
DEF CON 33 - Investigating Threat Actor Targeting Researchers, Academics - C Tafani-Dereeper, M Muir
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 35:40
Researchers Discover MUT 1244 Threat Actor Targeting Security Professionals Through Multi-Vector Campaign
Researchers discovered MUT 1244, a sophisticated threat actor systematically targeting security researchers, academics, and offensive actors through multiple attack vectors including malicious npm packages, phishing campaigns, and trojanized tools 0:31.
Key Findings:
- Malicious npm package: The actor created "ox engine XML RPC" (typosquatting legitimate "XML RPC" package) containing a backdoor that exfiltrated nearly 400,000 credentials to a Dropbox account controlled by "Paul Müller 977" 1:41
- Second-stage payload: The malware downloaded additional code that deployed both a coin miner and an info stealer targeting cloud credentials (AWS, Azure), Electrum wallets, bash history, and SSH keys 1:41
- Academic phishing campaign: The actor scraped researcher emails from arXiv and sent fake CPU microcode update emails, directing victims to a malicious website that delivered the same payload 6:02
- Trojanized security tools: The attackers created "YOP," a WordPress credential validator tool targeting offensive actors. The tool used the malicious XML RPC package as a dependency and stole the very credentials it was supposed to validate 8:17
- Fake proof-of-concept repositories: The actor established credibility through fake CVE exploit repositories with detailed READMEs, which were promoted through SEO-optimized websites and social media accounts 15:03
- Cryptocurrency targeting: Evidence showed earlier operations targeting blockchain communities through a fake "token recovery" tool promoted on Medium, Quora, and Russian-lang
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Uh, good afternoon, Defcon. Uh, got a great talk for you today. Um, Kristoff and Matt are going to talk to you about weaponizing trust. Uh, please give a nice Defcon welcome to Kristoff and Matt. [Applause] >> Hi everyone. Thanks for coming to our talk to our Defcon talk. Um, so this is our first time speaking at Defcode and we're very excited. Matt is coming all the way from Scotland. I'm coming all the way from Switzerland. So, thanks for being here. This is the story of us investigating a threat actor that we called the MUD 1244 that started in December December 2024. At first, we thought that the investigation would look something like this. You know, going lly from point A to point B in a very linear fashion. In the end, it went more something like that. Um, where we had a few hiccaps…