

#195 - Intel Chat: APT tunnelling, BadPilot, CVE-2025-0108, emojis & Kitty Stealer (take 2)
8 snips Feb 21, 2025
Delve into the intriguing world of network traffic tunneling, where attackers bypass security controls with techniques like DNS and HTTP/S tunneling. Explore the ominous BadPilot campaign linked to Russia's notorious Sandworm group. Discover the critical CVE-2025-0108 vulnerability, which exposes firewall security, and learn about an innovative emoji-based data smuggling technique. Plus, meet Kitty Stealer, a malware targeting macOS user data, showcasing the evolving landscape of cyber threats.
AI Snips
Chapters
Transcript
Episode notes
Ransomware Payment Drop
- Ransomware payments dropped 35% in 2024, totaling $813.55 million.
- Improved defenses, law enforcement actions, and data exfiltration tactics contributed to the decline.
Sustaining Security Efforts
- Continue investing in security measures that proved effective in 2024.
- Analyze successful mitigation and prevention strategies to maintain a downward trend in ransomware payments.
8Base Arrest
- Law enforcement arrested a suspected core member of the 8Base ransomware group.
- 8Base focuses on data theft and extortion, primarily targeting small and medium-sized businesses.