<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Mal-Eats</title><link>https://mal-eats.net/en/</link><description>Recent content on Mal-Eats</description><generator>Hugo</generator><language>en</language><lastBuildDate>Tue, 11 May 2021 16:21:06 +0900</lastBuildDate><atom:link href="https://mal-eats.net/en/index.xml" rel="self" type="application/rss+xml"/><item><title>Profile</title><link>https://mal-eats.net/en/profile/</link><pubDate>Tue, 11 May 2021 08:32:10 +0900</pubDate><guid>https://mal-eats.net/en/profile/</guid><description>&lt;p&gt;「Eat Malware/Maliciousness」&lt;/p&gt;&#10;&lt;p&gt;“Mal Eats” (&lt;a href="https://twitter.com/mal_eats"&gt;@mal_eats&lt;/a&gt;) is a Cyber Security Research Team in Japan.&#10;We’ll make articles such as malware analysis and threat intelligence from the perspective of the Blue Team.&lt;/p&gt;&#10;&lt;p&gt;This our research in this blog is based on our personal activities and not the opinion of the company we belong to.&lt;/p&gt;&#10;&lt;h2 id="member"&gt;Member&lt;/h2&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Ryo Tamura&lt;/li&gt;&#10;&lt;li&gt;Shotaro Hamamoto&lt;/li&gt;&#10;&lt;li&gt;Shuhei Sasada&lt;/li&gt;&#10;&lt;li&gt;Takuma Matsumoto&lt;/li&gt;&#10;&lt;li&gt;Yusuke Niwa&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;*alphabetical order&lt;/p&gt;&#10;&lt;h2 id="contact"&gt;Contact&lt;/h2&gt;&#10;&lt;p&gt;Please send a DM to &lt;a href="https://twitter.com/mal_eats"&gt;@mal_eats&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Campo, a New Attack Campaign Targeting Japan</title><link>https://mal-eats.net/en/2021/05/11/campo_new_attack_campaign_targeting_japan/</link><pubDate>Tue, 11 May 2021 08:23:26 +0900</pubDate><guid>https://mal-eats.net/en/2021/05/11/campo_new_attack_campaign_targeting_japan/</guid><description>&lt;p&gt;Since around March 2021, campaigns in Japan using an infrastructure called campo/openfield have been observed. This campaign has the potential to deliver subsequent malware depending on the infected organization, and some cases eventually could result in ransomware incidents overseas.&lt;/p&gt;&#10;&lt;p&gt;We keep tracking this attack campaign, and it started to be observed at least around October 2020 as far as we are aware. We anticipate that attackers will continue to be active in the future, and we are concerned that this could lead to serious impacts including ransomware encryption in the worst case. Therefore, in order to prepare for such threats, we will share in this blog the characteristics of campaigns for Japan and how to check for malware execution traces based on our research.&lt;/p&gt;</description></item></channel></rss>