Repurposing OnionDuke: A Single Case Study Around Reusing Nation State Malware

Black Hat USA 2015

Presented by: Joshua Pitts
Date: Thursday August 06, 2015
Time: 09:45 - 10:35
Location: Mandalay Bay BCD

The news media is awash with nation-states and criminals reusing malware. Why should they have all the fun? This is a case study about reversing the suspected Russian government made OnionDuke MitM patching system, discovered by the speaker in October 2014. During this talk we will seek to understand its inner workings, selecting desirable features, and repurposing it for use in other tools. This is pure malware plagiarism.

Joshua Pitts

Joshua Pitts works as pentester and reverse engineer. He began his IT career while serving the Marines working in Signals Intelligence and IT security in the mid to late 90's. He has audited and penetration tested numerous clients in both the commercial and government sectors. Josh the author of 'The Backdoor Factory' (BDF) and BDFProxy open source projects.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats