They Hacked Me. I Took Their Source Code.
This talk walks through how a $20 piece of cloud infrastructure became a fully functional threat intelligence pipeline. Starting with a simple honeypot, we capture an inbound attack, pivot back against the attacker's infrastructure using a reverse scan, discover an open staging server, and walk away with something most researchers only dream of — the actual source code behind the malware.
No enterprise budget. No team. No expensive tooling. Just cheap infrastructure, some curiosity, and attackers with terrible opsec.
We'll walk through the full attack chain in reverse — from the initial hit on the honeypot, through the pivot and enumeration of attacker infrastructure, to pulling the payload and source code from their own server. We'll then crack open both the binary in IDA Pro and the source code side by side, showing exactly what this bot was built to do and what the attacker left behind for anyone willing to look.
The key takeaway is simple — you don't need a SOC, a threat intel platform, or a six figure budget to find real malware in the wild. Sometimes the attackers do half the work for you.
This session demonstrates how minimal, low-cost cloud infrastructure (around $20) can be turned into a working threat intelligence pipeline without enterprise tooling, a dedicated team, or a large budget. The presenter starts with a basic honeypot, captures a live inbound attack, then pivots back against the attacker's own infrastructure using a reverse scan. That pivot uncovers an exposed staging server, ultimately yielding the malware's actual source code.
The talk walks the full attack chain in reverse: from the initial honeypot hit, through pivoting and enumerating the attacker's infrastructure, to pulling the payload and source code directly from the attacker's server. It then examines the malware two ways at once — analysing the binary in IDA Pro alongside the recovered source code — to show what the bot was designed to do and what the attacker inadvertently left exposed.
The core takeaway is that meaningful malware research in the wild doesn't require a SOC, a commercial threat intel platform, or a six-figure budget. With cheap infrastructure, curiosity, and attackers practicing poor operational security, researchers can sometimes let the attackers do much of the work for them.
David Rushmer is a technology leader, product strategist, and security researcher specialising in areas of artificial intelligence, reverse engineering, malware analysis, and threat intelligence. With a career spanning offensive and defensive security disciplines, he has built and operated threat research and intelligence teams, developed security products, and helped organisations better understand and defend against emerging cyber threats.
As a Tech Evangelist at Hex-Rays, David focuses on bridging the gap between cutting-edge reverse engineering technology and the practitioners who rely on it every day. His expertise spans binary analysis, vulnerability research, malware investigation, threat intelligence generation, and the application of AI to complex cybersecurity challenges.