BendyBear: difficult to detect and downloader of malicious payloads. episode artwork

EPISODE · Mar 20, 2021 · 15 MIN

BendyBear: difficult to detect and downloader of malicious payloads.

from Research Saturday · host N2K Networks

Guest Jen Miller-Osborn from Palo Alto Networks' Unit 42 joins us to discuss their research into BendyBear. Highly malleable, highly sophisticated and over 10,000 bytes of machine code. The code behavior and features strongly correlate with that of the WaterBear malware family, which has been active since as early as 2009. The malware is associated with the cyber espionage group BlackTech, which many in the broader threat research community have assessed to have ties to the Chinese government, and is believed to be responsible for recent attacks against several East Asian government organizations. Due to the similarities with WaterBear, and the polymorphic nature of the code, Unit 42 named this novel Chinese shellcode “BendyBear.” It stands in a class of its own in terms of being one of the most sophisticated, well-engineered and difficult-to-detect samples of shellcode employed by an Advanced Persistent Threat (APT). The research can be found here: BendyBear: Novel Chinese Shellcode Linked With Cyber Espionage Group BlackTech

Episode metadata supplied by the publisher feed · Published Mar 20, 2021

Embed this episode

NOW PLAYING

BendyBear: difficult to detect and downloader of malicious payloads.

0:00 15:52

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Research Saturday?

This episode is 15 minutes long.

When was this Research Saturday episode published?

This episode was published on March 20, 2021.

Can I download this Research Saturday episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!