Lessons learned: with a dynamic and reactive opponent with development resources and ops staff, a focus onstatic IOCs is an ancient philosophy stuck in the last decade. An attentive opponent will fix them before you can deploy detection.
The fact that Dragos has not done so, and has not provided any evidence that would qualify as a smoking gun, hypothetically *could* be a sign of an unimaginably, incomprehensibly advanced series of implants and an active attacker... but occam's razor says he's just seeing things.
-
-
At the end of the day, you turn the thing off, dump the Flash memory, and either the malware is there or it isn't. Yes, it can get more complicated than that... but the basic premise holds.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.