CYFIRMA

CYFIRMA Research

News EN ↓ 322 episodes

Cyber defenders, listen up! The CYFIRMA Research podcast has some juicy intel on the latest cyber threats that are lurking in the shadows. Tune in to this security briefing to stay on top of emerging threats and be ready to tackle digital risk like never before.

Author

CYFIRMA

Category

News

Podcast website

www.cyfirma.com

Latest episode

Jul 7, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

CYFIRMA Research - Episode 047: Philippines Threat Overview 11.10.2023

Our latest report unveils the pulse of cyber security threats in the Philippines! From the escalating risk of state sponsored espionage by global actors like China, North Korea, and Russia to the surge in ransomware attacks targeting key industries, including finance, government, healthcare, education, and retail, the nation is at a crossroads. Recent incidents, such as the widespread data breach...

CYFIRMA Research - Episode 046: NORTH KOREA–RUSSIA SUMMIT: A NEW ALLIANCE IN CYBERSPACE? 09.10.2023

September’s North Korea – Russia summit stoked fears that there could be increased weapons and technology transfers between the two nations, hostile to the West and its partners in Asia, with North Korea providing Russia with munitions for its war in Ukraine, in exchange for sensitive nuclear, missile and cyber knowhow. Both regimes have much to gain from each other at this particular geopolitical...

CYFIRMA Research - Episode 045: TRACKING RANSOMWARE – SEPTEMBER 2023 05.10.2023

Stay ahead of ransomware threats with our September 2023 Ransomware Report, which provides essential insights into the evolving landscape. The latest monthly report from CYFIRMA reveals a dynamic threat landscape marked by widespread ransomware attacks that have had a significant impact on critical industries worldwide. The 'LockBit' group has taken the lead, targeting 79 victims, while...

CYFIRMA Research- Episode 044: CHIT-CHAT WITH A RANSOMWARE OPERATOR 04.10.2023

Learn about the experience of a ransomware operator in their own words!   CYFIRMA Research recently published a report on a new threat actor group known as Fusion Core. In a follow-up, we were able to get in touch with “NecroSys”, who is the developer of SarinLocker ransomware and the current face of FusionCore. Read what NecroSys has to say about FusionCore's alleged links with APTgroups, th...

CYFIRMA Research - Episode 43: The Thin Line: Educational Tools vs. Malicious Threats – A Focus on The-Murk-Stealer 03.10.2023

CYFIRMA Research's latest report unveils "The-Murk-Stealer," an open-source threat that covertly extracts a wide array of information designed to infiltrate systems and harvest sensitive data. From gaming files to cryptocurrency wallet details, this malware operates stealthily, underlining the importance of heightened vigilance and advanced cybersecurity strategies.   Furthermore, o...

CYFIRMA Research - Episode 042: Apache NiFi CVE-2023- 34468 RCE Vulnerability Analysis and Exploitation 29.09.2023

CYFIRMA Research examines a MAJOR threat - CVE-2023-34468 in Apache NiFi! This vulnerability risks your data integration and automation tool, allowing remote code execution through manipulative H2 database connection strings. The implications are severe– unauthorized access, compromised data integrity, and the potential for remote code execution, all leading to substantial operational and reputati...

CYFIRMA Research - Episode 041: Japan Threat Landscape 27.09.2023

Japan's Threat Landscape ETLM Report reveals the dynamic challenges faced by this economic powerhouse. From state-sponsored giants to stealthy financial hackers, gain insights into the full spectrum of cyber threats impacting Japan's cutting-edge tech, automotive, and financial sectors. With an extensive network of overseas subsidiaries and proximity to cyber-capable neighbours, Japan st...

CYFIRMA Research - Episode 040: Mini Cyber-Conflict Leaving Impact on Small Businesses and Government Sector 22.09.2023

 CYFIRMA’s Research team is closely monitoring an evolving cyber conflict between independent hacktivist groups in Asia and the middle east. This isn't state backed, but it's impacting small businesses.   A surge in cyber-attacks from Islamic countries like Indonesia, Pakistan, Bangladesh, Afghanistan, and Malaysia, initially sparked by perceived injustices against Muslims in India, has...

CYFIRMA Research - Episode 039: RedLine Stealer: A new variant surfaces, Deploying using Batch Script 19.09.2023

CYFIRMA Research delves deep into the new variant of RedLine Stealer, investigating this novel strain of malware, disguising as a document packaged within a zip archive that houses a batch script file.   RedLine Stealer is designed to steal sensitive information from the compromised system and is available on underground forums as Malware-as-a-Service (MaaS).   The best way to protect organization...

CYFIRMA Research - Episode 038: Malware Detection: Evasion Techniques 15.09.2023

In today's ever-evolving cybersecurity landscape, the role of malware detection solutions has become more critical than ever. As cybercriminals continually evolve their evasion tactics, it's essential to understand the intricate web of strategies they employ; from signature-based to behaviour-based and anti-analysis techniques. Discover why these evasion methods overlap and how they chal...

CYFIRMA Research - Episode 037: Tracking Ransomware- August 2023 07.09.2023

The CYFIRMA monthly Ransomware Report report thoroughly analyses ransomware activity in August 2023, covering significant attacks, the top five ransomware families, geographical distribution, targeted industries, evolution of attacks, new ransomware groups, vulnerabilities exploited by ransomware groups, and trends between July and August 2023. Organizations can leverage these insights to enhance...

CYFIRMA Research - Episode 036: New MaaS Prysmax Launches Fully Undetectable Infostealer 05.09.2023

CYFIRMA delves into the Prysmax  MaaS operations, currently promoting their new stealer- Prysmax Stealer. Almost all the builds of the infostealer have zero detections by signature-based solutions. The infostealer was released in June this year and has remained undetected by over 95% of antivirus vendors - no matter how many times it is scanned. It is a sophisticated tool designed to covertly stea...

CYFIRMA Research - Episode 035: The China–Russia Nexus: Fortress Eurasia or Strategic Rivalry? 01.09.2023

When dealing with the question of the strategic relationship between China and Russia, the narrative often splits between camps of proponents of upcoming fortress EURASIA or inevitable future rift between historical rivals. In this research, CYFIRMA Researchers are looking at the relationship between the two cyber superpowers, their military and intelligence cooperation and the possible future of...

CYFIRMA Research - Episode 034: Unveiling CVE-2023-3519: Citrix ADC & Gateway Vulnerability Analysis 28.08.2023

A critical unauthenticated remote code execution vulnerability, denoted as CVE- 2023-3519, has been exposed within the architecture of Citrix ADC and Citrix Gateway products. This flaw enables threat actors to execute arbitrary code on susceptible systems without the need for authentication: this signifies a grave security concern, impacting numerous Citrix instances on a global scale, with the po...

CYFIRMA Research - Episode 033: The Persistent Danger of Remcos RAT 24.08.2023

The latest report by CYFIRMA Research delves deep into the Remcos Remote Access Trojan (RAT). This analysis uncovers a complex ecosystem of tactics, IPs, and advanced payloads utilized by malicious actors. From initial infection to persistent control, we explore the dynamic landscape of cyber threats and the need for proactive defense measures.   Discover the evolving tactics of the Remcos RAT cam...

CYFIRMA Research - Episode 032: Unmasking EVLF DEV-The Creator of CypherRAT and CraxsRAT 22.08.2023

CYFIRMA Research analysis EVLF, the MaaS operator behind CypherRAT & CraxsRAT.    These malicious tools grant remote access to cameras, mics, filesystem and applications on victim devices. With features like live screen monitoring, shell access and Google play protect bypass features, CraxsRAT can be categorized as one of the most dangerous android RATs in the current threat landscape.    Over...

CYFIRMA Research - Episode 031: TRACKING RANSOMWARE– JULY 2023 17.08.2023

The latest CYFIRMA Monthly Ransomware report presents an evolving threat landscape marked by a surge in ransomware attacks, significantly impacting critical industries on a global scale. The 'Cl0p' group stands at the forefront, targeting 183 victims, while the IT and Manufacturing sectors endure the highest toll, each encountering 50 incidents. The United States faces the brunt with 186...

CYFIRMA Research - Episode 030: Stealthy malicious MSI Loader - Overlapping Technique and Infrastructure with BatLoader! 15.08.2023

The Cyfirma Research team has recently discovered a disguised Stealthy MSI Loader being advertised in underground forums by Russian threat actor, showcasing its remarkable ability to evade detection by both Virus Total scan and Windows Defender. Additionally, through our investigation, we have established a link between this MSI Loader and the BatLoader campaign observed in March 2023, highlightin...

CYFIRMA Research - Episode 029: RANSOMWARE TRENDS: H1 2023 Part-2 10.08.2023

This report is Part 2 of a comprehensive analysis of ransomware activity in 2023. Part 1 covered major ransomware attacks, the top five prolific ransomware families since January 2023, and the geographical distribution of ransomware, whereas, this publication will delve into targeted industries, industrial trends analysis for H1-2022 and H1-2023, the ongoing evolution of ransomware attacks, notabl...

CYFIRMA Research - Episode 028: ANONYMOUS SUDAN: A BYPRODUCT OF CIVIL WAR? 09.08.2023

Since the beginning of 2023, a new hacking collective has appeared, claiming origins in Sudan; a war-torn African country with a pre-modern societal structure, limited internet connectivity, and very low per capita incomes. A Russian private military company which executes elements of foreign policy for the Kremlin has been operating in the country for years, and the self-described Islamist hackti...

CYFIRMA Research - Episode 027: RANSOMWARE TRENDS: H1 2023- Part 1 03.08.2023

This two-part report provides a comprehensive analysis of ransomware activity in 2023, where part 1 covers major ransomware attacks, the top five prolific ransomware families, since January 2023, and the geographical distribution of ransomware. ​​​​​​​In 2023, major companies and government departments such as, Yum! Brands, Royal Mail, and the US Marshals Service were amongst the victims of cyberc...

CYFIRMA Research - Episode 026: APT Bahamut Targets Individuals with Android Malware Using Spear Messaging 02.08.2023

The team at CYFIRMA recently obtained advanced Android malware targeting individuals in the South Asia region. The suspicious Android malware is a dummy chatting app named SafeChat that was initially disguised as a harmless chatting app called Coverlm on WhatsApp. The user interface of this app is designed in such a convincing manner that it successfully deceives users into believing it to be auth...

CYFIRMA Research - Episode 025: Analyzing the Ultimate Member Plugin Vulnerability – CVE-2023-3460 31.07.2023

CYRFIRMA Research examines a MAJOR threat - CVE-2023-3460 in Ultimate Member Plugin!   This flaw in the widely used Ultimate Member WordPress Plugin allows attackers to escalate privileges, bypassing regular security measures. By exploiting the zero-day vulnerability, attackers can manipulate user roles, leading to data breaches, content tampering, and worse. Don't let your website be the nex...

CYFIRMA Research - Episode 24: Attacker-Crypter (v0.9): Unveiling a Powerful Tool for Evading Antivirus and Enhancing Malware Capabilities 26.07.2023

Cyfirma remains committed to tracking new threats and trends in the cybersecurity landscape. One noteworthy tool that has emerged is Attacker-Crypter. A crypter is a type of software that can encrypt, obfuscate and manipulate malicious code to make detection harder by the security tools, and is used by cybercriminals to create malware that can deceive security checks and AV detections.  Attacker-...

CYFIRMA Research - Episode 023: DEV-0970/Storm-0970: The Threat Actors Behind Big Head and Poop69 Ransomware 20.07.2023

CYRFIRMA Research team has uncovered the recent activities of DEV-0970/Storm-0970, a financially motivated threat actor group. Armed with a ransomware builder, acquired from a Malware-as-a-Service operator, they unleash multiple ransomware variants to expand their malicious arsenal. Our report highlights the connection between Poop69 and BIG HEAD ransomware, which we attribute to DEV-0970/Storm-09...

Listen to the CYFIRMA Research podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.