Join us at Gartner SEC London and discover how LevelBlue can help you secure what’s next. Learn More

SpiderLabs Blog

Explore the latest threats, critical vulnerability disclosures, cutting-edge research, and intelligence from our elite global threat experts.

circleradial-blogs

Using the InterPlanetary File System For Offensive Operations

January 02, 2020 | Stephan Borosh

Introduction In this blog post, I intend to provide some insight into using the ...

Leveraging Disk Imaging Tools to Deliver RATs

December 23, 2019 | Joshua Deacon, Diana Lopera, Fahim Abbasi

This year we observed a notable uptick in disc imaging software (like .ISO) ...

Undressing the REvil

December 20, 2019 | Rodel Mendrez

Contributors: Lloyd Macrohon and Rodel Mendrez

Anyone Can Check for Magecart with Just the Browser

December 18, 2019 | Michael Yuen

In the past, there have been plenty of articles and blog posts recommending the ...

Typosquatting in Python Repositories

December 13, 2019 | Radoslaw Zdonczyk

Python's popularity is amazing and constantly growing. For the first time, ...

Patch Tuesday, December 2019

December 10, 2019 | Karl Sigler

December's Patch Tuesday is upon us, and, as in years gone by, it's a rather ...

SCshell: Fileless Lateral Movement Using Service Manager

December 09, 2019 | Charles Hamilton

During red team engagements, lateral movement in a network is crucial. In ...

CVE-2019-1429: (Another) Microsoft Internet Explorer 0-Day

December 05, 2019 | SpiderLabs Researcher

November’s Patch Tuesday from Microsoft included a patch for yet another ...

Introducing Password Cracking Manager: CrackQ

December 04, 2019 | Daniel Turner

Today we are releasing CrackQ, a queuing system to manage password cracking ...

Time Windows for Penetration Testing

November 22, 2019 | Albert Campa

Often when penetration tests are scheduled, it will be requested that testing ...

CVE-2019-15652: SatLink VSAT Vulnerabilities

November 21, 2019 | Robert Foggia

Back in May of this year, I discovered a few vulnerabilities in the SatLink ...

Fake Windows Update Spam Leads to Cyborg Ransomware and Its Builder

November 19, 2019 | Diana Lopera

Recently, fake Microsoft Windows Update emails were spammed with the following ...

Windows Debugging & Exploiting Part 2 - WinDBG 101

November 18, 2019 | Bruno Oliveira

Introduction Hello again! After our previous post about the environment setup, ...

Fingerprinting FreeBSD OS Versions using OpenSSH

November 14, 2019 | Manuel Nader

In the past, we’ve described how to fingerprint Ubuntu OS Version using ...

A Call for Cooler Heads

November 08, 2019 | Trustwave SpiderLabs

One of the unfortunate parts of a business like ours is when disputes arise ...

Double Loaded Zip File Delivers Nanocore

November 05, 2019 | Diana Lopera

Most malware sent via emails is packaged in archives such as ZIP, RAR, and 7z ...

Windows Debugging & Exploiting Part 1 - Environment Setup

October 23, 2019 | Bruno Oliveira

Introduction In this blog series, I will try to set some base knowledge for ...

Messing with Azorult Part 2: Command and Control

October 18, 2019 | Rodel Mendrez

As we mentioned in our earlier blog, Azorult is very popular in the underground ...

Messing with Azorult Part 1: Malware Breakdown

October 15, 2019 | Rodel Mendrez

In this blog series, we dive into an information stealing Trojan called Azorult ...

Patch Tuesday, October 2019

October 08, 2019 | Karl Sigler

Microsoft’s security update for the month of October is one of the lightest ...

Chaining Low/Info Level Vulnerabilities for Pwnage

September 30, 2019 | Liam Somerville

Chained Critical Everyone gets critical. It’s part of our vernacular: ...

Documents with IRM Password Protection Lead to Remcos RAT

September 27, 2019 | Diana Lopera

Documents attached to emails are commonly used as the initial vector to deliver ...

Digital Canaries in a Coal Mine: Detecting Enumeration with DNS and AD

September 26, 2019 | Stephan Borosh

Introduction A fundamental part of any network is the Domain Name Service ...

Tracking the Chameleon Spam Campaign

September 25, 2019 | Dr. Fahim Abbasi

In this blog, we draw attention to a persistent high-volume spam campaign that ...

Microsoft Internet Explorer Remote Code Execution 0-Day (CVE-2019-1367)

September 24, 2019 | SpiderLabs Researcher

Microsoft released an out-of-band patch for a 0-day vulnerability in Internet ...

Remote Code Execution and other Vulnerabilities in WS_FTP Server

September 18, 2019 | Dan Bastone and Devon Greene

CVE-2019-12143, CVE-2019-12144, CVE-2019-12145, CVE-2019-12146: Multiple ...

Getting Started With Azure DevOps

September 18, 2019 | Stephan Borosh

Recently, I set out to find a simple solution to manage the building of all my ...

Patch Tuesday, September 2019

September 11, 2019 | Karl Sigler

For September 2019, Microsoft is releasing 78 CVEs. Of these CVEs, 17 are rated ...