
And so we wanted to bring it sort of out to the public to say, like, hey, like there's this thing that maybe kind of got overlooked when the French released this.
00:30:11.200 --> 00:30:13.200
We see this as a defined cluster.
00:30:13.440 --> 00:30:29.519
The evidence that I would need, like, I don't know, a real like a government that does that kind of work, or you know, even a peer in the Thread Intel space that does that kind of work, like it's kind of it's kind of been a joke the last week internally, but like my job is just to put the phishing emails in the bag, bro.
00:30:29.839 --> 00:30:43.680
It's uh our visibility is amazing, and we are really fortunate to work on things that can disrupt important espionage operations, even like across our customer base.
00:30:44.000 --> 00:30:48.559
But my job isn't finding the humans or finding the units behind them.
00:30:48.720 --> 00:31:06.640
And I think that kind of extends to like one of the ways that we're kind of benefiting from the the joint reporting taking this long is one of the alleged members of Void Blizzard, um, Longybear got extradited to the US and sentenced in Boston a week or two ago.
00:31:06.960 --> 00:31:09.519
And again, that's kind of one of those things like that's cool.
00:31:09.680 --> 00:31:20.079
It's cool to see like cuffs go on someone that is doing harm to entities in the US and entities in Ukraine, but like it isn't my job to identify those people.
00:31:20.240 --> 00:31:37.279
So I sort of floated out there more as a like, hey, I think that there's like not only can we define these clusters differently, but I think that there might be a military hierarchy reflection of this that is plausible.
00:31:37.359 --> 00:31:42.400
But again, like I don't this isn't me like sitting on information that I'm trying to dance around.
00:31:42.480 --> 00:31:58.799
It's more like, guys, I think that like this might be the thing, that this might be the unit behind at least the the versions of these exploits and payloads that we're seeing in our data, and kind of wanting to bring that to kind of the discussion forefront rather than we know it's this thing, we're being coy about it.
00:31:59.039 --> 00:31:59.440
Gotcha.
00:31:59.599 --> 00:32:15.200
So if anyone has any thoughts that they would like to share with Greg who does do that direct attribution activity, or if you are a member of GRU unit 2728 who has done these exploits, feel free to reach out to Greg and tell him that he's wrong or right.
00:32:15.599 --> 00:32:21.200
Reach out to S-L A R S O N at proofpoint.com.
00:32:23.440 --> 00:32:25.759
Or you can do that and I'll just forward to him.
00:32:26.160 --> 00:32:31.279
So on the attribution piece, because you mentioned uh so TA458, they were better.
00:32:31.440 --> 00:32:37.119
They were a little bit more sophisticated, had a little bit more of a grander arsenal and some different targeting.
00:32:37.279 --> 00:32:42.799
And TA488, aka avoid blizzard, laundry beer, uh, you mentioned it's a private contractor.
00:32:43.039 --> 00:32:52.720
So I'm curious, you know, does this contractor model explain many of the of the behavioral differences that you observed compared to the more sophisticated TA458?
00:32:52.880 --> 00:33:05.519
Like how do you think that that, you know, the the resources available or the the targeting or objectives might vary depending on if they are actually part of government espionage versus contractors?
00:33:05.920 --> 00:33:12.400
This is actually a really good question that I wish I had considered much earlier in kind of our collective analysis of these things.
00:33:12.720 --> 00:33:14.799
Because I think it totally does.
00:33:15.119 --> 00:33:15.440
Right?
00:33:15.599 --> 00:33:23.279
Like there was a big blog about TA458 last year from ESET that we mentioned called Operation Round Press.
00:33:23.599 --> 00:33:27.599
If they are actually uh a unit, they were completely unbothered by it.
00:33:27.680 --> 00:33:38.079
Like they didn't burn down a bunch of infrastructure, they just kind of kept plotting along and doing their thing and targeting kind of their traditional government military entities.
00:33:38.319 --> 00:33:55.440
Meanwhile, I think 488 kind of has more diverse targeting, like the targeting of American nuclear entities and state and federal level government stuff and Ukraine are kind of diverse in what they're doing.
00:33:55.759 --> 00:33:59.519
And and I think that the bigger thing though is how skittish they are.
00:33:59.759 --> 00:34:13.440
You know, once one of their phishing emails got flagged um in a blog that got uploaded basically an email got uploaded to VT and then um a blog came out and they burnt down all their infrastructure after it, including stuff that wasn't mentioned in the blog.
00:34:13.679 --> 00:34:21.119
And so I think that that speaks to the fact that they are don't have as many resources in that space compared to 458.
00:34:21.360 --> 00:34:31.199
Um, and I think that the targeting is a little bit reflective of that, but I also think that like a small upstart contractor is gonna do what it can to retain its investment.
00:34:32.559 --> 00:34:36.480
And I think part of it is they didn't want to leave those servers up for people.
00:34:37.039 --> 00:34:49.280
Like it could be peer or rivals in the Russian Intel or contractor space that are gonna pillage those things and somehow monetize that information for their own contracts in some way.
00:34:49.360 --> 00:35:07.440
Whether that's how to weaponize the exploit, whether that is like, oh, well, we actually have a better way to mine the data that you stole, as well as like all of the risks of US law enforcement and government or international government and law enforcement coming in to um do whatever intelligence agencies do on other people's C2s.
00:35:07.679 --> 00:35:10.639
Whereas like, again, like 458 kind of just didn't care.
00:35:10.880 --> 00:35:14.480
And I think that the bigger thing for them is efficacy of the exploit, right?
00:35:14.559 --> 00:35:20.880
Like they keep rolling all these new ones because they just want to wait and see when one of their targets will be vulnerable.
00:35:21.039 --> 00:35:29.760
So it's kind of it's not throwing um spaghetti at a wall, but I think it's it's kind of like, well, until we're in, we're gonna keep trying whatever we can.
00:35:29.920 --> 00:35:33.440
And I think 488 was like, we have this cool slick vector.
00:35:33.599 --> 00:35:36.320
Oh my God, somebody knows about it, like sound the alarm.
00:35:37.519 --> 00:35:45.360
And I think that's I think that some is somewhat explained by the one of them being a contractor and one of them being a military entity.
00:35:45.679 --> 00:35:54.079
You mentioned discovering multiple instances where TA458 had sent exploits to targets that weren't running vulnerable webmail servers, right?
00:35:54.159 --> 00:35:55.440
They weren't running those apps.
00:35:55.599 --> 00:36:01.679
So do you think this was intentional or was it possibly operational sloppiness?
00:36:01.920 --> 00:36:07.440
Could they have known from prior recon efforts whether the target was running a vulnerable instance?
00:36:07.760 --> 00:36:12.480
Feels like that's something they may have tried to flesh out before firing off.
00:36:12.559 --> 00:36:13.360
But what do you think?
00:36:13.760 --> 00:36:16.239
I'm gonna go with certified slop.
00:36:17.360 --> 00:36:23.199
Yeah, it's we've seen that it happening once would be like kind of okay, that that's weird.
00:36:23.280 --> 00:36:24.480
Maybe they were working on bad information.
00:36:24.639 --> 00:36:27.119
It happening a few times is kind of like uh, huh?
00:36:27.280 --> 00:36:29.840
Like, are you really you guys really not checking?
00:36:30.159 --> 00:36:34.800
And actually with this group though, they're they're like the solid group, right?
00:36:34.880 --> 00:36:35.760
They like stick around.
00:36:35.840 --> 00:36:36.880
We do you just went over it.
00:36:36.960 --> 00:36:39.119
They're like the OG one out of the two.
00:36:39.679 --> 00:36:41.039
Does this surprise you?
00:36:41.199 --> 00:36:46.159
Does the sloppiness surprise you, or do they have a history or maybe of doing this?
00:36:46.400 --> 00:36:47.840
I'm not sure about having a history.
00:36:47.920 --> 00:37:03.840
I think that the there could be a little bit of like resting on their laurels, and like for them, there isn't as much they don't feel the same risk of exposure if they fire off a phishing email or or one of these half-quick exploit emails that isn't gonna compromise someone.
00:37:04.000 --> 00:37:08.239
Because if it doesn't, like to them, it's like, oh, what's the worst that's gonna happen?
00:37:08.400 --> 00:37:12.320
Someone's gonna do a blog about it, yes, and make fun of us for it.
00:37:12.400 --> 00:37:12.960
I don't care.
00:37:13.119 --> 00:37:15.760
Like that that's kind of my interpretation of it.
00:37:15.920 --> 00:37:26.159
There's definitely like multiple instances of them throwing, like, not even just like, oh, they're not vulnerable to this, but that target isn't even a running round cube at all, more than once.
00:37:26.400 --> 00:37:44.000
So I think that there's definitely like a a discrepancy somewhere, but I also don't know that they can be be made to care because there is an element that our visibility doesn't let us see, which is kind of the breadth of their tar breadth and volume of their targeting.
00:37:44.239 --> 00:37:49.199
You know, when we see them in-house, it's two to seven to ten emails at a time.
00:37:49.440 --> 00:37:57.039
But if they're doing that at every entity that they're targeting, that's not exactly like a tiny little blip sent to one user.
00:37:57.199 --> 00:37:59.519
It's kind of a kind of a broad thing.
00:37:59.599 --> 00:38:08.800
I think that they just have a higher risk tolerance for um failure and for opening themselves up to being discovered and blogged about.
00:38:09.360 --> 00:38:10.079
That makes sense.
00:38:10.239 --> 00:38:10.639
Yep.
00:38:11.119 --> 00:38:18.000
Also, I feel like if you're a contractor versus like a G R U operative, your reputation doesn't like your reputation matters more.
00:38:18.239 --> 00:38:25.199
Whereas if you're just like clocking in at G R U H Q, it's like, well, I have job security.
00:38:25.360 --> 00:38:29.920
I don't, I'm not like, you know, if my exploit gets blown up, whatever.
00:38:30.320 --> 00:38:34.639
The contractors are trying out for the full-time remote, so they're a little bit more careful.
00:38:35.920 --> 00:38:36.559
Exactly.
00:38:36.800 --> 00:38:38.320
It's a high higher stress.
00:38:38.400 --> 00:38:39.920
They have to market themselves, right?
00:38:40.079 --> 00:38:43.519
They they're the exploit influencers over there, okay?
00:38:43.760 --> 00:38:44.320
Yeah, yeah, yeah.
00:38:44.559 --> 00:38:53.360
And I think that that's like their differentiator, is they have all these exploits, and so like you just have to they can weather the storm and wait for another one to show up.
00:38:53.760 --> 00:38:57.199
Um, and I don't think that this all happens if they're not being successful.
00:38:57.360 --> 00:39:07.199
Like, I think if they were hitting dead ends, we wouldn't keep seeing it at the volume and rate that we are, but still they rise and still and still they keep throwing these these exploits and finding Oday.
00:39:07.280 --> 00:39:08.000
So yeah.
00:39:08.239 --> 00:39:13.679
So to wrap up this conversation, this has been a really interesting conversation about all of the actors' TTPs.
00:39:13.760 --> 00:39:25.119
And as I mentioned previously, we will make sure to share a link to all of the reporting that has come out around these threat actors and the half-click exploits that we are talking about today.
00:39:25.280 --> 00:39:31.360
But a few questions for listeners who might be wondering how they can defend themselves against this type of activity.
00:39:31.519 --> 00:39:42.159
So, entities that are running Zimbra or other targeted webmail platforms, are there any detection strategies or defensive recommendations that would have caught these attacks before the patches were available?
00:39:42.400 --> 00:39:46.639
Or are you kind of just out of luck when it comes to the half-clicks?
00:39:47.039 --> 00:39:54.639
So I think if you're running Zimbra or RoundCube or any of these sort of open source webmail providers, patching is definitely your best bet.
00:39:54.800 --> 00:39:57.920
That's kind of the best way to stay up to speed with these things.
00:39:58.079 --> 00:40:02.559
And then the second to that would on the detection side would be using a secure email gateway.
00:40:02.639 --> 00:40:06.800
And I think that obviously Proofpoint sells a secure email gateway.
00:40:06.880 --> 00:40:20.000
So there's a little bit of showing in there, but I think that there's another element of this that if you wanted to write your own rules, you could use Zimbra or RoundCube spam assassin features to kind of write rules for that.
00:40:20.159 --> 00:40:21.599
But again, it's kind of hard.
00:40:21.679 --> 00:40:30.000
And on especially on something like HTML and JavaScript, there's no perfect regex that's going to catch all of these things, right?
00:40:30.079 --> 00:40:43.280
There's sort of a like on our side, even there's like a set of heuristics and fraud searches that we kind of mine and then frankly, like get lucky that we found that we get able to collect and find find stuff.
00:40:43.440 --> 00:40:44.639
And that's not an accident.
00:40:44.719 --> 00:40:49.519
Like I think that many of these things are written to be overlooked or missed.
00:40:49.599 --> 00:40:57.119
And so on our side, like staying abreast with the exploits and things that are that are getting released is a really big part of the job right now.
00:40:57.440 --> 00:41:08.800
And so I if you had to defend one of these platforms without um sort of a partner in the secure email gateway space, I really Godspeed, maybe we can figure out something to get some free licenses out there.
00:41:08.880 --> 00:41:11.679
But yeah, it's kind of a daunting thing to be protecting right now.
00:41:12.559 --> 00:41:20.719
I do want to point out if you are a proof point customer and you were targeted by this activity, you will have been notified by our espionage team.
00:41:20.960 --> 00:41:27.440
So just Yeah, we uh everybody that saw this that we are aware of um has been sent a victim notification.
00:41:27.519 --> 00:41:32.800
But yeah, to any customers that think that we missed something, please file a support ticket.
00:41:34.239 --> 00:41:42.719
Interestingly, though, you in your reporting made several recommendations for how to check the Zimber Web at password thing, which I think is really cool, right?
00:41:42.800 --> 00:41:49.199
So people who are reading the blog, maybe working at SOC, whatever, can check for instances of compromise and so on and impact.
00:41:49.360 --> 00:41:55.199
So what percentage of compromise organizations do you think will actually find evidence at this point?
00:41:55.360 --> 00:42:10.800
Of course, not proof point customers, but outside, given the background of the threat actors and so I think for 458, where we've seen them installing web shells on roundcube servers, I think there's a high likelihood that those web shells are still there.
00:42:11.199 --> 00:42:24.480
On the 488 side, I think that you might be able to find some evidence of the Zimbra app password, but I think that because they burnt down all the infrastructure, I don't think that you will see like much interaction with it.
00:42:24.639 --> 00:42:32.000
Um I'm actually thankfully when they set that up, they ex-fill inside of HTTP the password used to create it.
00:42:32.159 --> 00:42:36.400
So there isn't like a dangling password out there somewhere.
00:42:36.639 --> 00:42:42.960
Theoretically, somebody else could try and brute force it, which I would hope that there are controls and alerts in place for that.
00:42:43.119 --> 00:42:49.039
But I think yeah, going to look for that just to be safe if you think that you've been targeted by these guys before would be good.
00:42:49.280 --> 00:42:57.280
In terms of percentage, I I really have no idea because I think that delivery and efficacy on this type of threat is really difficult.
00:42:57.599 --> 00:43:02.400
And some of it is like remediation after the fact rather than preventative.
00:43:03.119 --> 00:43:07.280
So yeah, I don't have a good estimate of what percentage remain impacted.
00:43:07.360 --> 00:43:18.800
Um, especially for like both 458 and 488 for things before 488 had the Zimbra app password, or most of 458 stuff doesn't have a persistence mechanism.
00:43:19.519 --> 00:43:21.199
Yeah, it could be kind of any of those.
00:43:21.280 --> 00:43:24.079
Um the number could be anywhere between zero and a hundred.
00:43:25.119 --> 00:43:25.760
Helpful.
00:43:25.920 --> 00:43:26.559
Yeah.
00:43:26.800 --> 00:43:28.800
Again, tea leaves, tea leaves over here.
00:43:29.440 --> 00:43:30.079
So, all right.
00:43:30.159 --> 00:43:42.159
Well, so one last question, um, because this is a really fun conversation, and we are going to wrap it up, but these reports represent months of investigation, vendor coordination, government collaboration, etc.
00:43:42.800 --> 00:43:49.599
What was the most challenging aspect of this research and how happy are you that it's finally been published?
00:43:50.480 --> 00:43:56.079
I am one ice cold beer happy that it's that it's finally getting published.
00:43:56.880 --> 00:44:01.519
Well, it's happening on a it comes out on a Thursday, and I will be Going to the beach the following week.
00:44:01.599 --> 00:44:04.880
So it will be ice cream and beer and margaritas that whole week.
00:44:05.039 --> 00:44:08.000
I honestly the most challenging part I think has been detection.
00:44:08.400 --> 00:44:17.519
Like inherently, and I don't want to like give too many state secrets away, but being in the secure email gateway space, we are kind of like a network sensor.
00:44:17.599 --> 00:44:27.760
We have one shot to view what is passing our wire, and if it gets past us, then there's some metadata left around, but not like a full thing to go investigate.
00:44:28.000 --> 00:44:42.559
And so kind of coming to grips with that, where we don't get multiple shots at detecting something and coming up with not just like a hey, we can write a solid detection in our authority stack, and special shout out to the people that run and work authority, particularly James.
00:44:42.639 --> 00:44:46.559
We're we're getting mentioned in all these places because of you specifically, so thank you.
00:44:46.880 --> 00:45:12.639
That like we can write a solid regex for a particular vulnerability or like actor JavaScript that we're aware of, but finding things that we the unknown unknowns of like who could be using a similar class of exploit and how would we go about finding that has been it's been both very, a very gratifying thing because I think that the number of unks that we're tracking now is like almost 20, if you count these two as unks anymore.
00:45:12.880 --> 00:45:17.760
Fully fledged actors and unks, I guess, um is around 20 using this kind of method.
00:45:17.920 --> 00:45:20.559
And some of them are like a flash in the pan and we don't see them again.
00:45:20.639 --> 00:45:24.320
Some of them are much more long-term and persistent, the way that 488 and 458 are.
00:45:24.480 --> 00:45:38.639
But definitely on the detection side of crafting something that will not only be resilient to find known stuff, but also give me enough of a a broad scope to find outliers that we didn't have existing signatures for.
00:45:38.719 --> 00:45:44.000
So that's kind of been entertains a very creative and uses a very creative part of the brain.
00:45:44.239 --> 00:45:54.320
But that's one of those things where when you're fighting with something like all day to get to try and get it like one of these, I don't want to call it a moonshot detection idea to work, but kind of like a this is kind of a chance.
00:45:54.480 --> 00:46:01.280
I hope that when I deploy this, I don't crash a downstream alerting service, which I have before, for writing too broad of a rule.
00:46:01.760 --> 00:46:13.039
But like, you know, just the there's an element of hope that kind of comes with doing all those things and standing up like an exploit detection program was definitely an exhausting but gratifying set of work.
00:46:13.199 --> 00:46:15.920
So yeah, shout out to shout out to the authority team.
00:46:16.159 --> 00:46:17.519
Woohoo! Yes, James.
00:46:17.599 --> 00:46:18.639
We love you, James.
00:46:18.880 --> 00:46:21.519
And yes, everyone on that team, you guys are doing amazing work.
00:46:21.599 --> 00:46:22.320
Thank you, thank you.
00:46:22.480 --> 00:46:24.559
Yeah, this has been a really interesting conversation.
00:46:24.719 --> 00:46:30.880
I do want to, you know, kind of wrap it up with a you know summary of the main takeaways, right?
00:46:30.960 --> 00:46:43.280
So we have TA488, which targeted Zimbra, one exploit used carefully, one dark, one exposed, and then TA458 targets multiple platforms, many exploits, very persistent, and keeps going despite exposure.
00:46:43.519 --> 00:46:54.079
Both of these groups are sophisticated, well-resourced, and will steal emails focusing on intelligence collection to support the Russian government and their collection priorities.
00:46:54.239 --> 00:47:14.159
So, bottom line, if you run a Zimbra RoundCube, so go, M Damon or Kiro email server, definitely read those blogs, check out your logs for suspicious activity, and make sure that you are fully patched against those vulnerabilities that are currently being exploited, were exploited previously and might be used again in the future.
00:47:14.480 --> 00:47:16.559
Greg, thank you so much for joining us today.
00:47:16.719 --> 00:47:17.840
This was a really fun conversation.
00:47:18.000 --> 00:47:20.639
Sarah and your chickens, always a pleasure as well.
00:47:20.960 --> 00:47:22.159
Thanks for having me.
00:47:22.320 --> 00:47:23.599
And the chickens.
00:47:24.480 --> 00:47:27.679
And to all our listeners, thank you so much for tuning in as always.
00:47:27.840 --> 00:47:30.400
Until next time, happy hunting.
00:47:31.280 --> 00:47:37.360
You've been listening to Discarded Tales from the Threat Research Trenches, a podcast by Proof Point.
00:47:37.760 --> 00:47:42.400
Never miss an episode by subscribing to the show in your favorite podcast player.
00:47:42.559 --> 00:47:43.920
Happy hunting.