Head of Global Research & Analysis Team (GReAT) Russia and CIS Unit
Dmitry Galov serves as the Head of Kaspersky's Global Research & Analysis Team (GReAT) Russia and CIS Unit. In this influential role, he leads the team of experts in charge of researching the most sophisticated cases related to APTs and financially motivated attacks. Dmitry embarked on his journey with Kaspersky in September 2015 as an intern and later joined GReAT in August 2018, gradually progressing to become Senior Security Researcher. Before assuming his current position, he spearheaded the crimeware research group, showcasing his leadership capabilities. Dmitry is an expert with a profound understanding of various threats. His extensive research, covering topics such as non-Windows malware, future connected healthcare, cyber-espionage campaigns, and ransomware, has been published on Securelist.com, a testament to his expertise and contributions. Known for his exceptional public speaking skills, Dmitry frequently represents Kaspersky at global and local events, leaving a lasting impact on audiences. Additionally, he actively participates in the creation of webinars and videos that delve into the realm of cybersecurity.Наши эксперты обнаружили новый вариант бэкдора CoolClient с драйвером-руткитом уровня ядра, который скрывает вредоносные процессы, файлы и сетевые соединения от средств защиты и аналитиков.
Эксперты «Лаборатории Касперского» разбирают новую кампанию Armored Likho, маскирующуюся под благотворительность и доставляющую новый Still Toolkit, нацеленный на кражу данных из Telegram и прослушку.
Мы рассказали о миграции APT-группы Awaken Likho на собственные бэкдоры TokenBuoy и TokenBuoySH и разобрали цепочку заражения — от фишингового письма до эксфильтрации данных.
Разбираем Umbrij — новый инструмент APT-группы ToddyCat для компрометации корпоративной переписки в сервисе Gmail. Целью атак стал токен авторизации OAuth, при помощи которого злоумышленники получали доступ к сервисам Google.