Cyber Citadel: Episode 4 - Insights into PoolParty, COLDRIVER, and Lazarus Exploits....
1. PoolParty Process Injection Techniques - SafeBreach's Alon Leviev unveiled eight ingenious methods designed to execute code within Windows systems, skillfully evading detection by EDR systems. 2. COLDRIVER's Tactical Evolution - The threat actor COLDRIVER, also known as Star Blizzard, SEABORGIUM, and more, intensifies its credential theft operations, deploying deceptive domains and sophisticated evasion tactics. 3. Lazarus Group's Espionage Continues - Operation Blacksmith, orchestrated by the Lazarus Group, targets Log4j vulnerabilities to deploy RATs, revealing a strategic shift in their espionage activities.