DEF CON 32 - Behind Enemy Lines: Engaging and Disrupting Ransomware Web Panel - Vangelis Stykas

DEF CON 32 - Behind Enemy Lines: Engaging and Disrupting Ransomware Web Panel - Vangelis Stykas

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 39:01

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Vel Stias disrupts ransomware groups by exploiting vulnerabilities in their command-and-control infrastructure using web penetration testing and open-source threat intelligence, highlighting the growing professionalism and structure of the ransomware industry. 3:00

Key Takeaways:
• Uses web app penetration testing and CTI sources like Ransomware.lu and GitHub to identify ransomware groups such as Malo, Black Cat, and Everest 3:00.
• Exploits a reply ID parameter vulnerability in Malo’s chat to access internal messages, revealing team dynamics and decryptor details 20:01.
• Continuously scans Black Cat’s C2 servers, discovering documentation that exposed lateral movement and data exfiltration commands, leading to the interruption of a campaign targeting four cryptocurrency companies 24:00.
• A child’s observation of a misconfigured WordPress server named "vertigo" leads to unauthorized access, revealing sensitive data and enabling exploitation of a Windows 2012 server with remote command execution 31:00.
• Advocates for greater transparency in the cybersecurity community, calling for open sharing of threat data to improve collective defense and challenge the status quo without becoming a vigilante 36:40.

Stias positions himself as a "socratic fly" who challenges malicious actors ethically, emphasizing that his actions aim to disrupt criminal behavior without crossing into harmful vigilantism, and calls for stronger, more open collaboration in threat intelligence.

Sources:

  • 3:00 Vel Stias discusses his use of open-source threat intelligence and web penetration test

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

hello defon uh first of all if anyone does not uh want to be photographed I'm going to take two pictures that's for my mom she never believes that anyone comes and hear me talking that says a lot about her trust issues but yeah so hello everyone and welcome to my talk Behind Enemy Lines engaging and disrupting ransomware web panels this talk uh is pg17 due to two reasons first uh there are going to be some Notions about drugs and bad words from uh people in the dock and secondly I love saying [ __ ] and [ __ ] and I'm not going to stop it hello as you can see I'm Vel stias I'm the CTO and co-founder of a penetration testing firm called called atropos we specialized in API penetration testing and green uh PV and electronic vehicle Chargers penetration testing my research interest for the pa…