malware

Red Leaves malware analysis

This technical note discusses a relatively undocumented implant used by the APT10 group. This is named "Red Leaves" after strings found in the malware. The sample discussed was found during an incident response engagement in March 2017. The earliest …

Sakula DLL planting analysis

This technical note discusses a version of Sakula uploaded to VirusTotal on the 25th April 2016. The sample initially looked interesting as it uses a signed Kaspersky binary to load itself, presumably to avoid UAC.