Ben
Ben Folland is a volunteer researcher at Ctrl-Alt-Intel, where they investigate cybercrime and
espionage operations, track threat actor infrastructure, analyze TTPs, and expose threat actors.
His professional work has included stopping Akira affiliates, responding to Qilin, and Space Bear
ransomware incidents, investigating Storm-2603 activity linked to Warlock ransomware, tracking
Chinese adversaries targeting IIS servers for SEO fraud, and hunting DPRK malware used in
supply-chain attacks.
They are passionate about DFIR, threat hunting, CTI, malware analysis, and OSINT, and
regularly write about security research at Ctrl-Alt-Intel. They have previously spoken on the main
stage at DEF CON, as well as hack.lu, Malware Village, DC441905, and multiple BSides events.
Sessions
Command & Control, or C2, is used at some point in all intrusions in order for the threat actor to communicate with victim hosts and control them.
This talk explores how defenders can turn adversary C2 implementations against them by finding mistakes in cryptography, protocol design, infrastructure hygiene, and operational security. Through real-world case studies, we will walk through malware that used blockchain-based C2 with weak encryption, allowing historic commands to be recovered from public on-chain data, and a separate campaign where expired attacker infrastructure enabled sinkholing, victim telemetry collection, and safe reimplementation of server-side C2 behavior for analysis.
Rather than treating C2 as a black box, this talk shows how reverse engineering, infrastructure hunting, emulation, and creative defensive thinking can provide intelligence collection opportunities.
Nation-state operators are often treated as disciplined, sophisticated, and untouchable. But sometimes, their own infrastructure tells a different story.
In this talk, we examine two active espionage campaigns linked to Russia’s GRU and Iran’s MOIS where exposed command-and-control infrastructure revealed source code, operator logs, tooling, and evidence of live operations. By turning the adversaries’ own mistakes against them, we show how defenders can move beyond indicators and gain rare insight into how state-backed campaigns actually function.
This is a story about C2, OPSEC failures, and what happens when the hackers accidentally expose themselves.