CyberWire Daily cover image

CosmicEnergy: OT and ICS malware from Russia, maybe for red teaming. Updates on Volt Typhoon. Legion malware upgraded for the cloud. Natural-disaster-themed online fraud.

CyberWire Daily

00:00

The Atlantic Hurricane Season and Social Engineering Techniques

Legion, a commercial malware tool, has been upgraded to target Amazon Web Services from which it extracts credentials for authentication over SSH. Cato's security released a report on the threat emphasizing the progression towards exploiting more cloud services. Legion is known for its use of Telegram as an avenue of exfiltration and sending spam messages to dynamically generated US mobile numbers by making use of the stolen SMTP credentials.

Play episode from 05:54
Transcript

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app