BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: OopsSec -The bad\, the worst and the ugly of APTâ€™s
  operations\n   security\n   When: Friday\, Aug 12\, 10:30 - 11:15 PDT\n  
  Where: Caesars Forum - Alliance 301-309\, 321 (Track 4) - [1]Map\n\n   Sp
 eakerBio:Tomer Bar \, Director of Security Research at SafeBreach\n   Tome
 r Bar is a hands-on security researcher with ~20 years of unique\n   exper
 ience in cyber security. In the past\, he ran research groups for\n   the 
 Israeli government and then led the endpoint malware research for\n   Palo
  Alto Networks. Currently\, he leads the SafeBreach Labs as the\n   direct
 or of security research.\n\n   His main interests are Windows vulnerabilit
 y research\, reverse\n   engineering\, and APT research.\n\n   His recent 
 discoveries are the PrintDemon vulnerabilities in the\n   Windows Spooler 
 mechanism which were a candidate in the best privilege\n   escalation of 2
 021 Pwnie awards and several research studies on\n   Iranian APT campaigns
 .\n\n   He is a contributor to the MITRE ATT&CK® framework.\n\n   He prese
 nted his research at BlackHat 2020\, Defcon 2020\, 2021\, and\n   Sector 2
 020 conferences.\n\n\n   Description:\n   Advanced Persistent Threat group
 s invest in developing their arsenal\n   of exploits and malware to stay b
 elow the radar and persist on the\n   target machines for as long as possi
 ble. We were curious if the same\n   efforts are invested in the operation
  security of these campaigns. We\n   started a journey researching active 
 campaigns from the Middle East to\n   the Far East including the Palestini
 an Authority\, Turkey\, and Iran\,\n   Russia\, China\, and North Korea. T
 hese campaigns were both\n   state-sponsored\, surveillance-targeted attac
 ks and large-scale\n   financially-motivated attacks. We analyzed every te
 chnology used\n   throughout the attack chain: Windows (Go-lang/.Net/Delph
 i) and Android\n   malware\; both on Windows and Linux-based C2 servers. W
 e found\n   unbelievable mistakes which allow us to discover new advanced 
 TTPs\n   used by attackers\, for example: bypassing iCloud two-factor\n   
 authentication' and crypto wallet and NFT stealing methods. We were\n   ab
 le to join the attackers' internal groups\, view their chats\, bank\n   ac
 counts and crypto wallets. In some cases\, we were able to take down\n   t
 he entire campaign. We will present our latest breakthroughs from our\n   
 seven-year mind-game against the sophisticated Infy threat actor who\n   s
 uccessfully ran a 15-year active campaign using the most secured\n   opSec
  attack chain we've encountered. We will explain how they\n   improved the
 ir opSec over the years and how we recently managed to\n   monitor their a
 ctivity and could even cause a large-scale\n   misinformation counterattac
 k. We will conclude by explaining how\n   organizations can better defend 
 themselves.\n   '\n\n   1. https://defcon.outel.org/consolidated_page.html
 #CaesarsAllianceBR\n\n\n
DTEND:20220812T181500Z
DTSTART:20220812T173000Z
LOCATION:DC - Caesars Forum - Alliance 301-309\, 321 (Track 4)
SUMMARY:OopsSec -The bad\, the worst and the ugly of APTâ€™s operations sec
 urity
END:VEVENT
END:VCALENDAR
