Typhon Reborn v2 is looking to steal your crypto and any secret data it can! This new version of this "stealer" malware is fairly advanced with new and improved Anti-Analysis and Sandbox Evasion techniques.
Let's dive into the details and see what we can learn from Typhon, so that we can use that information to build better defenses against it and other malware like it!
Buy Me A Coffee:
https://www.buymeacoffee.com/daniello...
The Hacker News:
https://thehackernews.com/2023/04/typ...
Talos Blog:
https://blog.talosintelligence.com/ty...
Typhon Github Repo:
https://github.com/p4rab3llum/typhon-...
Cisco Talos IoCs:
https://github.com/Cisco-Talos/IOCs
=========
Chapters
=========
00:00 Intro
01:15 Typhon Reborn Overview
08:05 Typhon Darkweb Advert
12:13 Notable Updates in v2
14:50 String Obfuscations
19:40 Demo of XOR Payload for Reverse Shell
30:40 Anti-Analysis / Sandbox Evasion Overview
33:30 Anti-Analysis Execution Flow and Details
38:20 Stealer Functions
42:30 Data Exfiltration & Covert Channels
45:50 Protections
46:24 IoCs
46:50 Typhon's Github Repo
49:50 Final Thoughts
#cti #cybersecurity #cyberthreats #cyberthreatintelligence #threatintelligence #threathunting #informationsecurity #infosec #malware #malwareanalysis #ethicalhacking #cybersecurityawareness