Artwork

Content provided by Proofpoint. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Proofpoint or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Decoding TA4903: Exploring the Dual Objectives of a Unique Cyber Threat Actor

40:57
 
Share
 

Manage episode 410238606 series 3348167
Content provided by Proofpoint. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Proofpoint or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
Today’s focus is on the elusive threat actor known as TA4903. But that's not all - we've got a special treat for you as well. Our longtime producer, Mindy, is joining us as a co-host, bringing her expertise and insights to the table, as we turn the mic around and interview, Selena!
We explore recent research conducted by Selena and her team on TA4903’s distinct objectives. Unlike many cybercrime actors, TA4903 demonstrates a unique combination of tactics, targeting both high-volume credential phishing campaigns and lower-volume direct business email compromises.
We also dive into:
  • TA4903 spoofs government entities like the Department of Transportation and the Department of Labor to lure victims
  • Use of advanced techniques including evil proxy for multi-factor authentication token theft and QR codes for phishing campaigns
  • Rising trends in cryptocurrency-related scams and other financial frauds

Resources mentioned:
MFA Bypass (Blog) by Timothy Kromphardt
IC3 2023 FBI Report
New TA4903 research: https://www.proofpoint.com/us/blog/threat-insight/ta4903-actor-spoofs-us-government-small-businesses-phishing-bec-bids
For more information, check out our website.
  continue reading

54 episodes

Artwork
iconShare
 
Manage episode 410238606 series 3348167
Content provided by Proofpoint. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Proofpoint or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
Today’s focus is on the elusive threat actor known as TA4903. But that's not all - we've got a special treat for you as well. Our longtime producer, Mindy, is joining us as a co-host, bringing her expertise and insights to the table, as we turn the mic around and interview, Selena!
We explore recent research conducted by Selena and her team on TA4903’s distinct objectives. Unlike many cybercrime actors, TA4903 demonstrates a unique combination of tactics, targeting both high-volume credential phishing campaigns and lower-volume direct business email compromises.
We also dive into:
  • TA4903 spoofs government entities like the Department of Transportation and the Department of Labor to lure victims
  • Use of advanced techniques including evil proxy for multi-factor authentication token theft and QR codes for phishing campaigns
  • Rising trends in cryptocurrency-related scams and other financial frauds

Resources mentioned:
MFA Bypass (Blog) by Timothy Kromphardt
IC3 2023 FBI Report
New TA4903 research: https://www.proofpoint.com/us/blog/threat-insight/ta4903-actor-spoofs-us-government-small-businesses-phishing-bec-bids
For more information, check out our website.
  continue reading

54 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide