DEF CON 33 - Don’t Cry Wolf: Evidence based assessments of ICS Threats - Jimmy Wylie & Sam Hanson

DEF CON 33 - Don’t Cry Wolf: Evidence based assessments of ICS Threats - Jimmy Wylie & Sam Hanson

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 23:54

Malware Analysis
No ratings yet Log in to rate
Transcript Available
Description

Here's the revised summary addressing the feedback concerns, with improved clarity, completeness, and emphasis on key themes:

Revised Summary:

The video details how malware analysts at DRAOS systematically identify and assess Industrial Control System (ICS) threats using a rigorous three-part framework to prevent misclassification and unnecessary alarm. The analysts stress that evidence-based rigor is critical to maintaining community trust, as demonstrated by the 2021 "Tardigrade" incident, where a misidentified ransomware variant caused widespread panic in the biotech sector despite being nothing more than a common Cobalt Strike Beacon delivery tool 1:49-2:52.

Core Framework for ICS Malware Classification 3:14-4:36:
For a sample to be classified as ICS malware, it must satisfy three evidence-based criteria:

  1. ICS Capability: Code can interact with ICS/OT environments (e.g., speak OT protocols, manipulate PLC logic).
  2. Malicious Intent: Provable evidence the software was designed to harm OT environments (e.g., not a red team tool).
  3. Adverse Effects: Verified potential to cause OT harm (e.g., steal process data, enable unauthorized access, alter device logic).

Case Studies Highlighting Analytical Challenges:

  • IoT Exploit Toolkit 7:37-11:58:
    A massive tool with 175+ ICS exploits and 19 industrial protocol support. Despite its capabilities, it was deemed not ICS malware due to "dual-use dilemmas" (e.g., detailed vulnerability documentation suggesting defensive/red team use).
  • Kurtler SCADA 12:04-15:15:
    A simple VNC client brute-forcer that successfully compromised HMIs. Though not technically ICS malware (lacking ICS-specific actions), it proved that **sophistication is irrelevant

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Malware Analysis. Commonly maps to: Security Operations, Security Architecture and Engineering. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Welcome to Don't Cry Wolf. I'm Jimmy Wy. I'm a malware analyst at DRAOS. >> I'm Sam. I'm a half and half vulnerability researcher and malware analyst at Draos. And we're here to talk to you about how we hunt for and assess threats to IC capabilities in Virus Total. >> So, it's 2021 and a customer is asking me for an assist. They sent me a zip file um with some stuff to look at, validate some results that another team had done. I take a look. It's fairly straightforward. identified the thing as Cobalt Strike Beacon for delivering KTI ransomware. The customer dissatisfied. I didn't really think any more of it. At that time, ransomware had really started to grow in the industrial space and this kind of stuff was getting more and more common. A few months later in 2021, a BioSac partner releas…