
DEF CON 33 - Man in the Malware: Intercepting Adversarial Communications - Ben 'polygonben' Folland
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 33:09
Revised Summary
The talk "Man in the Malware, Intercepting Adversarial Communications" by Benolan (Ben) from Huntress demonstrates how threat actors' operational security failures when using Telegram for command and control (C2) can be exploited to intercept their communications and gain valuable intelligence.
Key Technical Concepts:
- Info stealers: Malware designed to exfiltrate sensitive data and credentials from victim machines
- Command and control (C2): Methods by which malware communicates with threat actor-controlled servers
- Threat actor shift: Moving from traditional C2 infrastructure (domains, hosting) to trusted platforms like Telegram, which offers free, encrypted, high-availability, and relatively anonymous communication
Technical Methodology:
- Telegram API exploitation: Malware developers embed Telegram API tokens directly in their code to enable communication
- API functions used by threat actors:
sendMessageto exfiltrate stolen datagetMeto validate bot tokensgetUpdatesto enumerate chats and find chat IDsforwardMessageto intercept communications between chats
Case Study Analysis:
- Initial delivery: DHL phishing campaign with malicious JavaScript attachment leading to PowerShell execution
- Malware chain: JavaScript → PowerShell → .NET executable (x.exe) → Nova info stealer injected into regasm.exe
- Critical vulnerability: Unencrypted Telegram bot token embedded in the Nova info stealer code
- Major opsec failure: Threat actor tested malware on their own machine rather than a test environment
- Exploitation process: Using scripts to add the threat actor's bot to a controlled chat, then forwarding messages from the threat actor's chat to access their communications
Intelligence Gains:
- Access to the threat actor's entire operation including:
- Screenshots of their own desktop showing development of phishing pages
- Stolen credentials in plaintext f
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
We have a new speaker today. So, please give him a big round a big, you know, hand of applause. The guy's name is called Benolan. He's from England, uh, across the pond. The talk we're giving today is called Man in the Malware, Intercepting Adversarial Communications. Um, so it's his first time. Make him feel welcome and thanks for coming today, guys. All right, here we go. Thank you. Thank you. Thank you and welcome. As um he mentioned there, yeah, this is my first Defcon talk. This is actually the second time I've been in the States. The first was last week. Um I'm loving it. It's been an an incredible event so far. Um and before I get started, I just want to say a massive thank you to everybody who's chosen to come to this talk. I know you've got super busy days. Um so I appreciate that…