Shark Stealer & EtherHiding & Captchas: End of year evasion pack

Shark Stealer & EtherHiding & Captchas: End of year evasion pack

Source: YouTube · VMRay · published Dec 16, 2025 · 30:29

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

VMware researchers Arurul and Julian Wolf review 2025's top threat detection trends, highlighting new WTI detections, Yara rules, and a spotlight on the Ether Hiding technique used by Shark Stealer 1:09.

Key Takeaways:
• The team added dozens of new Windows Threat Intelligence detections, config extractors, and hundreds of Yara rules driven by a rapidly shifting threat landscape 1:45.
• New VTIs target direct system calls for EDR evasion, dropped files masquerading as system utilities like MSI exec, and brand-logo overlays on captchas for phishing 1:50.
• Yara rule updates address Cloudflare captchas, fake captchas serving as leading initial access techniques, and malicious VS Code extensions posing supply chain risks 1:50.
• Shark Stealer leverages Ether Hiding to store encrypted C2 data on the BNB blockchain, accessed via a stable Binance testnet API endpoint that offers high-fidelity, low false-positive detection opportunities 1:09.

The session reflects VMware's shift toward sharing campaign-level intelligence alongside detection updates, with the next webinar planned for late January 2026.

Sources:

  • 1:09 Introduction and Ether Hiding spotlight.
  • 1:45 WTI additions and Yara rule overview.
  • 1:50 Details on new VTIs and config extractors.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hello everyone. Let's wait for a minute. Um I still do see people joining. Then we are going to start. All right. Hello everyone um and welcome. Great to have you with us for the December edition of detection and intelligence highlights. I am Arurul, senior PMM here at VMRA and I'm joined by uh my colleague Julian Wolf uh from our labs team. Um he's a threat researcher here and before that he spent years as a hands-on uh practitioner analyst in enterprise environments. That's what I know. So um he has experience from the uh front lines. Hi Julian. >> Hi Andrew. Thanks. >> Amazing. So u it's the end of the year obviously and it's a good moment I think to zoom out for a second. Um so over the course of this year we have added dozens of new uh WTI, new detections, new config extractors and I …