DEF CON 33 - Investigating Threat Actor Targeting Researchers, Academics - C Tafani-Dereeper, M Muir

DEF CON 33 - Investigating Threat Actor Targeting Researchers, Academics - C Tafani-Dereeper, M Muir

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 35:40

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Researchers Discover MUT 1244 Threat Actor Targeting Security Professionals Through Multi-Vector Campaign

Researchers discovered MUT 1244, a sophisticated threat actor systematically targeting security researchers, academics, and offensive actors through multiple attack vectors including malicious npm packages, phishing campaigns, and trojanized tools 0:31.

Key Findings:

  • Malicious npm package: The actor created "ox engine XML RPC" (typosquatting legitimate "XML RPC" package) containing a backdoor that exfiltrated nearly 400,000 credentials to a Dropbox account controlled by "Paul Müller 977" 1:41
  • Second-stage payload: The malware downloaded additional code that deployed both a coin miner and an info stealer targeting cloud credentials (AWS, Azure), Electrum wallets, bash history, and SSH keys 1:41
  • Academic phishing campaign: The actor scraped researcher emails from arXiv and sent fake CPU microcode update emails, directing victims to a malicious website that delivered the same payload 6:02
  • Trojanized security tools: The attackers created "YOP," a WordPress credential validator tool targeting offensive actors. The tool used the malicious XML RPC package as a dependency and stole the very credentials it was supposed to validate 8:17
  • Fake proof-of-concept repositories: The actor established credibility through fake CVE exploit repositories with detailed READMEs, which were promoted through SEO-optimized websites and social media accounts 15:03
  • Cryptocurrency targeting: Evidence showed earlier operations targeting blockchain communities through a fake "token recovery" tool promoted on Medium, Quora, and Russian-lang

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Uh, good afternoon, Defcon. Uh, got a great talk for you today. Um, Kristoff and Matt are going to talk to you about weaponizing trust. Uh, please give a nice Defcon welcome to Kristoff and Matt. [Applause] >> Hi everyone. Thanks for coming to our talk to our Defcon talk. Um, so this is our first time speaking at Defcode and we're very excited. Matt is coming all the way from Scotland. I'm coming all the way from Switzerland. So, thanks for being here. This is the story of us investigating a threat actor that we called the MUD 1244 that started in December December 2024. At first, we thought that the investigation would look something like this. You know, going lly from point A to point B in a very linear fashion. In the end, it went more something like that. Um, where we had a few hiccaps…