Rise of the Vermilion: Cross-Platform Cobalt Strike Beacon Targeting Linux and Windows

Presented at BSidesSF 2022 Rescheduled, June 5, 2022, 1:30 p.m. (25 minutes)

This talk is about the first publicly documented cross-platform Cobalt Strike re-implementation active in real world attacks. Because Cobalt Strike is a heavily used red team tool by threat actors, Vermilion Strike is among the key recent unique discoveries in the malware research world.


Presenters:

  • Ryan Robinson - Intezer
    Ryan Robinson is a security researcher for Intezer. He specializes in malware reverse engineering and threat intelligence. In previous roles, Ryan has worked as a Security Engineer securing cloud applications and as an analyst in Anomali's Threat Research team.
  • Avigayil Mechtinger - Intezer
    Avigayil is a security researcher at Intezer specializing in malware analysis and threat hunting. During her time at Intezer, she has uncovered and documented different malware targeting both Linux and Windows platforms. As part of her ongoing work she has initiated the ELF Malware Analysis 101 series, to make ELF analysis approachable for beginners. Prior to joining Intezer, Avigayil was a cyber analyst in Check Point's mobile threat detection group.

Links: