Dropbots: Command & Control using Cloud Storage

BSides SATX 2018

Presented by: Mitchell Moser
Date: Saturday June 16, 2018
Time: 09:30 - 10:00
Location: Moody 102
Track: Track 1 In The Beginning

Command & Control infrastructure is commonly thought of as spun up servers using newly found or known-bad domains and IP addresses. But what about common cloud storage services being used for such purposes? We'll look at some real-world examples of APTs using this technique in the wild. We'll demo an open source tool that uses Dropbox as a Command & Control server and observe the network activity associated with this communication.

Mitchell Moser

I am a Senior at UTSA double majoring in Cyber Security and Information Systems, intern on Frost Bank's Security Monitoring & Incident Response team, Captain of UTSA's CCDC Red Team with an interest in offensive security.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats