Insights from the front lines of cyber
defense powered by Eye Research.

STORIES FROM THE SOC: Eye see you, Axios

Eye Security investigates new threat actors and their methods, focusing on business email compromise (BEC). For example, an alert was triggered when a phishing attempt bypassed multi-factor authentication. Analysts quickly revoked access, limiting damage to a stolen password. Their rapid response ensures threats are mitigated effectively.

“Master” Malware – a new C2 framework

A new malware sample was discovered during an incident response engagement, suggesting potential ransomware deployment while bypassing antivirus defenses. This malware, dubbed "Master," is Python-based and acts as a C2 framework. It utilizes multiple encoding schemes common in Eastern Europe and supports diverse commands, highlighting flaws in traditional antivirus systems.

How Microsoft might have lured unsuspecting end-users into the hands of criminals

Eye Security conducted phishing simulations and tested Microsoft's Attack Simulator. They discovered a vulnerability where links in simulation emails pointed to unregistered domains, allowing potential exploitation. After reporting to Microsoft, the issue was confirmed and addressed multiple times, highlighting the importance of vigilant cybersecurity measures and quick response capabilities.