
Betygsätt avsnittet
Bli först med att betygsätta
Om avsnittet
- Publicerad
- 30 aug. 2026
- Längd
- 43 min
- Avsnitt
- E334
#334 - Angripare tar till "vibe hacking" och förenklad malware
Om avsnittet
I dagens avsnitt diskuterar Erik Zalitis och Mattias Jadesköld tillsammans med Patrick Schlapfer på HP. Patrick arbetar till vardags med Threat reseach och ligger bakom HP:s senaste rapport. Vad är det senaste metoderna som angripare använder?
"vibe-hacking" - vad är det? Hur an de komma åt kryptovaluta genom en backupfil? Och hur kan angripare använda ljudfiler för att ta sig in i datorer? Det och en hel del annat i dagens avsnitt som är på engelska!
Bara en sån sak liksom.
Transkript
~43 min · AI-genererat
Detta avsnitt av IT-sektorspodden görs i samarbete med HP. I dagens avsnitt tar vi oss en titt på hotlandskapet tillsammans med HP. Det finns några angrepp som sticker ut under den första delen av 2026.
Ja, precis. Wype hacking, till exempel. Och hur angripare döljer skadlig kod i ljudfiler. Rena gäddfilmen. Ja, det är kanske en sanning som kan läsas ut i HP Wolf Security Threat Insights Report som släpptes för ett par månader sedan.
Det ska vi ta en titt på närmare idag och det gör vi tillsammans med Patrik Schläpfer som arbetar som Principal Threat Research. Vi kommer att prata engelska i detta avsnitt av IT-podden som förutom Patrik består av Mattias Jaderkälv, Excelitis, i vanlig ordning. Welcome Patrik.
Welcome. Hey, thank you so much for having me. How are you? I'm all good. Pretty good actually today. How are you doing? Fine, thank you. We had some issues with the sound, but now it seems to be working.
Eric is happy with the sound solution now. It's always something screwing up with the sound, that's just how it is. Right, okay, so normally you work as a threat researcher at HP.
What you do on a normal basis, Patrik? I do, and that's a good question. Well, I have the fun job to actually look through all the collected telemetry data from our different security solutions, analyze that data and then find all the interesting threats and take them apart.
With all the data and the analysis I do, I do then get to write interesting reports such as the quarterly Threat Insights report. I do also write occasional blog posts, which is published on our threat blog. And I also do share quite a lot of information with the community because in the end security is a game as a team, so sharing is definitely caring.
Besides the whole threat research part, I do work together with the defensive security research team so that we can improve security solutions and create new solutions, which hopefully also protect from the future threats. Right, okay, so a lot of different tasks during a day, I guess. Absolutely, yeah.
And where are you located? I'm actually located in Zurich in Switzerland. Oh, okay. It's a bit of a big difference between Switzerland and Sweden, but... Yeah, I get them confused all the time, isn't it?
Like, yeah, Switzerland and Sweden, same country. Yeah, absolutely. Quite a different place, but both, I would say, very beautiful landscapes. Yeah, definitely. Right, so it seems like you've been working with IT security for some years now, but how did it all start?
Well, that was actually quite some time ago. So when I studied at the university, I grew my interest in security in general, so I decided to take one or the other course in the area of security, like from cryptography to network security to malware analysis. And I decided that malware analysis is probably the most interesting thing to have a look at because I quite like to take apart software and understand how it works.
So after I finished my degree, I actually had the chance to work as a research assistant directly for the university in a research project. So what we built back then was a dynamic malware analysis sandbox, which we created through writing a custom Linux kernel module to basically do virtual machine introspection. I was very much into memory forensic at the time, and with the kernel module, we were able to capture the memory of a virtual machine from the hypervisor level and therefore basically do dynamic analysis without having an ingested agent.
So that was the start and that was the whole fun around malware analysis. I later then decided after the research project, it would be good to understand how security works in the real world outside academia. So I joined to work for a bank in security operations and we focused a lot on incident response, but also did a bit of threat intelligence, basically taking apart and analyzing the threats we see and then share it with the community.
After working for the bank, I was quite keen to understand malware even more in depth. And that's when I actually joined HP as a threat researcher almost six years ago. Yeah, that's been quite an interesting journey.
And here we are six years in. Right. So interesting. Yeah, you have a lot of banks in Switzerland, don't you? So it's a good way to start. Well, I mean, back at the time, this was one of the, I would probably say one of the two main companies who would hire security professionals.
The other one was the government. Definitely very interesting projects as well, but working for a bank was quite an interesting experience as well. Yeah. Right. So we're going to dig into this annual report, as Eric said mentioned in the beginning, that it's called HP Wolf's Security Threat Insight Report.
But a bit overall, what's the reason why this is report being created annually? Well, we do collect all this valuable threat information, right? And one thing I'd like to say is that it does never represent like the full threat landscape.
It's just yet another different vantage point if we compare it to other security vendors and security companies. And therefore, with all the data we have, we thought, well, it's very valuable information, so let's share it with the community. First of all, it gives a lot of security awareness to share a bigger picture of the threat landscape, even on a higher level.
But there are also technical nuggets in the Threat Insights report, such as interesting techniques, which are used by the attackers, which actually help the security practitioners to understand those techniques and then build protections or build detections against those attacks. Right. So, but if you compare this report with previous ones, is there anything that stands out a bit different or something?
Well, that's a wide question, I think, but there are definitely four, I would say, like well, a couple different things that stand out. Well, if we look back about 10 years ago or so, we were used to having those classic attacks with Word documents containing macros, which are then sent as an attachment to the user. And only with probably like one or two clicks, your device was infected.
Back at the time, like Emotet was one of the big malware families, which is luckily not around anymore. Nowadays, it's quite a bit different. So from those two clicks, I would say it's like a click to infection.
This increased quite a bit. So nowadays we see that an infection requires more clicks because the user has to open a file, open an archive file, type in a password and then open probably a script inside it and such kind of things. So this whole amount, number of clicks to infection increased, which also means that attackers and threat actors are focusing a lot more on social engineering.
So the social engineering component in the beginning of an attack becomes very relevant for them. So they invest quite a bit of resources to make them more convincing so the attacker actually, well, performs a specific task. Most often, they try to blend in with standard business operations.
So it's very difficult for a user to distinguish between something legitimate and something malicious. Then another thing we're seeing is that there has been this shared intermediate stage. Now, if we look from a higher level at an infection chain of such a cyber attack, we can probably split it into three different stages.
We have the initial infection with the social engineering. Then we have an intermediate stage with all the scripts which are running, basically which are responsible to then install the final payload. And then in the end, we do have the final payload.
And one of the things we're seeing lately is that not only the social engineering and the final payloads are shared amongst threat actors, but also those intermediate stages. And this tells us that it's not this one man show where a hacker tries to target an organization, but it's a full ecosystem of cybercrime that works together. So threat actors can go and buy malware families, intermediate stages, or also all kinds of different lures off the shelf from hacker markets or from hacking forums and such kind of things.
And then there's one thing I didn't mention yet, but AI is of course also a part of the threat landscape and how it evolves over time, right? So one thing I can say up front is that we haven't seen autonomous attacks as they are like shown in the movies, but attackers are making very much use of AI models to then create all kinds of different stages. For example, the intermediate stage, which is responsible to install the final payload.
It's very often created through wipe coding or so-called wipe hacking. So they use a model and then they tell the model, Hey, in normal language, create me this specific infection stage, do this and that. And then it creates this very well.
And it also works quite well for the social engineering lures in the beginning. So if they want to create like a simple website or if they want to create a simple document or something like this, the AI models are very, very helpful for the attackers in this case. So that would probably be the four main things, I would say.
Yeah, we're gonna dig in a bit more on some topics and some of them are vibe hacking, as Eric mentioned as well. But I found three interesting topics, which from this report, I think we should dive into. So let's start with the first one.
This is about remote tools that hackers are using remote tools like LogMeIn or ScreenConnect. How does this work? Well, that's a good question. So first of all, that's not something that is entirely new, right?
We have seen such attacks in the past, like attackers using official and legitimate remote access tools to compromise devices. That's been around for quite some time. Now, what's different now is that we have seen quite an uptick over the And the complete inventory is pretty much impossible, but having an idea of specific services you're using can be quite helpful.
So if you know that, hey, you're using this or the other remote access tool, then you can monitor for other remote access tools to be used within the same organization, which is probably not legitimate in this case. And then the other thing is that, well, try to install software only from trusted sources. Now, in those specific campaigns, threat actors are actually installing the software.
So it's not a user installing the software, but it's a threat actor. And last but not least, if you control the admin privilege on the user device, then they have less capabilities to install such potentially malicious software on their operating system. Yeah.
Eric, you work as a pentester. Have you ever experienced that these type of attacks using remote tools? Well, as a pentester, I'm trying to do the same pretty much.
So I can't say that. But as working with this SOC, the security operations center, which I kind of help at my company, the company I work for, that is, yeah, we've seen different stuff like that. Mostly they're trying stuff like that with phishing attacks.
But of course, that's not the only show, so to speak. So yeah, that's the thing. No disagreement. Okay, that's good. Okay, let's jump to the next topic, which is also kind of interesting.
A bit outside my comfort zone, because it's about crypto wallets and restore. That it's mentioned in the report that is false restoring of crypto wallets. How does it with this work?
Well, it's like, yeah, that's definitely interesting. So did you ever lose your own crypto wallet? Don't have any. It seems like a smart thing. The only way to win this game is not playing it.
Exactly. Well, definitely, definitely on my side here as well. Well, yeah, what is it? Well, so a crypto wallet, it's basically the key to the kingdom, right? So it's basically a key that you have locally on your device.
If you decide to have it locally, it's a private key, which allows you to gain access to the whole crypto assets you have. The crypto assets themselves are actually stored on the blockchain, such as Bitcoin, as an example. But the private key is something you keep to yourself, hence the name private key.
Now, if an attacker is able to get access to such a private key, then they basically control all the funds you have on the specific blockchain, which is quite a bit disaster in this case. Yeah, because the banks cannot help you in this case because it's decentralized like Bitcoin, for example. Exactly.
Yeah, it's decentralized. So there is no help from anyone. And if an attacker controls the private key, they can basically redirect all your bitcoins or whatever cryptocurrency you are using to yet another wallet because they have the private key and with the private key, they can easily sign new transactions, which then sends the money to someone else, which presumably in this case will be attacker in its own.
That's why attackers are so interested in finding local crypto wallets and exfiltrating those private keys. So this is a very common technique when we look at all kinds of different information stealers. They are usually built in a modular way where they have like all kinds of different capabilities, such as like password stealing or browsing history stealing.
And one of those modules is definitely always like crypto wallet stealers because a crypto wallet can contain quite a lot of money in those days. So if they get hold of one of those wallets, then well, they might be rich at some point. Okay, but how does it work with restoring a crypto wallet?
Where does this come into picture? Now, this is actually the interesting part because this is this is just used as the lure, right? So imagine yourself, you lost your crypto wallet on your device and now you're quite desperate because this is a lot of money and you want to find this crypto wallet again.
So what what's the steps you take? Well, in this desperation, you probably reach out to the internet and search for tools that can recover your crypto wallet because it's a lot of money. And that's basically where the users get trapped because the attacker set up this GitHub repository to tell the user, hey, I built this solution and this solution will actually help you to find your lost crypto wallet on your device.
In reality, in reality, it doesn't do it. In reality, what happens if you download this crypto wallet recovery tool is that, well, it exfiltrates all kinds of interesting and sensitive information. At some point, they do promise what they claim.
They do indeed recover your crypto wallet, but they don't give it to the user, but they simply exfiltrate this crypto wallet and send it to the attacker's server. So besides system information, passwords and browsing data, as I mentioned earlier, they of course also collect crypto wallets. They compress it in an archive file and then they send it to an attacker controlled server in this case.
So yeah, unfortunately, no crypto wallet recovery tool here. All I can say is empathy is not a thing with them. No, absolutely not. No, no. But how can I, if I'm having, if I'm worried about this, how should I avoid these type of attacks?
Well, if you actually lost your crypto wallet on your device, then yeah, it is very frustrating. I do understand this, but don't act too fast. First of all, I would probably try to investigate, well, where is this crypto wallet actually stored on the device?
Like in which folder does it normally reside? And I think that's very different depending on the blockchain you're using. Then in the end, you have different names, right?
Different file names. So what I would suggest if you actually lost it, go and search and investigate how this crypto wallet is built, where it usually resides and what the file name is. And then use like built-in Windows tools or Linux tools if you're using Linux to search for the files in the different folders.
That's definitely better than downloading a random application from an untrusted source. Because, yeah, well, in this case, there were definitely proof to be something malicious. Right.
Okay. Let's go to the third topic, I guess. This called ClickFix campaign. This was, there was some sort of recent attack related to ClickFix. What is ClickFix? Well, ClickFix has actually been around for, well, I don't want to say anything wrong, probably one or two years now.
So it's been around for quite some time. But during this time, they did evolve the attacks and the campaigns. So ClickFix is in the end a social engineering technique.
So what happens is that an attacker builds like a social engineering website or a social engineering image, which convinces the user to basically paste some malicious code into the local Windows run box and then execute malicious code. Actually interesting you would say that because I actually investigated such a code a few weeks ago. And it was extremely clever.
It tried to look like some kind of Cloudflare warning that says, please click and execute this in the run box. And I actually looked through the code and it was extremely well obfuscated, sending those deobfuscator tools into some sort of eternal loop. The obfuscation level of that was like 11 out of 10.
Enormously well done. Seriously. Yeah, I totally believe that. We have seen so many different, like specifically obfuscated scripts, which are terrible to analyze.
And I definitely do get that. Like, I do understand your frustration. I've spent hours picking apart like JavaScript code or VBScript code, which is like, it's unbelievable what kind of techniques attackers can make use of to obfuscate their scripts.
I don't like hackers very much, but I respect them. Begrudgingly, I do respect them. Well, in this case, I actually have to give it to them specifically for the idea to create such a social engineering lure.
Right. I mean, in the past, like if you remember the good old Word and Excel documents where they try to convince the user to click the enable button to basically run the included VBA macros. Now, this was quite basic.
And this was around for probably like 10, 15 years or so. Now, this is a totally new concept. And I think that is quite interesting. And now, if you think around, well, it's been this Cloudflare CAPTCHA you mentioned.
If you think back, like many, many years ago, those CAPTCHAs are not something that are new, right? Because in the end, it's like just the idea to distinguish whether you're an actual user or if you're a robot or if you're some kind of crawler accessing the website. I remember like many years ago, like even like simple web forms had such a very simple CAPTCHA where you get like two numbers, you have to add them together.
And then you have to type in the number in a specific field. And only if the answer was correct, your form was submitted basically to prevent automated attacks. Yeah, I remember that too.
I remember that too. The kind of distinction between them were there were two kinds. They were super secure and no human beings could solve them. Or they were very easy to solve and only hackers could solve them.
Yeah, I mean, that's absolutely true. I mean, I remember well when you get like those other CAPTCHAs, like, hey, yeah, click on all the pictures which contain a mountain, click on all the pictures which contain, I don't know, a bicycle or a car. And I remember sitting in front of the PC, like clicking all the images and then next.
But you felt stupid. It felt like I never got it right. It's like, what the heck? That's supposed to be a mountain, but obviously not for some reason. And another thing was back in the day of PHP BB, if you So you can't expect people to be the same, but they aren't.
I mean, that's to say, some people may actually be old and they have a problem understanding these things because they don't have the skills. Some people may have some kind of mental deficiency, making it impossible for them to solve the CAPTCHAs. This is not a level playing field.
Yeah, I absolutely agree with that, yeah. But about this ClickFix campaign that was mentioned in the report, there was something about malicious code within a sound file. How does that work?
Exactly. Well, if we look quickly at the evolution of those ClickFix campaigns, it's that basically what happens is that the attacker copies malicious code into the clipboard of the user. Then the user wants to fulfill the CAPTCHA, so they press the key combination like Windows R, Control V and Enter.
And that's basically how they execute the malicious code, right? And in the beginning, the threat actors always used PowerShell because PowerShell is just so common. You execute PowerShell, you can supply an encoded command in base64 and then the whole device is infected.
Now, of course, various different solutions which build detection in AV systems actually kept up and improved their detection and are therefore able to block such an attack. But yeah, attackers usually find a way around it. So what the attackers did is instead of launching PowerShell, they decided to use MSHTA.
And MSHTA is very often used to display those help messages if you press F1 in an older program. It shows up and then you have a library of all kinds of different documentations. But what you can do in this case, you can also simply supply an HTML document which contains script code which is then executed on the host system because there is simply no sandbox.
So what the threat actor did in this case is that they simply put in the command line MSHTA and then a link to a sound file. Now, this is not actually a sound file, but it is just using the extension of sound files. And the reason here is that if you look at the web gateway logs, which is something the security operation center usually does, then they will realize that, okay, a sound file was downloaded to the specific device, but it doesn't suspect anything malicious.
Now, in reality, the sound file is actually a script file, in this case, an HTML file contained with JavaScript. And MSHTA doesn't really care what kind of file extension you're using. So you can use like any kind of like sound file or picture or movie file.
It simply executes and renders the file as an HTML within this box. And that's basically the trick we see quite often used by threat actors basically assigning either a wrong file extension or assigning double file extensions. So for example, if a user by default hides file extensions, then they're tricked with a double extension to think that an executable file might be a PDF or that an executable file might be a Word document or something like this.
So this is quite the common technique used by threat actors nowadays. But that seems old, doesn't it? I mean, the whole thing with the double extensions is like, I love you virus kind of days.
That's still a thing, you say? Yeah, it's super old. I mean, like so many techniques are so super old and they still work nowadays, which is to me on the one hand, quite surprising, but on the other hand, like we didn't solve the simple security problems probably as an industry.
And that's that's quite difficult. How do you teach a user to not click on a specific file? Like we usually get also the question, well, if you have this archive file which is distributed by an attacker and within this archive file there is a script file such as like JavaScript or VBS.
Why should the user open this specific file? Because it's not a document, is it? Well, in the end, the user has no idea, right? The user has no clue whether this is an actual document or if this is a script file or if this is an executable file or whatever.
A normal user doesn't even know what a script file is. And that's how we have to look at it. And that's why we have to build like technical protections against such attacks.
Yeah. This is kind of scary because nothing of this feels new. It feels like you're using very old technology onto the users because I do believe that many of those help files, is that really used anymore?
Isn't that kind of a legacy component? That is a really good question. And so in new applications, if you press one, you're usually redirected to a website, right?
I still imagine that there are quite a lot of older applications which do have this helper function implemented through MSHTA. But yeah, that's actually a really good question. I haven't come across many of those, but certainly MSHTA is still part of the operating system, which makes it in some sense even more dangerous for an organization because an organization might lose track of such an executable and therefore they don't track it anymore in their detections and then in their protection mechanisms and therefore open yet another whole attack infection vector for threat actors.
Yeah, but I was thinking about, is it used in the Trident engine? That's like Internet Explorer. Could it be that old? I mean, that's a thing to just like thinking about because Windows such as it is, has a lot of legacy code, stuff that was around in the 90s and the 2000s, such as it was.
And that is not secure and a lot of it is kind of abandoned, but still for some reason works. Totally, totally agree. I mean, if you remember, it's a long time ago, but to be honest, we're still seeing them.
Remember the equation editor exploits. Like where you had like a malicious RTF document and then there was a vulnerability within the Word's equation editor and the threat actor was actually able to well exploit this vulnerability and download and execute a file from a remote server. Now this has been legacy code for a very long time and this has been on Windows system for ages.
And in the end Microsoft actually got rid of this whole equation editor because they had a very new version in new office installations. But nevertheless, we still see attackers using this specific exploit and targeting all kinds of different users. I believe myself that this equation editor is gone on most devices nowadays because that's been like 2017 actually.
But for some reason they're still using it. So probably there is still one or the other device which contains this equation editor and therefore is still vulnerable to this exploit. Right, and how do I prevent these attacks from to happen for me?
Well, to prevent such a click fix attack is certainly not something that is easy, right? Yeah. Run Linux. Well, run Linux. Even though, well, if you run Linux, you do have different distributions and you have like key shortcuts and so on.
In the end, it's very difficult also for a user to understand, but nevertheless, I think this whole concept of the social engineering technique should be part of like an awareness program where you tell the users how to behave. In the end, however, this doesn't solve the problem, right? Awareness is just one aspect, but you have to have a technical solution to protect the users.
So one thing I can think of is that in most cases they use Windows R which opens the run box. Like a normal user in everyday work, they don't use the run box at all. So what you can do is you can use group policies, for example, to disable the run box entirely.
An alternative solution is that, well, if you have a secure browser, so HP basically has this kind of isolation technology where we embed a browser within a micro VM. And there you can disable the clipboard from being used by the website because a normal website can usually simply write to the clipboard if the user clicks a button. There is different permissions.
You can also set in a regular browser, but as far as I know, in most cases, it's very difficult to determine from reading from the clipboard, which is very sensitive and can be restricted to writing to the clipboard, which is often not possible to restrict by the normal user or in a normal browser. So there were various different approaches to protect from such an attack. And I think in the end it has to be a combination of all of those.
All right. Any idea, Eric, how to print this? Yeah, that's the problem. Should you teach people not to do dumb stuff? Should you lock the computers down? Depends on.
I mean, when people are taught not to do stuff, the hackers kind of mutate attacks. So they don't look like what the people were taught not to do. And secondly, all those mechanisms also suffer the same fate.
Basically put, everything looks good now, but the hackers always evolve their attack. Try something a little bit differently. It passes through whatever you locked down.
That's the problem. It's very hard. You can, of course, say, don't do stuff that feels wrong. If it feels like the gut feeling is like, this is weird. Should I really click?
Should I really do this? If the website says, click this in this combination, is that really a good thing to do? I think that's the only thing you can do, basically.
Right. So yeah, a lot of interesting topics that you can read more about in this report. And that is public available, right, Patrick? So we can share the link to the report in this.
Exactly. Yeah. The report is available on our blog website. There is also there are all kinds of other blog posts we usually publish around like different malware campaigns, but around all kinds of other security topics as well.
If people are interested to have a look there as well. And there is actually a new report coming probably mid-end September, which will be published pretty soon. So I'm actually doing the analysis at the moment for this specific report.
I thought
Automatiskt genererat, kan innehålla fel.
Kommentarer
Inga kommentarer ännu. Bli först med att skriva något om avsnittet.
Fler avsnitt
- #336 - Anders Sandberg om allt du behöver veta om AI 202613 sep. 2026 · 1 h 23 min
- #335 - Testdata, för utveckling med informationssäkerhet, har du kontroll?6 sep. 2026 · 45 min
- #333 - Har AI tagit ett kliv i sommar?26 aug. 2026 · 29 min
- #332 - Wordpress säkerhetsresa5 juli 2026 · 46 min
- #331 - AI, säkerheten och tre infallsvinklar8 juni 2026 · 46 min
- #330 - Säker drift av kod samt utveckling med eller utan AI?1 juni 2026 · 29 min
- #329 - Skurkar och hjältar i tevespelen27 maj 2026 · 41 min
- #328 - Cyberkriget i Latinamerika12 maj 2026 · 38 min