1 min read
Cyber twins investigate how threat actors hurt skilled software developers and why is it essential for software vendors to be trusted by their users

Copyright 2023, IT Voice Media Pvt. Ltd.
All Rights Reserved

In 2017, news from CCleaner and NetSarang supply chain attacks made global headlines. This caught the attention of cybersecurity twins, Noushin Shabab and Negar Shabab to dive deeper and uncover details around the compromised software development environment.
The younger twin Noushin who is a Senior Security Researcher for Kaspersky ANZ, did a further investigation in two well-known supply chain attacks–ShadowPad targeting server management software and ShadowHammer infecting the gaming industry. Both cases displayed compromised linker modules inside the software development environments deployed by attackers. The final payloads towards end user victims were also hidden on the developers systems in one of these two forms; a separate source code file or a malicious software library. With the help of the trojanised linker, malicious code was instantly linked with the original source code and this resulted in trojanised software programs impacting large number of user victims.