BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Demystifying the Playboy RaaS\n   Tags: Malware Vill
 age | Creator Talk/Panel\n   When: Saturday\, Aug 8\, 10:45 - 11:25 PDT\n 
   Where: LVCCW Level 1 Hall 2 600 (Malware Village) Talks - [1]Map\n\n   D
 escription:\n\n   In recent years\, ransomware has become one of the most 
 prolific forms\n   of cybercrime with financial gain as primary motive. Th
 e problem keeps\n   getting bigger\, with a new operation seeing the light
  almost every\n   month. The Dutch National Police is often a key player i
 n large-scale\n   ransomware investigations. Operation Cronos is a prime e
 xample\, where\n   law enforcement took down infrastructure of the infamou
 s LockBit group\n   in 2024.\n\n   Today\, many ransomware groups operate 
 RaaS (ransomware-as-a-service)\n   models. They provide the ransomware and
  a platform to extort victims\n   as a service\, and affiliated hacker gro
 ups carry out the actual\n   attacks. The platform is often run from a VPS
  (virtual private\n   server)\, and sometimes\, this server is in the Neth
 erlands. Dutch law\n   enforcement seizes those servers and extracts their
  content for\n   investigation. This happened to the Playboy ransomware in
  late 2024.\n\n   A chain of various tools is used to provide a ready-to-u
 se ransomware\n   package to affiliates of a RaaS program. Several modern 
 ransomware\n   operations even support CPU architectures and operating sys
 tems other\n   than x86-64 and Windows. New cryptographic keys are generat
 ed for\n   every victim\, ransomware parameters are configured\, and a bui
 lder\n   creates the final package to be used by the affiliate. In this ta
 lk\,\n   we will reveal how we seized the Playboy ransomware servers\, div
 e into\n   its toolchain\, and look at how executables were prepared to br
 each\n   victims.\n\n   SpeakerBio:  Gijs Rijnders\, Malware & CTI Special
 ist\n\n   Gijs is a cyber threat intelligence analyst and malware reverse\
 n   engineer at the Dutch National Police where he defends the Police\n   
 organization from cyber attacks. He previously worked at the CERT of\n   T
 esorion\, a Dutch cybersecurity company\, where he reverse engineered\n   
 various ransomware families and published decryption tools to the\n   NoMo
 reRansom initiative to help victims recover from attacks.\n\n   '\n\n   1.
  #LVCCW_Level1_Hall2\n\n\n
DTEND:20260808T182500Z
DTSTART:20260808T174500Z
LOCATION:Malware Village - LVCCW Level 1 Hall 2 600 (Malware Village) Talks
SUMMARY:Demystifying the Playboy RaaS
END:VEVENT
END:VCALENDAR
