Ticket Discounts for Cyber Events

GET ALERTS!

Recommended Event: Gartner Security & Risk Management Summit | 22 - 24 Sep 2026

10 New VTIs, 50+ YARA Rules, 4 Config Extractors, and H1 Threat Landscape Report Sneak Preview

Solution Category Security Analytics
Type Webinar
Organization VMRay
Event Format Company Webinar

Webinar Description

Key Takeaways

  • VMRay Labs presents new detection capabilities including ten VMRay Threat Identifiers, four configuration extractors, and over fifty YARA rules
  • Coverage of emerging attack techniques including Web3 dead drops, multi-step redirect chains, and advanced MFA phishing kits
  • Analysis of decentralised malware communication methods and command-and-control resilience mechanisms
  • Relevant for threat researchers, malware analysts, and security operations professionals

Introduction

VMRay’s August technical briefing examines the latest detection innovations developed by VMRay Labs, with threat researcher Julian Wolf presenting new capabilities designed to address evolving attacker methodologies. The session focuses on phishing infrastructure, malware communication techniques, and expanded detection coverage—topics of particular relevance as threat actors increasingly leverage legitimate services to obscure malicious activity and build more resilient attack infrastructure.

Phishing Infrastructure and Evasion Techniques

A significant portion of the briefing addresses how attackers exploit legitimate platforms to conceal malicious infrastructure. Web3 services have emerged as an effective mechanism for threat actors to implement dead drop resolvers, allowing them to dynamically direct victims to malicious destinations while hiding the true infrastructure behind legitimate decentralised services. This technique has become particularly prevalent in ClickFix-style phishing campaigns, where the combination of legitimate service abuse and dynamic resolution complicates traditional detection approaches.

Multi-step redirect chains represent another infrastructure obfuscation method under examination. Threat actors chain multiple legitimate redirector services together, creating complex navigation paths that obscure the final phishing destination. VMRay Labs has developed behavioural heuristics capable of identifying unusually complex redirect sequences that deviate from normal browsing patterns.

Advanced MFA Phishing Kit Detection

The session introduces new meta VMRay Threat Identifiers specifically targeting Sneaky2FA and Tycoon2FA phishing kits. These sophisticated toolkits have gained traction among threat actors seeking to bypass multi-factor authentication protections. Rather than relying on single indicators, the new VTIs correlate multiple behavioural signals—including fake CAPTCHA implementations, challenge-and-response workflows, suspicious infrastructure characteristics, and anti-analysis techniques—to identify these campaigns with greater confidence.

Additional phishing email detections address the psychological manipulation tactics commonly employed in credential harvesting campaigns. New capabilities identify urgency and pressure language, externally hosted branding images designed to impersonate trusted organisations, and popular-brand impersonation techniques that lend apparent legitimacy to malicious messages.

Malware Communication and Resilience Mechanisms

The briefing examines how modern malware families build resilience into their command-and-control infrastructure. Phorpiex serves as a case study for decentralised communication, utilising UDP-based peer-to-peer protocols that eliminate single points of failure and complicate takedown efforts. This architectural approach allows infected systems to maintain connectivity even when individual command-and-control servers are disrupted.

Related detection capabilities address malware that retrieves backup command-and-control configurations, enabling persistent communication when primary infrastructure becomes unavailable. Understanding these fallback mechanisms provides defenders with additional opportunities to identify and disrupt malware operations.

Expanded Detection Coverage

Four new configuration extractors extend analyst visibility into specific malware families and remote access tools. Coverage now includes Phorpiex, NetSupport Manager, ScreenConnect, and ValleyRAT. These extractors automatically parse malware configurations, providing analysts with actionable intelligence about command-and-control infrastructure, operational parameters, and potential indicators of compromise.

More than fifty new YARA rules expand detection across multiple threat categories, including information stealers, botnets, loaders, remote access trojans, backdoors, ransomware, phishing kits, and various evasion techniques. This breadth of coverage reflects the diverse threat landscape that security teams must address.

Who Should Attend

This technical briefing is designed for threat researchers, malware analysts, security operations centre personnel, and detection engineers seeking to understand current attacker methodologies and corresponding detection strategies. The session assumes familiarity with malware analysis concepts and phishing campaign mechanics.