The Low Down
The Low Down
Rust Supply Chain Chaos, Firefox Crypto Theft, and the DEF CON Conference Phishing Campaign
0:00
-1:09:11

Rust Supply Chain Chaos, Firefox Crypto Theft, and the DEF CON Conference Phishing Campaign

Welcome to The Low Down, the best show on the internet for hackers The Low Down is presented by Maze. LinkedIn: https://www.linkedin.com/company/mazehq/ X: https://twitter.com/Maze_Security Follow Us! https://www.instagram.com/lowdown.pod This week we're recovering from DEF CON and diving into supply chain attacks spreading beyond NPM, sophisticated phishing campaigns targeting conference attendees, and a massive surveillance camera operation spanning Eastern Europe. Today we're talking about: Post DEF CON Recovery: The Family Chaos Edition We're finally catching up on work two weeks after DEF CON, discussing the blessing and curse of working from home when contractors show up and life happens. Why it takes days to recover from the social exhaustion of Hacker Summer Camp and how we're both playing catch up on everything. Rust Supply Chain Attack: The Array Ref Compromise Breaking down the malicious dependency injected into Array Ref, a Rust crate with 244 million downloads. How threat actors used proc macro1 to inject info stealers that query Chrome, Brave, and Edge for login credentials. Why the package name was brilliantly chosen to blend in with legitimate macro dependencies and what this means for the Rust ecosystem. Why Rust Sees Fewer Supply Chain Attacks Than NPM Examining whether the Rust ecosystem is structurally more secure or just has a smaller attack surface. Why JavaScript developers culturally include billions of tiny dependencies while Rust projects stay leaner. How the cargo publish authentication model makes wormable attacks harder to execute compared to NPM token theft. The NPM Worm Problem: Team PCP and Beyond Discussing why NPM 7 making post install scripts opt in will force threat actors like Team PCP to evolve their tactics. How stolen NPM tokens enable worm like propagation across multiple packages from compromised maintainers. Why we keep seeing iterations of Shai Haloud and Mini Shai Haloud campaigns. 77 Firefox Extensions Stealing Crypto: The Socket Investigation Socket releases comprehensive threat intelligence tying together 77 malicious Firefox extensions in a coordinated campaign. Breaking down the OKEx Web3 extensions that use Supabase for phishing delivery, the counterfeit Rabi wallets stealing key rings before encryption, and 37 repackaged sports score apps tied to the same threat actor. Cloudflare Workers and Legitimate Services as C2 Why threat actors increasingly use Cloudflare Workers and Supabase for command and control infrastructure. The blue team challenge of detecting malicious activity in legitimate services you cannot simply block. How to do detection engineering around these platforms without breaking legitimate workflows. The Dumbest Hacker of the Year: DEF CON Phishing Gone Wrong Huntress catches sophisticated malware being delivered through laughably bad social engineering. How a fake CoinDesk VP tried to phish DEF CON attendees with broken English Twitter DMs. Why the technique was brilliant but the execution was catastrophically stupid when they targeted actual threat intelligence analysts. Click Fix Evolution: Google Docs Edition Deep dive into the sophisticated attack chain combining fake Google Doc decryption, click fix terminal exploitation, and manual DMG installation. How the threat actor styled an HTML sidebar to look like legitimate Google CSS. Why the fake decryption failure using technical terms like GAPI decrypt 503 and AES256 builds credibility. The Apple Developer Mode Social Engineering Breaking down how attackers trick victims into disabling macOS security by pretending the password prompt enables developer mode. Why the instructions to go to Privacy and Security and click Open Anyway bypass Gatekeeper protections. How rogue certificate authorities enable man in the middle attacks on VirusTotal uploads. Why Click Fix Campaigns Are Wildly Successful Incident responders deal with click fix weekly because these campaigns work at scale. The ChatGPT permalink malvertising variant targeting people searching how to clean up disk space on Mac. Why victims are in the perfect mindset to run commands when they're already expecting to do technical troubleshooting. Operation Cameras Forum: 14,000 Hacked IP Cameras Hunt.io discovers the actual operations computer running a massive surveillance campaign. How threat actors exploited Dahua cameras across Russia, Ukraine, Vietnam, and Mexico using CVEs from 2021. Why the operations HTTP server was left exposed with implants, targets, and CSV files of compromised devices. Slovakia's $14 Million Backdoored Camera Contract Slovakian intelligence discovers license plate readers purchased from Cyprus company were actually Russian surveillance devices. Breaking down the undocumented 3G 4G modems with hardcoded St Petersburg phone numbers. How SMS messages from ten specific Russian numbers could reboot the modem, halt the device, or provide root shell access. IoT Security Reality Check:

Discussion about this episode

User's avatar

Ready for more?