My crimeware digital garden
A digital garden is a living collection of notes, reflections, and half-formed ideas that grow and connect over time. After more than twenty years spent reverse engineering, tracking, and disrupting botnets, mine has become a map of what endures in crimeware; the patterns that survive every reinvention of the threat landscape. In this talk I walk through the core ideas at the center of my crimeware digital garden.
Each concept presented is illustrated with recent, hands-on cases. Financial motivation still shapes almost every design decision attackers make. Detection evasion explains a lot of convoluted functionalities analysts need to dig through. This includes sandbox awareness, software packing, and tricks against static detection engines. On the defender's side, concrete actions can be taken to protect users and organizations, from technical protection, to takedowns and litigations.
The recurring lesson surfaced in organizing this knowledge is that there is rarely magic here; just malware developers, and operators, with their objectives. Keeping objectives and techniques in focus is what makes analysis tractable, whether you are doing the work yourself or guiding agents to help.
This presentation aims at organizing crimeware related knowledge to surface the most important concepts used when analyzing new malware campaigns. Each concept is illustrated with real world examples.
Pierre-Marc Bureau is an independent security researcher. He has more than 20 years of experience in malware analysis, threat intelligence, reverse engineering, and the disruption of large-scale criminal operations. Over the last decade, he has held several roles at Google — first on Chrome, then on Safe Browsing, and most recently within the Threat Analysis Group (now part of Google's Threat Intelligence Group). Across the roles, he has focused on protecting billions of users from malware and phishing. He has also supported external partners and internal Google teams in combatting financially motivated threat actors.
Before joining Google, he worked at ESET and Dell SecureWorks. At both ESET and Google, he has built and led teams of analysts. He has presented at international conferences including Black Hat Europe, Recon, Hack.lu, and Virus Bulletin.