Digital Forensics and Incident Response Specialist
Ahmad Zaidi Said, a Malaysian cybersecurity expert with broad international experience, has more than 14 years of knowledge and experience in the field and has been involved in high-profile cybersecurity incident investigations globally. Joined Kaspersky Global Emergency Response Team (GERT) in 2021 as Digital Forensics and Incident Response (DFIR) specialist, Zaidi brings valuable experience in a variety of cyber security domains, including digital forensics and incident response (DFIR), malware analysis and reverse engineering, threat intelligence, and threat hunting Zaidi is a committee member of the Malaysia Cyber Security Community Organization (MCCO) & rawSEC and active member of the High Technology Cyber Investigation Association (HTCIA), which contribute to the evolution of the cybersecurity ecosystem through information sharing and collaboration. His expertise has also led him to speak at a number of international and local events, in which he has offered vital insights and best practises with a wide range of audiences.Наши эксперты обнаружили новый вариант бэкдора CoolClient с драйвером-руткитом уровня ядра, который скрывает вредоносные процессы, файлы и сетевые соединения от средств защиты и аналитиков.
Эксперты «Лаборатории Касперского» разбирают новую кампанию Armored Likho, маскирующуюся под благотворительность и доставляющую новый Still Toolkit, нацеленный на кражу данных из Telegram и прослушку.
Мы рассказали о миграции APT-группы Awaken Likho на собственные бэкдоры TokenBuoy и TokenBuoySH и разобрали цепочку заражения — от фишингового письма до эксфильтрации данных.
Разбираем Umbrij — новый инструмент APT-группы ToddyCat для компрометации корпоративной переписки в сервисе Gmail. Целью атак стал токен авторизации OAuth, при помощи которого злоумышленники получали доступ к сервисам Google.