
CyberWire Daily
Caught in the funnel. [Research Saturday]
January 24 · 23 min · Season 10 · Episode 409Bonus
0:00-23:33
Streams straight from the publisher. podnod never proxies or re-hosts episode audio.
Today we have Andrew Northern, Principal Security Researcher at Censys, discussing "From Evasion to Evidence: Exploiting the Funneling Behavior of Injects". This research explains how modern web malware campaigns use multi-stage JavaScript injections, redirects, and fake CAPTCHAs to selectively deliver payloads and evade detection.
It shows that these attack chains rely on stable redirect and traffic-distribution chokepoints that can be monitored at scale. Using the SmartApe campaign as a case study, the report demonstrates how defenders can turn those chokepoints into high-confidence detection and tracking opportunities.
The research can be found here:
Andrew Northern
linkedin.comCensys
linkedin.com