
Shark Stealer & EtherHiding & Captchas: End of year evasion pack
Source: YouTube · VMRay · published Dec 16, 2025 · 30:29
VMware researchers Arurul and Julian Wolf review 2025's top threat detection trends, highlighting new WTI detections, Yara rules, and a spotlight on the Ether Hiding technique used by Shark Stealer 1:09.
Key Takeaways:
• The team added dozens of new Windows Threat Intelligence detections, config extractors, and hundreds of Yara rules driven by a rapidly shifting threat landscape 1:45.
• New VTIs target direct system calls for EDR evasion, dropped files masquerading as system utilities like MSI exec, and brand-logo overlays on captchas for phishing 1:50.
• Yara rule updates address Cloudflare captchas, fake captchas serving as leading initial access techniques, and malicious VS Code extensions posing supply chain risks 1:50.
• Shark Stealer leverages Ether Hiding to store encrypted C2 data on the BNB blockchain, accessed via a stable Binance testnet API endpoint that offers high-fidelity, low false-positive detection opportunities 1:09.
The session reflects VMware's shift toward sharing campaign-level intelligence alongside detection updates, with the next webinar planned for late January 2026.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Hello everyone. Let's wait for a minute. Um I still do see people joining. Then we are going to start. All right. Hello everyone um and welcome. Great to have you with us for the December edition of detection and intelligence highlights. I am Arurul, senior PMM here at VMRA and I'm joined by uh my colleague Julian Wolf uh from our labs team. Um he's a threat researcher here and before that he spent years as a hands-on uh practitioner analyst in enterprise environments. That's what I know. So um he has experience from the uh front lines. Hi Julian. >> Hi Andrew. Thanks. >> Amazing. So u it's the end of the year obviously and it's a good moment I think to zoom out for a second. Um so over the course of this year we have added dozens of new uh WTI, new detections, new config extractors and I …