Vangelis Stykas: Hacking Malware Command-and-Control Servers
A DEF CON 31 talk on compromising command-and-control (C2) servers used by malware. After malware campaigns end, these servers are often left exposed and poorly secured.
The researcher shows that many C2 servers are vulnerable to common web attacks. By exploiting typical web application flaws, it’s possible to access admin panels, control infected devices, analyze malware source code, and even uncover the identities of operators and organizations behind the attacks.
The researcher shows that many C2 servers are vulnerable to common web attacks. By exploiting typical web application flaws, it’s possible to access admin panels, control infected devices, analyze malware source code, and even uncover the identities of operators and organizations behind the attacks.