Tangling With Malware Adversaries: A Few Short War Stories

No ratings

Presented at BSidesVancouver 2019 by

The anti-malware industry is a game of cat and mouse between the attackers who are constantly innovating new malware techniques and us security researchers who try to stop them. In this talk I'll present a few interesting short stories from my time at Windows Defender battling these attackers. First, I'll talk about the discovery of a botnet known as Sefnit that nearly took down the Tor network in 2013, and the subsequent investigations that accidentally led to an in-person meeting with one of the malware authors, and how this led to the demise of the botnet. Secondly, I'll talk about battling a stealthy click-fraud malware that was always one-step ahead of the AV detection signatures I was authoring to remove them from infected machines.