BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//hack-lu-2025//talk//XDPLNP
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20241024T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20241027T030000
RDATE:20251026T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20250330T030000
RDATE:20260329T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Exploiting Legit APIs for Covert C2: A New Perspective on Cloud-ba
 sed Malware Operations - cocomelonc
DTSTART;TZID=Europe/Luxembourg:20251024T114500
DTEND;TZID=Europe/Luxembourg:20251024T121500
DTSTAMP:20260812T000430Z
UID:pretalx-hack-lu-2025-XDPLNP@pretalx.com
DESCRIPTION:As modern security defenses evolve\, attackers continue to lev
 erage legitimate cloud services for command-and-control (C2) communication
 \, effectively bypassing traditional network detection systems. This talk 
 presents original research into the abuse of lesser-known free cloud APIs 
 such as GitHub Gists\, Telegram Bot API\, Discord Webhooks\, and Google Ap
 ps Script for stealthy malware communication. Unlike well-documented abuse
 s of Google Drive or Dropbox\, our study explores new\, unmonitored attack
  surfaces that can be exploited by adversaries while remaining under the r
 adar of enterprise security monitoring tools.\n\nKey topics of my talk:\nT
 echniques for establishing C2 channels using free cloud services.\nEncrypt
 ion and obfuscation strategies to evade EDR/ML-based detection.\nCase stud
 ies demonstrating real-world proof-of-concepts (PoC) of API abuse.\nRecomm
 endations for mitigating risks and detecting malicious API-based C2 activi
 ty.\n\nTraditional C2 detection methods focus on recognizing known malware
  signatures or anomalous network traffic. However\, API-based C2 channels 
 blend seamlessly into normal cloud service usage\, making them exceptional
 ly difficult to detect. This talk will provide defenders with insight into
  how attackers exploit these mechanisms and offer practical countermeasure
 s to strengthen security postures against emerging threats.\n\nTarget Audi
 ence:\n\nRed Teamers\, Ethical Hackers\, and Penetration Testers\nSOC Anal
 ysts and Threat Hunters\nIncident Responders and Security Engineers
LOCATION:Europe
URL:https://pretalx.com/hack-lu-2025/talk/XDPLNP/
END:VEVENT
END:VCALENDAR
