Agenda

Threats adapt, so should defense: Meet Kobalos, a multiplatform malware

Wed Apr 28 / 13:45 - 14:15 CEST
08. Marc-Étienne Léveillé (ESET) - Malware Researecher

Marc-Étienne Léveillé (ESET)

Malware Researecher
09. Romain Wartel (CERN) - Security Officer

Romain Wartel (CERN)

Security Officer

In February 2021, ESET published details about malware used in the compromise of European high-performance computing clusters (HPCs) and servers in academia networks. This very small but well-crafted malware we called Kobalos opens a backdoor on compromised servers. Kobalos demonstrates the capacity of this group to target a wide range of operating systems generally reserved for server applications such as Linux, FreeBSD and Solaris.

The analysis of the malware itself provides quite limited information about the intentions of the group behind it. After ESET researchers realized the targets were high profile, they reached out to the CERN Computer Security Team, who was already aware this malware was active. We have worked together with others who were involved in handling incidents that involved Kobalos. In some case, we faced challenges where the administrators of these systems were ill-equipped to properly handle the incidents.

This presentation will summarize what Kobalos is and how we should raise the bar to defend assets besides endpoints, such as servers.

Romain has been actively trying to protect the academic & research community and "Science For Peace" for more than 15 years.
He works at the European Organization for Nuclear Research, in Geneva, Switzerland.
He has been fighting botnets and bad actors for many years, while protecting the Worldwide LHC Computing Grid. This distributed cyber-infrastructure, supporting CERN’s Large Hadron Collider, spans across hundreds of organizations worldwide. Romain specializes in large-scale security intrusions, affecting multiple organizations and mission critical services. This implies focusing on malware, malicious infrastructures, forensics, threat intelligence, and building international collaborations to prepare for and manage crises.

Marc-Étienne has been a malware researcher at ESET since 2012. He specializes in malware attacking unusual platforms, whether it’s fruity hardware or software from south pole birds . Marc-Étienne focuses his research on the reverse engineering of server-side malware to discover their inner working and operation strategy. His research led to the publication of the Operation Windigo white paper which won Virus Bulletin’s Péter Szőr Award for best research paper in 2014. While still keeping his eyes on crimeware, he also focuses on the analysis of targeted attacks. He has presented at multiple conferences including RSAC, FIRST, 44con, CARO and Linuxcon Europe. Outside cyberspace, Marc-Etienne plays the clarinet and reads comics.