<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Malware Archives - Burgess Forensics</title>
	<atom:link href="https://burgessforensics.com/category/malware/feed/" rel="self" type="application/rss+xml" />
	<link>https://burgessforensics.com/category/malware/</link>
	<description>Computer Forensics, Electronic Discovery &#38; Expert Witness</description>
	<lastBuildDate>Wed, 05 Aug 2026 03:33:31 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://burgessforensics.com/wp-content/uploads/2016/08/burgess-42x42.png</url>
	<title>Malware Archives - Burgess Forensics</title>
	<link>https://burgessforensics.com/category/malware/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>The Metadata You Didn&#8217;t Know You Were Sending</title>
		<link>https://burgessforensics.com/the-metadata-you-didnt-know-you-were-sending/</link>
					<comments>https://burgessforensics.com/the-metadata-you-didnt-know-you-were-sending/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Tue, 04 Aug 2026 21:10:04 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cyber Investigations]]></category>
		<category><![CDATA[Expert Witness Insights]]></category>
		<category><![CDATA[Forensic stories]]></category>
		<category><![CDATA[Litigation Support]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Technology & Law]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=16161</guid>

					<description><![CDATA[<p>You thought you sent a one-page letter. What you actually sent was a one-page letter and a small pile of paperwork the letter filled out about itself when you weren&#8217;t looking. That paperwork is metadata — data about data. And it travels with your files whether or not you invited it along for the trip. [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/the-metadata-you-didnt-know-you-were-sending/">The Metadata You Didn&#8217;t Know You Were Sending</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='The Metadata You Didn&#039;t Know You Were Sending' data-link='https://burgessforensics.com/the-metadata-you-didnt-know-you-were-sending/' data-app-id-name='category_above_content'></div><p>You thought you sent a one-page letter. What you actually sent was a one-page letter and a small pile of paperwork the letter filled out about itself when you weren&#8217;t looking.</p>
<p>That paperwork is metadata — data about data. And it travels with your files whether or not you invited it along for the trip.</p>
<p style="text-align: left;">Metadata is the stuff a document quietly jots down while you&#8217;re jotting down words. There’s a lot of potential information there: Who created it, when, and on what computer.<a href="https://burgessforensics.com/wp-content/uploads/2026/08/stowaway.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16166 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/stowaway-300x225.jpg" alt="" width="300" height="225" /></a> Who edited it, and when they last saved it. Where a photo was taken, down to the GPS coordinates. What camera, what settings, what software. None of it shows up on the page. All of it comes along, like a stowaway.</p>
<p>Most of the time this is harmless, but occasionally, it&#8217;s the whole story.</p>
<h4>A photo is a very talkative little file.</h4>
<p>Take a picture with your phone and you&#8217;ve created a small autobiography. The image, surely, but tucked inside is a section called EXIF data: the make and model of the phone, the date and time down to the second, and, if location services were on, the exact spot on Earth where you stood. Share that photo in its original form and you may be handing over your home address without meaning to.</p>
<p>The good news: most social platforms started stripping this out a few years ago when there was a public hue and cry about it. The bad news: &#8220;most&#8221; is not &#8220;all,&#8221; and emailing the original file, or dropping it in a shared folder, sends the whole talkative package along.</p>
<h4>Documents keep a diary too</h4>
<p>A Word document remembers more than the final draft. Depending on your settings, it can carry the author&#8217;s name, the company the software was registered to, how long the file was open, and sometimes, a list of former edits and tracked changes and comments you thought you&#8217;d removed. Every &#8220;on second thought, delete that paragraph&#8221; can live on in the file&#8217;s memory.</p>
<p><img loading="lazy" decoding="async" class="size-medium wp-image-16162 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/08/genrating-metadata-300x225.jpg" alt="" width="300" height="225" />The Internet is dotted with cautionary tales of press releases and legal filings that were sent out with the edits still readable underneath. The same is true with newsworthy congressional hearings. Most of us are not popular enough to warrant interest from the government. Still, the words on the page said one thing but the metadata said &#8220;here&#8217;s what we almost admitted.&#8221; Oopsie.</p>
<p>&nbsp;</p>
<h4>So, what to do?</h4>
<p>There&#8217;s no need to get paranoid about this. Depending on what you’re shopping for, your grocery list is not a national secret. But a few practical habits go a long way:</p>
<ul>
<li><strong>Before sending anything sensitive, look under the hood.</strong> In Word on Windows, &#8220;Inspect Document&#8221; should find and remove hidden data, comments, and tracked changes. Do it on the final version, not the draft.</li>
<li><strong>Turn off location tagging for your camera</strong> if you don&#8217;t need it — or scrub EXIF data from photos before sharing the originals. By the way, if litigation is foreseen that involves these photos, don’t scrub the EXIF metadata. It will be considered spoliation of data and will go poorly for you if and when it goes to court.</li>
<li><strong>Remember that &#8220;delete&#8221; inside a file often just means &#8220;hide.&#8221;</strong> Removing a comment from view is not always the same as removing it from the file.</li>
</ul>
<p>None of this requires becoming a hermit. It&#8217;s the digital equivalent of checking your pockets before you send the coat to the cleaners.</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/08/hermit.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16163 aligncenter" src="https://burgessforensics.com/wp-content/uploads/2026/08/hermit-300x225.jpg" alt="" width="300" height="225" /></a></p>
<p>Metadata isn&#8217;t sinister. It&#8217;s just honest — sometimes more honest than we&#8217;d like. The trick is knowing it&#8217;s there, so you decide what to share instead of the file deciding for you.</p>
<p><em>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1984.</em></p>
<p><em><strong>Don’t miss a single issue of our informative newsletter … </strong></em><a href="https://burgessforensics.com/subscribe/"><em><strong>Subscribe now</strong></em></a><em><strong>!</strong></em></p>
<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='The Metadata You Didn&#039;t Know You Were Sending' data-link='https://burgessforensics.com/the-metadata-you-didnt-know-you-were-sending/' data-app-id-name='category_below_content'></div><div style='display:none;' class='shareaholic-canvas' data-app='recommendations' data-title='The Metadata You Didn&#039;t Know You Were Sending' data-link='https://burgessforensics.com/the-metadata-you-didnt-know-you-were-sending/' data-app-id-name='category_below_content'></div><p>The post <a href="https://burgessforensics.com/the-metadata-you-didnt-know-you-were-sending/">The Metadata You Didn&#8217;t Know You Were Sending</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/the-metadata-you-didnt-know-you-were-sending/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Cyberwar History and Ukraine</title>
		<link>https://burgessforensics.com/cyberwar-history-and-ukraine/</link>
					<comments>https://burgessforensics.com/cyberwar-history-and-ukraine/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Mon, 04 Apr 2022 23:19:40 +0000</pubDate>
				<category><![CDATA[Cyberwar]]></category>
		<category><![CDATA[Malware]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=12832</guid>

					<description><![CDATA[<p>Cyberwar History and Ukraine People are much more drawn to images of blown-up building, fires, mushroom clouds, refugees in dire circumstances, color pictures of pain that are better in black and white than they are to explanations of code or even fallout from code if it’s not resulting in something blown-up, fiery, or pictures of [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/cyberwar-history-and-ukraine/">Cyberwar History and Ukraine</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='Cyberwar History and Ukraine' data-link='https://burgessforensics.com/cyberwar-history-and-ukraine/' data-app-id-name='category_above_content'></div><p><strong>Cyberwar History and Ukraine </strong></p>
<p>People are much more drawn to images of blown-up building, fires, mushroom clouds, refugees in dire circumstances, color pictures of pain that are better in black and white than they are to explanations of code or even fallout from code if it’s not resulting in something blown-up, fiery, or pictures of people in pain that are better in black and white.</p>
<p>That is to say, while we see plenty of stories of ransomware, temporary business disruptions, and credit card &amp; ID fraud, it’s not visceral. It goes by quickly on the page and in our minds.</p>
<p>So, whatever happened to the stories we saw before the cyberattack age? When the US Cybercommand was <a href="https://burgessforensics.com/wp-content/uploads/2022/04/440px-Seal_of_the_United_States_Cyber_Command.svg_.png"><img loading="lazy" decoding="async" class="wp-image-12835 alignleft" src="https://burgessforensics.com/wp-content/uploads/2022/04/440px-Seal_of_the_United_States_Cyber_Command.svg_-300x300.png" alt="" width="160" height="160" srcset="https://burgessforensics.com/wp-content/uploads/2022/04/440px-Seal_of_the_United_States_Cyber_Command.svg_-300x300.png 300w, https://burgessforensics.com/wp-content/uploads/2022/04/440px-Seal_of_the_United_States_Cyber_Command.svg_-150x150.png 150w, https://burgessforensics.com/wp-content/uploads/2022/04/440px-Seal_of_the_United_States_Cyber_Command.svg_-146x146.png 146w, https://burgessforensics.com/wp-content/uploads/2022/04/440px-Seal_of_the_United_States_Cyber_Command.svg_-50x50.png 50w, https://burgessforensics.com/wp-content/uploads/2022/04/440px-Seal_of_the_United_States_Cyber_Command.svg_-380x380.png 380w, https://burgessforensics.com/wp-content/uploads/2022/04/440px-Seal_of_the_United_States_Cyber_Command.svg_-90x90.png 90w, https://burgessforensics.com/wp-content/uploads/2022/04/440px-Seal_of_the_United_States_Cyber_Command.svg_-80x80.png 80w, https://burgessforensics.com/wp-content/uploads/2022/04/440px-Seal_of_the_United_States_Cyber_Command.svg_.png 440w, https://burgessforensics.com/wp-content/uploads/2022/04/440px-Seal_of_the_United_States_Cyber_Command.svg_-42x42.png 42w, https://burgessforensics.com/wp-content/uploads/2022/04/440px-Seal_of_the_United_States_Cyber_Command.svg_-130x130.png 130w, https://burgessforensics.com/wp-content/uploads/2022/04/440px-Seal_of_the_United_States_Cyber_Command.svg_-100x100.png 100w" sizes="(max-width: 160px) 100vw, 160px" /></a>just a twinkle in some geeky eyes? What happened to the discussion that cyberattacks would engender kinetic responses? Bombs not electrons.</p>
<p>Perhaps it was a sense of proportion. Perhaps it was a recognition that we consider that an increasing cyberwar, if responded to with bullets, might just result in use seeing those images of things that would be better in black and white on our own doorstep?</p>
<p>Did we back off, or did sanity take hold in the minds of the planners?</p>
<p>Let’s look at a little history.</p>
<p>Back in 2003, a cyberattack originating from China &#8211; and christened, “Titan Rain,” by the US &#8211; managed to get access to loads of sensitive government information by compromising the systems of US government contractors and of government systems themselves. Only unclassified information was stolen, but the world woke up to this kind of attack.</p>
<p>In 2004, the Joint Chiefs of Staff declared cyberspace an important domain of conflict alongside the air, land, sea, and space domains. No doubt, this was prompted by the reality of Titan Rain. As a culture, we were just starting to think about these things on a national level.</p>
<p>In 2007, Estonia experienced a broad cyberattack that included their parliament, banks, and media. It was believed to have originated from Russia, or from Russian actors. NATO’s response was to create the NATO Cooperative Cyber Defence Center of Excellence (CCDCOE) in 2007. Now, continents were beginning to wake to the threat and the need to do something about it.</p>
<p><strong>The Tailinn Manual</strong></p>
<p>The CCDCOE began to develop an extensive study and code about what how international law applies to cyber conflicts and cyberwarfare; these previous acts were beginning to be recognized as acts of war. Calling on legal scholars and legal practitioners that were experienced in cyber issues, the CCDCOE produced Tailinn Manual on the International Law Applicable to Cyber Warfare in 2012.<a href="https://burgessforensics.com/wp-content/uploads/2022/04/Tallinn-Manual.png"><img loading="lazy" decoding="async" class="wp-image-12840 alignright" src="https://burgessforensics.com/wp-content/uploads/2022/04/Tallinn-Manual-300x152.png" alt="Tailinn Manual image" width="229" height="116" srcset="https://burgessforensics.com/wp-content/uploads/2022/04/Tallinn-Manual-300x152.png 300w, https://burgessforensics.com/wp-content/uploads/2022/04/Tallinn-Manual-260x132.png 260w, https://burgessforensics.com/wp-content/uploads/2022/04/Tallinn-Manual-50x25.png 50w, https://burgessforensics.com/wp-content/uploads/2022/04/Tallinn-Manual-155x80.png 155w, https://burgessforensics.com/wp-content/uploads/2022/04/Tallinn-Manual-130x66.png 130w, https://burgessforensics.com/wp-content/uploads/2022/04/Tallinn-Manual.png 600w" sizes="(max-width: 229px) 100vw, 229px" /></a></p>
<p>The Tailinn Manual declared that killing hackers in response to certain cyberattacks was justifiable.</p>
<p>Killing hackers?!</p>
<p>Meanwhile, other state-sponsored cyberattacks marched their way into the public consciousness.</p>
<p>The Stuxnet Worm was developed to sabotage Iran’s nuclear development efforts – in particular, the centrifuges used to enrich uranium gas. It is believed to be the first malware designed to and succeeding in visiting physical destruction on physical equipment. Wired Magazine called it the first digital weapon.</p>
<p>It&#8217;s widely considered that the US and Israel collaborated over a period of 5 years to develop this malware.</p>
<p>In 2009, Secretary of Defense, Robert Gates, recognizing how important AND vulnerable important computers and networks were (are), directed the creation of USCYBERCOM. It is the unified command for the cyberspace domain in the US and the world.</p>
<p>In 2016, the organization described the 2016 espionage ops against the Democratic National Committee while in the midst of a national election “serious business . . . [that] may destroy democracy.”</p>
<p>Administration officials at the time considered that cyber weapons were so potentially destructive that they should be unleashed only on the direct orders of the Commander in Chief, like nuclear weapons. I do not know if there is an equivalent “Cyber Football.” Would it have red and blue buttons?</p>
<p>Article 51 of the UN Charter allows individual countries to defend themselves and to band together to defend each other. It also allows the same if an armed attack is anticipated and recognizes the right to use force in such a situation. It allows a cyberattack to be considered an armed attack.</p>
<p>In 2019, Israel did just this, by conducing airstrikes on a building that they said had Hamas members inside that were planning to launch a cyberattack on Israel. Before they launched the anticipated cyberattack. If they were indeed going to do so.</p>
<p>In 2021 the topic was up for noticeable public discussion again. NATO heads of state and government met at NATO’s North Atlantic Council meeting in Brussels and issued a communiqué that ultimately equates cyberattacks with kinetic attacks and leaves the possibility of military action against hackers on the table.<br />
Still, what we generally see is that cyberattacks &#8211; or anticipated cyberattacks &#8211; by states are dealt with by preemptive and after-the-fact punishing cyberattacks. Tit for tat, as it were, and even before the tat.</p>
<p><strong>Cyberwar in Action</strong></p>
<p>What we have seen in practice in Georgia in 2008, Crimea in 2014, and in Ukraine in 2021 is the “softening up” cyberattack. The attack used to diminish and disable defensive and civil systems before a kinetic attack, rather than a kinetic attack in response to a cyberattack.</p>
<p>Many said that the 2014-2015 cyberattacks were on a an entirely different – and grander – level than had been seen previously. Several Ukrainian banks and government agencies became inaccessible and malware – using a tool called “HermeticWiper” &#8211; was wiping data from hundreds of PCs and servers.</p>
<p>But we’ve gotten used to common DDOS attacks, data-wiping and ransomware in recent years on the civilian level. It’s kind of taken for granted that these things are ongoing and all over.</p>
<p>The use of cyberwar and kinetic war together has been labeled “hybrid warfare.”</p>
<p>And yet, the world seems surprised that Russian cyberattacks on Ukraine in 2021 and 2022 have been substantially less severe than anticipated. To be sure, they were and are ongoingly widespread. Hackers caused the Viasat satellites to become inoperative. But that may have affected Russian soldiers and commanders to lose connectivity as well. And said attack has been mitigated somewhat by the Musk’s activation of Starlink Internet satellites over Ukraine.</p>
<p>Additionally, Ukrainian modems were zombie-fied by Russian malware, being used as nodes for targeted DDOD attacks within Ukraine.</p>
<p>But the ruination from malware that was expected has not really seemed to occur. We haven&#8217;t seen a cyber-Armageddon. Were they more pr<a href="https://burgessforensics.com/wp-content/uploads/2022/04/Russia-and-Ukraine-flags.jpg"><img loading="lazy" decoding="async" class="wp-image-12839 alignleft" src="https://burgessforensics.com/wp-content/uploads/2022/04/Russia-and-Ukraine-flags-300x169.jpg" alt="" width="240" height="135" srcset="https://burgessforensics.com/wp-content/uploads/2022/04/Russia-and-Ukraine-flags-300x169.jpg 300w, https://burgessforensics.com/wp-content/uploads/2022/04/Russia-and-Ukraine-flags-768x432.jpg 768w, https://burgessforensics.com/wp-content/uploads/2022/04/Russia-and-Ukraine-flags-260x146.jpg 260w, https://burgessforensics.com/wp-content/uploads/2022/04/Russia-and-Ukraine-flags-50x28.jpg 50w, https://burgessforensics.com/wp-content/uploads/2022/04/Russia-and-Ukraine-flags-142x80.jpg 142w, https://burgessforensics.com/wp-content/uploads/2022/04/Russia-and-Ukraine-flags-776x438.jpg 776w, https://burgessforensics.com/wp-content/uploads/2022/04/Russia-and-Ukraine-flags-130x73.jpg 130w, https://burgessforensics.com/wp-content/uploads/2022/04/Russia-and-Ukraine-flags-600x338.jpg 600w, https://burgessforensics.com/wp-content/uploads/2022/04/Russia-and-Ukraine-flags.jpg 1024w" sizes="(max-width: 240px) 100vw, 240px" /></a>epared? Were the US and/or the EU pumping up Ukraine’s cyber defenses or attacking the offensive cyber capabilities of Russia? The newspapers wonder about this and government sources overtly express surprise and confusion that there isn’t more cyber damage.</p>
<p>I would be willing to wager that they know more about this than they are letting on. But then, isn’t that almost always the case?</p>
<p>The coming days and weeks will tell us more about cyberwar in Ukraine. It’s possible that all-out disruption of Ukraine’s Internet will come to pass. We hope not.</p>
<p>But one thing about this history stands out. We have not seen the kinetic response to cyberattacks on a wide scale that was being discussed a decade ago.</p>
<p>Luck? Cooler heads? Invisible cyber counterattacks? Thoughts of a Cyber version the Mutually Assured Destruction (MAD) doctrine that has, in theory, kept the world from launching nuclear war? Or is physical destruction on a massive scale enough to satisfy those bent on domination?</p>
<p>These times we’re living in will surely shape the times we will be living in. Let us hope and work for that cyberwar doesn’t exceed the malign effects we have seen to date and that going forward we see fewer dire images because of fewer dire circumstances.</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2022/04/10-grunge-stamp-peace-symbol-5.png"><img loading="lazy" decoding="async" class="wp-image-12837 aligncenter" src="https://burgessforensics.com/wp-content/uploads/2022/04/10-grunge-stamp-peace-symbol-5-300x294.png" alt="" width="198" height="194" srcset="https://burgessforensics.com/wp-content/uploads/2022/04/10-grunge-stamp-peace-symbol-5-300x294.png 300w, https://burgessforensics.com/wp-content/uploads/2022/04/10-grunge-stamp-peace-symbol-5-1024x1002.png 1024w, https://burgessforensics.com/wp-content/uploads/2022/04/10-grunge-stamp-peace-symbol-5-768x752.png 768w, https://burgessforensics.com/wp-content/uploads/2022/04/10-grunge-stamp-peace-symbol-5-1536x1504.png 1536w, https://burgessforensics.com/wp-content/uploads/2022/04/10-grunge-stamp-peace-symbol-5-149x146.png 149w, https://burgessforensics.com/wp-content/uploads/2022/04/10-grunge-stamp-peace-symbol-5-50x50.png 50w, https://burgessforensics.com/wp-content/uploads/2022/04/10-grunge-stamp-peace-symbol-5-82x80.png 82w, https://burgessforensics.com/wp-content/uploads/2022/04/10-grunge-stamp-peace-symbol-5-42x42.png 42w, https://burgessforensics.com/wp-content/uploads/2022/04/10-grunge-stamp-peace-symbol-5-130x127.png 130w, https://burgessforensics.com/wp-content/uploads/2022/04/10-grunge-stamp-peace-symbol-5-600x587.png 600w, https://burgessforensics.com/wp-content/uploads/2022/04/10-grunge-stamp-peace-symbol-5.png 2043w" sizes="(max-width: 198px) 100vw, 198px" /></a></p>
<div style='display:none;' class='shareaholic-canvas' data-app='share_buttons' data-title='Cyberwar History and Ukraine' data-link='https://burgessforensics.com/cyberwar-history-and-ukraine/' data-app-id-name='category_below_content'></div><div style='display:none;' class='shareaholic-canvas' data-app='recommendations' data-title='Cyberwar History and Ukraine' data-link='https://burgessforensics.com/cyberwar-history-and-ukraine/' data-app-id-name='category_below_content'></div><p>The post <a href="https://burgessforensics.com/cyberwar-history-and-ukraine/">Cyberwar History and Ukraine</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/cyberwar-history-and-ukraine/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
