Hack.lu 2026

Turning the Tables: Command & no Control

Command & Control, or C2, is used at some point in all intrusions in order for the threat actor to communicate with victim hosts and control them.

This talk explores how defenders can turn adversary C2 implementations against them by finding mistakes in cryptography, protocol design, infrastructure hygiene, and operational security. Through real-world case studies, we will walk through malware that used blockchain-based C2 with weak encryption, allowing historic commands to be recovered from public on-chain data, and a separate campaign where expired attacker infrastructure enabled sinkholing, victim telemetry collection, and safe reimplementation of server-side C2 behavior for analysis.

Rather than treating C2 as a black box, this talk shows how reverse engineering, infrastructure hunting, emulation, and creative defensive thinking can provide intelligence collection opportunities.


Command & Control is usually discussed from the attacker’s perspective: how operators maintain access, issue commands, evade takedown, and keep infrastructure alive. This talk flips that view. Instead of asking how adversaries control malware, we ask: where does that control break?

We will highlight case-studies from Ctrl-Alt-Intel research where Command & Control implementations were vulnerable. The first case study focuses on Aeternum Loader, a malware family using Polygon smart contracts as C2 infrastructure. Blockchain-based C2 appears attractive to threat actors because it is decentralised, resilient, and difficult to remove. But immutability cuts both ways. In this case, weak encryption design meant that once the smart contract address was known, historic encrypted commands could be recovered and decrypted, turning the attacker’s “forever C2” into a permanent forensic record.

The second case study focuses on KazakRAT, a lightweight Windows RAT observed in long-running activity against Kazakh and Afghan-themed targets. Its C2 protocol was simple, unencrypted HTTP. An operational lapse left a C2 domain available for registration, enabling defensive sinkholing and passive visibility into beaconing victims. From there, the protocol could be understood, emulated, and safely reimplemented in a controlled lab.

Ben

Ben Folland is a volunteer researcher at Ctrl-Alt-Intel, where they investigate cybercrime and
espionage operations, track threat actor infrastructure, analyze TTPs, and expose threat actors.
His professional work has included stopping Akira affiliates, responding to Qilin, and Space Bear
ransomware incidents, investigating Storm-2603 activity linked to Warlock ransomware, tracking
Chinese adversaries targeting IIS servers for SEO fraud, and hunting DPRK malware used in
supply-chain attacks.

They are passionate about DFIR, threat hunting, CTI, malware analysis, and OSINT, and
regularly write about security research at Ctrl-Alt-Intel. They have previously spoken on the main
stage at DEF CON, as well as hack.lu, Malware Village, DC441905, and multiple BSides events.