NSO Pegasus Malware - How Governments spy on any phone

  Рет қаралды 13,879

cybercdh

cybercdh

Күн бұрын

Пікірлер: 47
@Pocketpapi-JP
@Pocketpapi-JP 3 жыл бұрын
As a newby in the cyber security field, this video was super good at explaining what this vulnerability is and how it was exploited by this malware. Gained a new subscriber 🤙🏽
@cybercdh
@cybercdh 3 жыл бұрын
welcome :)
@ReversingHub
@ReversingHub 3 жыл бұрын
Awesome analysis! Thanks for posting this! One small note, the strings app for macOS finds ASCII, that's why I believe it didn't work for that sample. Thanks again!
@thehen101
@thehen101 3 жыл бұрын
Nice video, good catch with the domain. OA Labs did a similar thing with a ~20 year old sample and he had hundreds of computers phoning home if I recall correctly. It would also be very interesting to see if you could get your hands on the code that was doing those requests you were talking about right at the start. (had to re-phrase this comment, youtube silently removed it the first time around, they are autocensoring comments with keywords in them)
@cybercdh
@cybercdh 3 жыл бұрын
OALabs rock for sure :)
@produKtNZ
@produKtNZ 3 жыл бұрын
Are you in any way able to advise what filterlist for Pi-Hole you would use fpr additional protection from these threats?
@snowdoxsecurity8486
@snowdoxsecurity8486 3 жыл бұрын
Excellent video as usual bro..... Thank you for doing this 😊 🔥
@cmdsecure
@cmdsecure 3 жыл бұрын
Excellent walkthrough as usual Colin. Particularly in the threat intel side, really interesting.
@Kattakam
@Kattakam 3 жыл бұрын
Amen brother, spot on about the lack of response. Just have to play the long game and hope for the best since there’s no possible way to completely re-engineer unless you’re the one writing the code. Educating institutions and users isn’t going to be as impactful as a critical mass event, which is, in this case what must happen to make the scale of change needed.
@DiendaMadick
@DiendaMadick 9 ай бұрын
If I was to see an app called Pegasus in my IOS crash analytics is that the same software/spyware? I got the phone from a pawn shop and eventually just ditched it but can it show up in crash logs? No idea who's phone it was before me. This was about a year ago
@DarkLord-mp8fu
@DarkLord-mp8fu 3 жыл бұрын
Amazing work! Loved it.
@kcthewanderer
@kcthewanderer 3 жыл бұрын
I've never used Patreon. That's about to change. These videos are excellent!
@cybercdh
@cybercdh 3 жыл бұрын
Amazing - much appreciated!!
@lahcenedaif7953
@lahcenedaif7953 3 жыл бұрын
Thank you for this high quality content keep it up 👏👏👏
@J4vv4D
@J4vv4D 3 жыл бұрын
Brilliant job! Thanks for sharing
@TheAdeelkhaliq
@TheAdeelkhaliq 3 жыл бұрын
Great work! Loved your dedication
@adelettouati4820
@adelettouati4820 3 жыл бұрын
Great Work Thanks for sharing , waiting for more Colin
@codinguy
@codinguy 3 жыл бұрын
Great video, excellent and really interesting work, love it 😍
@PrinterJamOnToast
@PrinterJamOnToast 3 жыл бұрын
Hi Colin - I'm currently going through the "Practical Malware Analysis" book, and was wondering if you think I should learn C before I learn Assembly, or vice versa?
@cybercdh
@cybercdh 3 жыл бұрын
There’s no right path tbh, personally I knew more about C before I tackled an intro to x86. I found it made more sense having learned some basic principles with C. But YMMV.
@PrinterJamOnToast
@PrinterJamOnToast 3 жыл бұрын
@@cybercdh Thanks! I have started going through a beginners book on C. I will do a deep dive on x86 after I finish it, and then will continue learning at least how to read other languages (VBA, JavaScript, etc.) by going through source code. I am trying to avoid doing practical coding exercises because I think that an understanding of the syntax plus using Google, will be enough to understand what a piece of malware is trying to achieve. Would you agree with this?
@cybercdh
@cybercdh 3 жыл бұрын
@@PrinterJamOnToast I think it’s a great pathway that will definitely help you explore the world of malware. Consider writing a blog; or tweeting about your progress, no doubt others will benefit from your journey
@PrinterJamOnToast
@PrinterJamOnToast 3 жыл бұрын
@@cybercdh Many thanks 🙏
@andrewh619
@andrewh619 3 жыл бұрын
I mean honestly, how do i get your knowledge....
@cybercdh
@cybercdh 3 жыл бұрын
There’s a LOT I don’t know.
@sbakor8043
@sbakor8043 3 жыл бұрын
Why do you think they would send a text with a domain they haven't registered? is it just because they don't need the user to click anything and they just put something random there?
@cybercdh
@cybercdh 3 жыл бұрын
They previously owned the domain, but let it expire.
@strudders2112
@strudders2112 3 жыл бұрын
Great Video as usual. Thanks.
@johnsnow228
@johnsnow228 2 жыл бұрын
Anyone know a documentary on Pegasus I can watch? Cant find any that are on. I just see 2 min trailers from forbidden stories
@cybercdh
@cybercdh 2 жыл бұрын
Not one to watch, but highly recommend episode 99 and 100 of Darknet Diaries podcast. Episode 99 for me was unreal.
@sumo-ninja
@sumo-ninja 2 жыл бұрын
So as someone as interested in a subject as you are to the point of making videos about it I'm pretty surprised that you've missed the point with the Pegasus samples. Pegasus basically is referring to whatever is zero days they're using at the time of the conversation because the whole remote compromise without user interaction is the only unique thing the malware needs after that you can use anything you want to compromise the phone and persist you can literally just use some of the built-in features to have the text and phone calls intercepted and blah blah blah once you install that malware dropper using hide the icon and you can do that one of several ways but again it could be the most basic dumb malware in the world if you wanted it to be after you compromise the phone it's to compromise it's important
@rudielvaston9399
@rudielvaston9399 Жыл бұрын
Great Info mate!
@davidhardy6881
@davidhardy6881 3 жыл бұрын
Very Interesting indeed
@allurbase
@allurbase Жыл бұрын
Great content, thank you!
@bbazzahh
@bbazzahh 3 жыл бұрын
Great video mate.
@MauroScomparin
@MauroScomparin 3 жыл бұрын
Always interesting!
@overlaw66
@overlaw66 3 жыл бұрын
More videos like this please :-)
@TechNobo
@TechNobo 3 жыл бұрын
Very interesting
@firosiam7786
@firosiam7786 3 жыл бұрын
Could you please do a vedio on malware analysis using ghydra for beginers to understand how malware analysis works
@1982masood
@1982masood 3 жыл бұрын
it takes balls to cover such topic.. (you know y i relate i m form india. heheheh)
@kantnklaar
@kantnklaar 3 жыл бұрын
Right on
@1982masood
@1982masood 3 жыл бұрын
Awesome awesome
@watap154
@watap154 3 жыл бұрын
Yeah
@Southized
@Southized 3 жыл бұрын
Im 100% sure i have this on my iphone 8. I get random texts all the time never clicked on one link never anything my phone will be on 100% at 6 am and by 10 oclok it will be at 20% with barely any usage the phone was brand new a year ago
The World’s Most Terrifying Spyware | Investigators
10:20
VICE News
Рет қаралды 1,3 МЛН
IL'HAN - Qalqam | Official Music Video
03:17
Ilhan Ihsanov
Рет қаралды 700 М.
小丑女COCO的审判。#天使 #小丑 #超人不会飞
00:53
超人不会飞
Рет қаралды 16 МЛН
Full Leaked Lyft Software Engineer Interview
50:14
AshesCode
Рет қаралды 887
Is Skynet watching you already?
1:04:00
David Bombal
Рет қаралды 1,1 МЛН
Investigating the truth: Amnesty's Security Lab and the Pegasus project
10:26
Amnesty Switzerland
Рет қаралды 2,2 М.
Discord Malware - "i hacked MYSELF??"
58:21
John Hammond
Рет қаралды 196 М.
Invisible surveillance: How spyware is secretly hacking smartphones
9:31