BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.nsec.io//2024//TQDKBA
BEGIN:VTIMEZONE
TZID:EST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T070000Z
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T080000Z
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-2024-NWRSZS@cfp.nsec.io
DTSTART;TZID=EST:20240516T130000
DTEND;TZID=EST:20240516T133000
DESCRIPTION:In 2014\, we published a paper about Operation Windigo\, where 
 we described a cluster of server-side threats fuelled by Ebury\, a backdoo
 r and credential stealer injected into the OpenSSH server and client of co
 mpromised servers. That report shed light on web traffic redirections\, de
 livery of Windows malware\, and spam campaigns\, all using Ebury-compromis
 ed servers.\n\nAfter the arrest and extradition of one of the perpetrators
  in 2015\, some of the monetization activities temporarily stopped\, but n
 ot all of the botnet’s activities. Ebury continued to be updated and dep
 loyed to tens of thousands of servers each year\, to reach a cumulative to
 tal of nearly 400\,000 victims since 2009\, the first year Ebury was seen.
  Moreover\, we have discovered its operators have added more tools to thei
 r arsenal\, such as Apache modules to exfiltrate HTTP requests or proxy tr
 affic\, Linux kernel modules to perform traffic redirections\, and modifie
 d Netfilter tools to inject and hide firewall rules.\n\nFor this investiga
 tion we set up honeypots to collect Ebury samples and understand deploymen
 t tactics\, and partnered with law enforcement. This gave us unique visibi
 lity into the perpetrators’ activities\, which expanded to include crypt
 ocurrency theft and possibly exfiltration of credit card details. We now h
 ave a better understanding of how they expand their botnet not only by ste
 aling credentials\, but also by actively trying to compromise the hosting 
 provider’s infrastructure to deploy malware on all of the providers’ c
 ustomer-rented servers. In some cases\, this resulted in the compromise of
  tens of thousands of servers\, hosting millions of domains.\n\nThe latest
  update to Ebury\, versioned 1.8.2\, was first seen in January 2024. In th
 e past years\, clever userland rootkit functionalities were added to Ebury
 \, which make its detection a lot more difficult than before. From a syste
 m administrator’s perspective\, not only is the malware file absent\, bu
 t none of the resources it uses – such as processes\, sockets\, and mapp
 ed memory – are listed when inspecting the system.\n\nThis presentation 
 not only reveals the latest toolset of the Ebury gang\, but also discusses
  detection techniques to protect against some of the trickiest Linux threa
 ts. Some techniques are specific to Ebury\, but most apply to the detectio
 n of any userland rootkit.
DTSTAMP:20260916T071842Z
LOCATION:Ville-Marie
SUMMARY:Ebury\, 10 years in: The evolution of a sophisticated Linux server 
 threat - Marc-Etienne M.Léveillé
URL:https://cfp.nsec.io/2024/talk/NWRSZS/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-2024-GV33WS@cfp.nsec.io
DTSTART;TZID=EST:20240516T151500
DTEND;TZID=EST:20240516T154500
DESCRIPTION:Q&A Discussion for the malware block.
DTSTAMP:20260916T071842Z
LOCATION:Ville-Marie
SUMMARY:Malware Q&A - Marc-Etienne M.Léveillé\, Alexandre Côté\, Pierre
 -Marc Bureau\, Greg Lesnewich\, Sergei Frankoff\, Alexis Dorais-Joncas
URL:https://cfp.nsec.io/2024/talk/GV33WS/
END:VEVENT
END:VCALENDAR
