New Config Extractors, a 4-VTI Phishkit Behavior Detection Set, and 30+ New YARA Rules

New Config Extractors, a 4-VTI Phishkit Behavior Detection Set, and 30+ New YARA Rules

Source: YouTube · VMRay · published Jun 30, 2026 · 35:41

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

VMRay's June detection highlights webinar showcases new behavioral threat identifiers (VTIs), config extractors, and Yara rules designed to counter evolving attacker techniques like living-off-the-land abuse and sophisticated phishing kits 3:19-3:52.

Key Takeaways:
• An updated VTI improves the identification of suspicious Office controls (like ActiveX and OLE objects) associated with known vulnerabilities, providing faster triage 5:33-8:03.
• A new defense evasion VTI detects malware, such as Squid Loader, attempting to bypass Windows Defender's emulator using the undocumented NtIsProcessInJob API call 8:12-10:58.
• A novel VTI identifies "ENV Loader," a technique that evades static detection by splitting malicious PowerShell commands across numerous environment variables before dynamically reconstructing them at runtime 11:04-13:06.
• Three new low-scoring VTIs work together to reliably detect Evil Proxy phishing pages by identifying embedded Microsoft password reset dialogs, line-broken login text, and suspicious connections to Microsoft authentication services 16:00-20:00.
• New configuration extractors were added for RHClient 2 (Setop Red) and the long-standing Ghost RAT malware families to extract high-quality IOCs 20:06-21:09.

These continuous updates ensure defenders can identify threats earlier and with greater confidence, even when attackers heavily obfuscate their payloads 33:20-33:32.

Sources:

  • 3:19-3:52 Introduction to June detection updates
  • 5:33-8:03 Suspicious Office controls and CVE association
  • 8:12-10:58 Windows Defender emulator evasion via Squid Loader
  • 11:04-13:06 ENV Loader PowerShell execution from environment variables
  • 16:00-20:00 Evil Proxy phishing kit behavioral detection set
  • 20:06-21:09 RHClient 2 and Ghost RAT config extractors

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hello everyone. I see some folks have joined us already. We're just going to hang out here for another two or three minutes, wait for others to join, and we'll go ahead and get started. Thanks for joining us today. Thanks everyone who's jumped on. We're just going to give it another minute or two and we'll go ahead and get started. Thanks for joining us today. All right, we're going to give it one more minute. We'll go ahead and get started. Thanks everyone who's joined us so far. All right, we are at the top of the hour, so let's go ahead and get started. Thanks everyone for joining us today and welcome to our June detection highlights webinar. We're going to be covering the latest detection innovations from VMray Labs. As hackers continue to evolve their techniques from abusing legitimat…