DEF CON 33 - Man in the Malware: Intercepting Adversarial Communications - Ben 'polygonben' Folland

DEF CON 33 - Man in the Malware: Intercepting Adversarial Communications - Ben 'polygonben' Folland

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 33:09

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Revised Summary

The talk "Man in the Malware, Intercepting Adversarial Communications" by Benolan (Ben) from Huntress demonstrates how threat actors' operational security failures when using Telegram for command and control (C2) can be exploited to intercept their communications and gain valuable intelligence.

Key Technical Concepts:

  • Info stealers: Malware designed to exfiltrate sensitive data and credentials from victim machines
  • Command and control (C2): Methods by which malware communicates with threat actor-controlled servers
  • Threat actor shift: Moving from traditional C2 infrastructure (domains, hosting) to trusted platforms like Telegram, which offers free, encrypted, high-availability, and relatively anonymous communication

Technical Methodology:

  • Telegram API exploitation: Malware developers embed Telegram API tokens directly in their code to enable communication
  • API functions used by threat actors:
    • sendMessage to exfiltrate stolen data
    • getMe to validate bot tokens
    • getUpdates to enumerate chats and find chat IDs
    • forwardMessage to intercept communications between chats

Case Study Analysis:

  • Initial delivery: DHL phishing campaign with malicious JavaScript attachment leading to PowerShell execution
  • Malware chain: JavaScript → PowerShell → .NET executable (x.exe) → Nova info stealer injected into regasm.exe
  • Critical vulnerability: Unencrypted Telegram bot token embedded in the Nova info stealer code
  • Major opsec failure: Threat actor tested malware on their own machine rather than a test environment
  • Exploitation process: Using scripts to add the threat actor's bot to a controlled chat, then forwarding messages from the threat actor's chat to access their communications

Intelligence Gains:

  • Access to the threat actor's entire operation including:
    • Screenshots of their own desktop showing development of phishing pages
    • Stolen credentials in plaintext f

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

We have a new speaker today. So, please give him a big round a big, you know, hand of applause. The guy's name is called Benolan. He's from England, uh, across the pond. The talk we're giving today is called Man in the Malware, Intercepting Adversarial Communications. Um, so it's his first time. Make him feel welcome and thanks for coming today, guys. All right, here we go. Thank you. Thank you. Thank you and welcome. As um he mentioned there, yeah, this is my first Defcon talk. This is actually the second time I've been in the States. The first was last week. Um I'm loving it. It's been an an incredible event so far. Um and before I get started, I just want to say a massive thank you to everybody who's chosen to come to this talk. I know you've got super busy days. Um so I appreciate that…