VB Blog

VB2021 localhost call for papers: a great opportunity

Posted by   Virus Bulletin on   Mar 17, 2021

VB2021 localhost presents an exciting opportunity to share your research with an even wider cross section of the IT security community around the world than usual, without having to take time out of your work schedule (or budget) to travel.

Read more  

New article: Excel Formula/Macro in .xlsb?

Posted by   Virus Bulletin on   Mar 2, 2021

In a follow-up to an article published last week, Kurt Natvig takes us through the analysis of a new malicious sample using the .xlsb file format.

Read more  

New article: Decompiling Excel Formula (XF) 4.0 malware

Posted by   Virus Bulletin on   Feb 23, 2021

In a new article, researcher Kurt Natvig takes a close look at XF 4.0 malware.

Read more  

The Bagsu banker case - presentation

Posted by   Virus Bulletin on   Jan 29, 2021

At VB2019, CSIS researcher Benoît Ancel spoke about a quiet banking trojan actor that has been targeting German users since at least 2014.

Read more  

VB2021 call for papers - now open, to all!

Posted by   Virus Bulletin on   Jan 19, 2021

The call for papers for VB2021 is now open and we want to hear from you - we're planning for flexible presentation formats, so everyone is encouraged to submit, regardless of whether or not you know at this stage whether you'll be able to travel to Prague!

Read more  

In memoriam: Yonathan Klijnsma

Posted by   Virus Bulletin on   Jan 11, 2021

We were very sorry to learn of the passing of researcher Yonathan Klijnsma last week. Here, former VB Editor Martijn Grooten shares his memories of a talented researcher and a very kind person: this month, infosec lost a really good one.

Read more  

VB2020 localhost videos available on YouTube

Posted by   Virus Bulletin on   Jan 8, 2021

VB has made all VB2020 localhost presentations available on the VB YouTube channel, so you can now watch - and share - any part of the conference freely and without registration.

Read more  

VB2020 presentation & paper: 2030: backcasting the potential rise and fall of cyber threat intelligence

Posted by   Virus Bulletin on   Dec 8, 2020

At VB2020 localhost, threat intelligence consultant Jamie Collier used the analytical technique of backcasting to look at the rise and fall of the cyber threat intelligence industry.

Read more  

VB2020 presentation: Behind the Black Mirror: simulating attacks with mock C2 servers

Posted by   Virus Bulletin on   Dec 4, 2020

At VB2020 localhost, Carbon Black's Scott Knight presented an approach he and his colleagues have taken to more realistically simulate malware attacks.

Read more  

VB2020 presentation & paper: Advanced Pasta Threat: mapping threat actor usage of open-source offensive security tools

Posted by   Virus Bulletin on   Dec 2, 2020

At VB2020, researcher Paul Litvak revealed how he put together a comprehensive map of threat actor use of open-source offensive security tools.

Read more  

Search blog

Throwback Thursday: KAOS on the Superhighway?

This Throwback Thursday, we turn the clock back to 1994, when KAOS4 was discovered on the Internet.
This Throwback Thursday, we turn the clock back to 1994, when KAOS4 was discovered on the Internet. A new virus has been found on the Internet — today, this is an unfortunate fact… https://www.virusbulletin.com/blog/2015/06/throwback-thursday-kaos-superhighway/

Paper: Using .NET GUIDs to help hunt for malware

Tool to extract identifiers incorporated into VirusTotal.
Tool to extract identifiers incorporated into VirusTotal. The large number of new malware samples found each day hasn't made malware analysis an easier task, and researchers could… https://www.virusbulletin.com/blog/2015/06/paper-using-net-guids-help-hunt-malware/

Steganoprague: a VB2015 competition & puzzle

Use your obfuscation and deobfuscation skills to win a prize during the VB2015 conference!
Use your obfuscation and deobfuscation skills to win a prize during the VB2015 conference! "It is time for defenders to go on the offence," wrote Andreas Lindh in Virus Bulletin… https://www.virusbulletin.com/blog/2015/06/steganoprague-competition-amp-puzzle/

NSA, GCHQ found to target anti-virus products

Agencies looked for vulnerabilities to exploit and for submitted malware samples.
Agencies looked for vulnerabilities to exploit and for submitted malware samples. New documents from NSA whistle-blower Edward Snowden have revealed the agency and its British… https://www.virusbulletin.com/blog/2015/06/nsa-gchq-found-target-anti-virus-products/

Paper: Beta exploit pack: one more piece of crimeware for the infection road!

Exploit kit currently being tested focuses primarily on Flash Player exploits.
Exploit kit currently being tested focuses primarily on Flash Player exploits. Nuclear, Angler, Magnitude and Rig. Security researchers know we're talking about exploit kits (or… https://www.virusbulletin.com/blog/2015/06/paper-beta-exploit-pack-one-more-piece-crimeware-infection-road/

Throwback Thursday: Macro Viruses & The Little Virus That Could...

This Throwback Thursday, we turn the clock back to 1999, when Melissa was causing havoc across the globe and VB presented a series of articles detailing all you ever wanted to know about macro viruses but were afraid to ask.
This Throwback Thursday, we turn the clock back to 1999, when Melissa was causing havoc across the globe and VB presented a series of articles detailing all you ever wanted to know… https://www.virusbulletin.com/blog/2015/06/throwback-thursday-macro-viruses-amp-little-virus-could/

Virus Bulletin announces 'Small Talks' for VB2015

Smaller, more informal format ideal for discussion and debate.
Smaller, more informal format ideal for discussion and debate. When, a few months ago, we announced the programme for VB2015, we promised 'a number of added extras'. We have… https://www.virusbulletin.com/blog/2015/06/announces-small-talks/

Throwback Thursday: Virus Writers

This Throwback Thursday, we bring you a series of articles from the archives that looked at virus writers, asking 'who are they?', 'why do they do it?', and other pertinent questions.
This Throwback Thursday, we bring you a series of articles from the archives that looked at virus writers, asking 'who are they?', 'why do they do it?', and other pertinent… https://www.virusbulletin.com/blog/2015/06/throwback-thursday-virus-writers/

Vawtrak uses Tor2Web to connect to Tor hidden C&C servers

Option hides the servers, without having to include a Tor client in the malware.
Option hides the servers, without having to include a Tor client in the malware. The authors of the Vawtrak trojan (also known as Neverquest) have moved some of its C&C servers to… https://www.virusbulletin.com/blog/2015/06/vawtrak-uses-tor2web-connect-tor-hidden-c-amp-c-servers/

Duqu 2.0 found to target security company

Advanced malware also targeted venues linked to Iranian nuclear negotiations.
Advanced malware also targeted venues linked to Iranian nuclear negotiations. There are some security stories you couldn't make up. The authors of an advanced malware tool have… https://www.virusbulletin.com/blog/2015/06/duqu-2-0-found-target-security-company/

June

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2015/06/

London calling!

Infosecurity Europe, BSides London and the Security Bloggers Meetup.
Infosecurity Europe, BSides London and the Security Bloggers Meetup. June is the new April, at least for the security industry, as its traditional get-together in London… https://www.virusbulletin.com/blog/2015/05/london-calling/

Paper: On the beat

Kevin Williams looks back at UK law enforcement successes at combating cybercrime.
Kevin Williams looks back at UK law enforcement successes at combating cybercrime. In a recent Throwback Thursday article, we looked back at the sentencing of self-confessed virus… https://www.virusbulletin.com/blog/2015/05/paper-beat/

Throwback Thursday: Research and Other Hobbies

This Throwback Thursday we reflect on the life of one of industry's greats, who sadly passed away this week: Prof. Klaus Brunnstein.
This Throwback Thursday we reflect on the life of one of industry's greats, who sadly passed away this week: Prof. Klaus Brunnstein. Professor Klaus Brunnstein was one of the… https://www.virusbulletin.com/blog/2015/05/throwback-thursday-research-and-other-hobbies/

Weak keys and prime reuse make Diffie-Hellman implementations vulnerable

'Logjam' attack possibly used by the NSA to decrypt VPN traffic.
'Logjam' attack possibly used by the NSA to decrypt VPN traffic. A group of researchers have discovered a number of vulnerabilities in the way the Diffie-Hellman key exchange… https://www.virusbulletin.com/blog/2015/05/weak-keys-and-prime-reuse-make-diffie-hellman-implementations-vulnerable/

Virus Bulletin announces student tickets for VB2015

87% discount for students and the option to give a lightning talk.
87% discount for students and the option to give a lightning talk. A few weeks ago, we opened registration for VB2015, which will take place in Prague from 30 September to 2… https://www.virusbulletin.com/blog/2015/05/announces-student-tickets/

Throwback Thursday: Double Trouble / The Perfect Couple

Once again this Throwback Thursday, we bring you not one but two (related) pieces from the archives as VB heads back to the mid-90s when a new era of viruses was believed to be dawning.
Once again this Throwback Thursday, we bring you not one but two (related) pieces from the archives as VB heads back to the mid-90s when a new era of viruses was believed to be… https://www.virusbulletin.com/blog/2015/05/throwback-thursday-double-trouble-perfect-couple/

Book review: The Florentine Deception, by Carey Nachenberg

John Hawes reviews Carey Nachenberg's debut novel.
John Hawes reviews Carey Nachenberg's debut novel. There's a rather serious problem with fiction involving computers, and computer security in particular. It seems like any time a… https://www.virusbulletin.com/blog/2015/05/book-review-florentine-deception-carey-nachenberg/

Book review: Data and Goliath, by Bruce Schneier

Paul Baccas reviews Data and Goliath 'The Hidden Battles to Collect You Data and Control Your World', by Bruce Schneier.
Paul Baccas reviews Data and Goliath 'The Hidden Battles to Collect You Data and Control Your World', by Bruce Schneier. This book has been difficult to review. It has proved… https://www.virusbulletin.com/blog/2015/05/book-review-data-and-goliath-bruce-schneier/

Throwback Thursday: When Love came to Town

Once again this Throwback Thursday, we bring you not one but two (related) pieces from the archives as VB heads back to 2000 in the week of the 15th anniversary of the LoveLetter virus.
Once again this Throwback Thursday, we bring you not one but two (related) pieces from the archives as VB heads back to 2000 in the week of the 15th anniversary of the LoveLetter… https://www.virusbulletin.com/blog/2015/05/throwback-thursday-when-love-came-town/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.