LIVE · cybersecurity feed
Live wire
vulnerability

Chasing AMMYY at Splunk .conf

A recent report detailed the detection of Flawed AMMYY RAT traffic at the Splunk .conf event, an incident uncovered through the combined capabilities of Cisco's Encrypted Visibility Engine (EVE) and Endace PCAP. The key takeaway from this discovery was the ability to identify this malicious activity without the need to decrypt TLS-encrypted communications, highlighting advancements in network…

ZeroDay News ·

Source: Cisco Security Blog

Photo: FASTILY (CC BY-SA 4.0) via Wikimedia Commons

A recent report detailed the detection of Flawed AMMYY RAT traffic at the Splunk .conf event, an incident uncovered through the combined capabilities of Cisco's Encrypted Visibility Engine (EVE) and Endace PCAP. The key takeaway from this discovery was the ability to identify this malicious activity without the need to decrypt TLS-encrypted communications, highlighting advancements in network visibility tools.

The technical mechanism behind this detection centers on the analysis of network traffic metadata and behavioral patterns rather than deep packet inspection of encrypted payloads. Cisco EVE, as an encrypted visibility engine, is designed to infer the presence of threats within encrypted traffic by observing characteristics such as connection patterns, certificate anomalies, and other flow-level telemetry. This approach allows security teams to gain insights into encrypted communications without compromising user privacy or introducing the operational complexities often associated with TLS decryption at scale.

Endace PCAP complements this by providing full packet capture capabilities. This allows for the retention of network traffic for retrospective analysis, forensics, and verification. When EVE flags suspicious encrypted traffic, the corresponding PCAP data can be reviewed to confirm the presence of anomalous patterns, even if the content remains encrypted. This combination is particularly effective against malware like Flawed AMMYY RAT, which, despite using encryption, often exhibits distinct network communication patterns that can be identified through advanced analytics.

Flawed AMMYY RAT is a well-known remote access trojan often associated with financially motivated cybercrime and targeted attacks. Its use of legitimate remote access software components can make it challenging to detect through traditional signature-based methods, especially when its command-and-control (C2) communications are encrypted. The ability to detect such threats without decryption is a significant advantage in environments where pervasive TLS encryption is the norm.

The likely scope of such a detection mechanism extends to any network environment where Cisco EVE and Endace PCAP are deployed. Events like large conferences, with their diverse and often untrusted network traffic, represent a challenging environment for security monitoring. The successful identification of Flawed AMMYY RAT in such a setting demonstrates the potential for these tools to enhance security posture in complex and dynamic networks.

Typical mitigation guidance for this class of issue involves a multi-layered approach. Beyond advanced detection, organizations are advised to implement robust endpoint security, network segmentation, and user awareness training. Regular patching and vulnerability management are also critical, as is the continuous monitoring of network traffic for anomalous behaviors. For detected threats, incident response protocols should be activated to contain, eradicate, and recover from the compromise.

This incident underscores the ongoing evolution of network security tools in response to the increasing prevalence of encrypted traffic and sophisticated malware. As attackers increasingly leverage encryption to evade detection, the development of non-decrypting visibility solutions becomes crucial for maintaining effective threat intelligence and defensive capabilities in modern enterprise networks.

vulnerabilitymalware
ShareXLinkedInWhatsAppFacebook

More News

view all →
breachcritical

Cisco Patches a Dozen Critical Vulnerabilities

Cisco has released patches addressing a dozen critical vulnerabilities across its product line. These security defects reportedly encompass a range of potential impacts, including unauthorized access, information leaks, privilege escalation, denial-of-service (DoS) attacks, and remote code execution (RCE). The widespread nature of these reported flaws suggests a significant security update…

vulnerabilitycritical

Cisco warns of critical flaws allowing Nexus switch takeover

Cisco has issued a warning regarding five critical vulnerabilities identified in its NX-OS data center network operating system, which could enable attackers to execute arbitrary code with root privileges on Nexus switches. In scenarios where remote code execution is not achievable, exploitation of these flaws could lead to process crashes and device reloads, resulting in denial-of-service…

malware

Midnight Mimosa Malware Found Preinstalled on Low-Cost Android Phones

Recent reports indicate that a new malware strain, dubbed "Midnight Mimosa," has been discovered preinstalled on certain low-cost Android smartphones. This finding suggests that some devices may be compromised with malicious software embedded directly into their firmware before they even reach consumers, posing a significant supply chain security risk.

malware

UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

A Russia-aligned threat actor, UAC-0099, has reportedly been observed deploying a new .NET-based infostealer and remote access trojan (RAT) named ASHVEIN. This malware has been specifically used in attacks targeting Ukrainian government personnel. The cybersecurity firm TrendAI is tracking this activity cluster under the designation Earth Sirrush, which was previously known as SHADOW-EARTH-065.

cloud

Admin in the Loop: Firewalls and the Agentic SOC

A recent report details the integration of Cisco Secure Firewall and Cloud Control with Splunk ES, specifically highlighting its role in feeding structured Snort 3 and EVE telemetry into an "Agentic SOC pipeline." This integration is presented as a foundational element for advanced security operations, leveraging automated data streams for analysis and response.

ai

Who watches the AI watching your street?

Yusaku Fujii, a professor at Gunma University in Japan, has developed a system designed to audit and penalize the misuse of artificial intelligence that analyzes street camera footage. His proposal, called the Verifiable Record of AI Output (VRAIO), aims to ensure accountability for AI systems operating in what he terms Fully Monitored Public Spaces (FMPS), areas with dense camera coverage…