Hi folks,
Greetings from a rather bleek autumn day in The Netherlands! I hope you get to read this while drinking a nice cup of warm tea, tonight or tomorrow.
We're a day early, I got some other work lined up for tomorrow (including studying for a re-exam, damned). But first I'm catching up with a friend tonight, and then catching up with a re-run of The Expanse :-)
Enjoy the read!
Some malware uses the browser on the compromised machine to retrieve commands from outside command and control (c2) servers.
However, more organisations are using browser isolation, where the actual browser requests are executed on a remote device, and you only get to see the rendered result (I suppose it's somewhat like an RDP session).
Attackers are now trying to work around this by returning responses from their c2 servers in QR code format, and using a headless browser on the compromised machine to read the rendered output. Nifty.