BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//hack-lu-2023//speaker//9D8VMP
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20221018T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20221030T030000
RDATE:20231029T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20230326T030000
RDATE:20240331T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Ongoing EvilEye Campaigns Targeting CCP Adversaries - Rascagneres 
 Paul
DTSTART;TZID=Europe/Luxembourg:20231018T093000
DTEND;TZID=Europe/Luxembourg:20231018T100000
DTSTAMP:20260812T203857Z
UID:pretalx-hack-lu-2023-ZBRV3J@pretalx.com
DESCRIPTION:Volexity has recently uncovered ongoing campaigns by EvilEye\,
  a Chinese state-backed threat actor\, targeting three of the five groups 
 the Chinese Communist Party (CCP) refers to as the “Five Poisons”. The
  targeted groups are members of the Tibetan community\, the Uyghur ethnic 
 group\, and Taiwanese nationals. Volexity's research has identified both c
 urrently active and historic activity for these campaigns. Volexity also i
 dentified related campaigns from this threat actor specifically targeting 
 the Uyghur ethnic group back in 2019 and 2020. \nThe ongoing campaigns con
 sist of two elements\, malicious mobile applications and fake websites\, w
 hich are created by the attacker to facilitate exploitation of end users b
 y way of zero or n-day exploits. The three Android malware families being 
 deployed include new versions of BADBAZAAR\, as well as two previously und
 ocumented families. In addition to these Android malware families\, there 
 is compelling evidence that EvilEye has developed an iOS implant and tried
  to distribute it via the Apple App Store.\nThis presentation outlines the
  current\, ongoing campaigns\; delves into the technical details of the An
 droid malware families involved\; discusses the threat actor's command-and
 -control (C2) infrastructure and configuration\; and reveals how the threa
 t actor builds communities to distribute their malware through trusted pla
 tforms. The presentation also explores overlaps between the campaigns and 
 explains links to historic activity.
LOCATION:Salle Europe
URL:https://pretalx.com/hack-lu-2023/talk/ZBRV3J/
END:VEVENT
END:VCALENDAR
