A good read and analysis.
Some of the issues raised are direct reasons for IFIN’s existence.
A good read and analysis.
Some of the issues raised are direct reasons for IFIN’s existence.
One immediate issue I notice with this analysis is the characterization of “infostealers like Redline, Lumma, or Stealc” as “highly effective but technically rudimentary”. Characterizing widely distributed infostealers as “technically rudimentary” is straight up just not true. Anyone who has had to actually deal with reversing Lumma or reversing StealC or reversing Rhadamanthys would seriously doubt that characterization, and those are three links, right there, to three technical deep dive articles that show exactly how interesting and annoying these stealers are to analyze.
This kind of very widely distributed, eCrime commodity malware tends towards being more technically sophisticated than targeted nation-state malware. The people who develop and/or sell this malware have an incentive to make it as hard as possible for researchers to automatically track the malware, get the actual payload modules, and mass-block their infrastructure.
To be quite honest, the author stating it this way makes me doubt that they’ve actually done any malware analysis recently.
Very good counterpoints! I had similar feelings on those arguments, thinking that I had seen rather complex malware well-analyzed. I do think the later points in the article still have value. The commoditization of second and third stages is a real trend, as is the commercialization of threat intelligence at large.
I would recommend reading the authors posts w/ Unit42 because they have been doing recentish malware analysis - Dominik Reichel, Author at Unit 42
The folks at Three Buddy Problem also had a similar discussion on this article specifically in their latest podcast (Three Buddy Problem: The disappointing death of big-game APT reporting)
I wonder too how much of this perspective is also just nostalgia and wishing intel reports read like the APT 1 report today. Even looking at that link I just posted, Dominik’s malware reports are really boring to read and lack any character or flavor. “This dropper does x, which starts y process, which exfiltrates z data” reads to me like someone who’s lost their passion for the industry.