In brief

A walk-through of the attack chain of the APT group Librarian Likho, following Kaspersky's recent report "Notes of a Digital Auditor". The whole attack is spear phishing, batch files and legitimate utilities, without a single binary implant: primitive, but it works, because people still run.pdf.exe. The value for a SOC is artifacts to hunt for: C:\Intel, nighttime scheduler tasks, AnyDesk under the name svchost, a dump of SAM/SYSTEM. A technical talk, but at the same time a showcase for the report and for Kaspersky's products.

Key points

Tools, artifacts, technologies

The report is devoted to Ukrainian groups operating against Russia; the group is described as state-sponsored, the evidence of its origin is circumstantial. Telemetry is limited by "regulators' requirements" and "all the GDPR stuff", the victim is not attributed — the mechanism is in the KSN agreement; publication follows the protocol "report → article → conferences", with a check that every implant is detected. Kaspersky is "not a government agency, we're a commercial company" and does not investigate incidents: "we're about Defensive, we're not about Offensive". The articles "272, 273, 274" are named without the words "Criminal Code".

Questions from the audience

The names of those asking were not spoken; the audience spoke without a microphone.

The speaker's position

A sarcastic, conversational lecture with asides addressed to the group's operators, who "will watch the stream or the recording either way". For him the blame lies first of all with the user who has no security awareness, and then with the SOC. He rates the attackers low, but admits that the primitive stuff works, and names the limits himself: he does not know what runtime.cab and the persistence are for, and the Mail.ru phishing he assumes "with medium confidence".

Quotes