BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//bsides-cymru-2023-2022//talk//E9HTYX
BEGIN:VEVENT
UID:pretalx-bsides-cymru-2023-2022-E9HTYX@pretalx.com
DTSTART:20230211T143000Z
DTEND:20230211T150000Z
DESCRIPTION:In 2022\, Mandiant identified spear-phishing activity targeting
  government entities\, diplomatic missions\, and international organizatio
 ns in Europe and North America. The threat actors were using a variety of 
 techniques and newly identified malware families that ultimately lead to d
 isseminating BEACON malware payloads.\n \nThe extensive email phishing ope
 rations were performing covert cyber espionage\, using CobaltStrike BEACON
  implant\, which Mandiant publicly exposed in the blog “Trello From the 
 Other Side: Tracking APT29 Phishing Campaigns” and attributed these camp
 aigns to APT29\; a Russian-nexus threat actor that’s also been attribute
 d to the SolarWinds supply chain intrusions.\n \nIn this talk\, Mathias wi
 ll provide:\n- A deeper overview of the various novel phishing campaigns t
 hey’ve observed since February 2021\n- Any changes in APT29 phishing cam
 paigns since the publication of findings in April 2022\n- Showcase the mal
 ware utilized to gain a foothold into a victim's network.\n- Provide recom
 mendations for defenders to mitigate risks
DTSTAMP:20260714T094315Z
LOCATION:Track 2  -  Foxhunter
SUMMARY:When diplomats send Beacon - A retrospective view of APT29 maliciou
 s phishing campaigns - Mathias Frank
URL:https://pretalx.com/bsides-cymru-2023-2022/talk/E9HTYX/
END:VEVENT
END:VCALENDAR
