Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Proofpoint. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Proofpoint or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

10 Things I Hate About Attribution: A Clustering Conundrum

56:24
 
Share
 

Manage episode 494525077 series 3348167
Content provided by Proofpoint. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Proofpoint or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

Send us fan mail!

Hello to all our cyber detectives and pedantic CTI friends! In this episode of Discarded, host Selena Larson is joined by Greg Lesnewich, Staff Threat Researcher at Proofpoint for a behind-the-scenes look at one of the most frustratingly fascinating attribution cases yet.

What begins as a lighthearted rant: “10 Things I Hate About Attribution,” quickly turns into a deep dive into the murky overlap between TA829 (aka RomCom), TA289, and the elusive GreenSec cluster. From TransferLoader and malware panels to REM proxy infrastructure and attack chain similarities, Greg and Selena dissect the breadcrumb trail that led to a 25-page blog, a mountain of malware chains (Dusty Hammock? Single Camper?), and an attribution headache.

Topics Include:

  • TA829 (aka RomCom) and the elusive GreenSec cluster: What’s the difference?
  • Vertical targeting overlap (and divergence)
  • Malware breakdown: TransferLoader vs. RomCom and related malware
  • Use of REM proxy and rebrand.ly infrastructure
  • Attribution logic and the perils of shared tooling
  • Bonus: Existential mysteries and karaoke mic commentary

The attribution game isn’t always about getting it right—it’s about asking better questions. Join us in the mess, and keep connecting the dots.

For more information about Proofpoint, check out our website.

Subscribe & Follow:

Stay ahead of emerging threats, and subscribe! Happy hunting!

  continue reading

85 episodes

Artwork
iconShare
 
Manage episode 494525077 series 3348167
Content provided by Proofpoint. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Proofpoint or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

Send us fan mail!

Hello to all our cyber detectives and pedantic CTI friends! In this episode of Discarded, host Selena Larson is joined by Greg Lesnewich, Staff Threat Researcher at Proofpoint for a behind-the-scenes look at one of the most frustratingly fascinating attribution cases yet.

What begins as a lighthearted rant: “10 Things I Hate About Attribution,” quickly turns into a deep dive into the murky overlap between TA829 (aka RomCom), TA289, and the elusive GreenSec cluster. From TransferLoader and malware panels to REM proxy infrastructure and attack chain similarities, Greg and Selena dissect the breadcrumb trail that led to a 25-page blog, a mountain of malware chains (Dusty Hammock? Single Camper?), and an attribution headache.

Topics Include:

  • TA829 (aka RomCom) and the elusive GreenSec cluster: What’s the difference?
  • Vertical targeting overlap (and divergence)
  • Malware breakdown: TransferLoader vs. RomCom and related malware
  • Use of REM proxy and rebrand.ly infrastructure
  • Attribution logic and the perils of shared tooling
  • Bonus: Existential mysteries and karaoke mic commentary

The attribution game isn’t always about getting it right—it’s about asking better questions. Join us in the mess, and keep connecting the dots.

For more information about Proofpoint, check out our website.

Subscribe & Follow:

Stay ahead of emerging threats, and subscribe! Happy hunting!

  continue reading

85 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play