Den Iuzvyk Profile picture
Co-Founder/CTO @ Simplerity #infosec
Oct 17, 2019 12 tweets 2 min read
🔥 Interesting research about The Dukes (aka APT29 and Cozy Bear) from ESET.
welivesecurity.com/2019/10/17/ope…

To save somebody time, it’s 40 pages. Some interesting info in the thread below RegDuke: first stage implant (.net obfuscated via .NET Reactor)
Standard switch/case inside a loop workflow.