Menu
Sign In Search Podcasts Charts People & Topics Add Podcast API Pricing

Omar Avilez

👤 Person
70 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
135: The D.R. Incident

Basically, I want to see all the computers where Domino's users are local admins.

Darknet Diaries
135: The D.R. Incident

Basically, I want to see all the computers where Domino's users are local admins.

Darknet Diaries
135: The D.R. Incident

This story starts much earlier, you know. Okay, so this is Omar, and he lives in the Dominican Republic, which is an island in the Caribbean Sea.

Darknet Diaries
135: The D.R. Incident

This story starts much earlier, you know. Okay, so this is Omar, and he lives in the Dominican Republic, which is an island in the Caribbean Sea.

Darknet Diaries
135: The D.R. Incident

Let me introduce myself before I start talking about the incidents. So I used to work in the Dominican Republic National Desert, which is the National Cybersecurity Incident Response Team.

Darknet Diaries
135: The D.R. Incident

Let me introduce myself before I start talking about the incidents. So I used to work in the Dominican Republic National Desert, which is the National Cybersecurity Incident Response Team.

Darknet Diaries
135: The D.R. Incident

So when the incident in Costa Rica happens, they contact us. just to ask for help.

Darknet Diaries
135: The D.R. Incident

So when the incident in Costa Rica happens, they contact us. just to ask for help.

Darknet Diaries
135: The D.R. Incident

You know, it was like a massive malware campaign in Costa Rica. They were targeting government organizations through phishing, exploiting vulnerabilities. But they, you know, compromised all the departments separately.

Darknet Diaries
135: The D.R. Incident

You know, it was like a massive malware campaign in Costa Rica. They were targeting government organizations through phishing, exploiting vulnerabilities. But they, you know, compromised all the departments separately.

Darknet Diaries
135: The D.R. Incident

We found an implant. a piece of malware.

Darknet Diaries
135: The D.R. Incident

We found an implant. a piece of malware.

Darknet Diaries
135: The D.R. Incident

But the malware, the implant was on the system from 10 to 11 months ago.

Darknet Diaries
135: The D.R. Incident

But the malware, the implant was on the system from 10 to 11 months ago.

Darknet Diaries
135: The D.R. Incident

It was a malware that did privilege escalation. So it exploded a window of vulnerability that was unknown to the Okay, this just got worse.

Darknet Diaries
135: The D.R. Incident

It was a malware that did privilege escalation. So it exploded a window of vulnerability that was unknown to the Okay, this just got worse.

Darknet Diaries
135: The D.R. Incident

They exploited a vulnerability, an unfortunate firewall. that allowed them to have VPN access to the infrastructure. So with the VPN access, they managed to compromise the entire organization and then try to ransom the organization.

Darknet Diaries
135: The D.R. Incident

They exploited a vulnerability, an unfortunate firewall. that allowed them to have VPN access to the infrastructure. So with the VPN access, they managed to compromise the entire organization and then try to ransom the organization.

Darknet Diaries
135: The D.R. Incident

So... That went very public. So on the investigation, we found out the attacker got into the network via a phishing attack, but that didn't tell us much information. So we concluded the investigation or the report without any attribution. So we just know that somebody compromised the system.

Darknet Diaries
135: The D.R. Incident

So... That went very public. So on the investigation, we found out the attacker got into the network via a phishing attack, but that didn't tell us much information. So we concluded the investigation or the report without any attribution. So we just know that somebody compromised the system.

← Previous Page 1 of 4 Next →