Some weeks ago, Heinrich and I had the pleasure to participate in the
heisec-Webinar
“Emotet bei Heise – Lernen aus unseren Fehlern”.
We really enjoyed the webinar and the (alas, due to the format: too short)
discussions and we hope we could contribute to understand how to make Active
Directory implementations out there a bit safer in the future.
Now, I have the pleasure to announce a continuation of our talk about Active
Directory security next week, Wednesday, 14^(th) of August @heisec in the format
of a technical talk
“Emotet bei Heise – Online-Fachgespräch zum Schutz vor Cybercrime”.
Seats are still available 😉
After the
Emotet Incident at Heise,
where
ERNW has been consulted for Incident Response,
we decided to start a blogpost series, in which we want to regularly report on
current attacks that we observe. In particular we want to provide details about
the utilized pieces of malware, different stages, and techniques used for the
initial infection and lateral movement. We hope that this information might help
you to detect ongoing incidents, apply countermeasures, and in the best case to
figure out proactive countermeasures and security controls beforehand.
Heise berichtet aktuell öffentlich über die
Emotet-Infektion im eigenen Haus,
bei dessen Aufklärung ERNW unterstützte.
Damit liefert Heise Informationen
zum Verlauf aktueller Angriffe, aber insbesondere auch wertvolle Einsichten zu
Vorbeugung, Erkennung, Analyse und Gegenmaßnahmen aus eigener Erfahrung, wie sie
nur selten der Öffentlichkeit preisgegeben werden.
Ein Team aus Incident-Response Spezialisten der ERNW Research unterstützte Heise
bei der Analyse und Rekonstruktion des Vorfalls und analysierte die
Schadsoftware, um deren Ausbreitungswege nachzuvollziehen und IoCs (Indicators
of Compromise) zu extrahieren. Hierdurch konnten effektive Gegenmaßnahmen
entwickelt und gemeinsam mit Heise erfolgreich umgesetzt werden.