Loading…
Botconf 2017 has ended
Back To Schedule
Friday, December 8 • 10:10 - 10:40
PWS, Common, Ugly but Effective

Log in to save this to your schedule, view media, leave feedback and see who's attending!

PassWord Stealer (PWS) are around since more than a decade now. They are legions. Some like Pony, aka FareIT are well known. But nobody takes really time to explain what is around, what it is capable of and how this little industry works.

However, they are still a common threat actively used according to our incidents logs.
A PWS is not a RAT we made this distinction. The aim of a PWS is to be launched, steal a lot of credentials and optionally keylog and/or drop another payload.

Sadly nobody cares about them anymore when they fire an antivirus inside a company.
To illustrate this, my presentation will go thought a couple of PWS that I meet, and I will an overview of the history and capabilities of the threat, give tricks and tools/script needed to identify and decipher them. A couple of these decoding/identification tools are freely available to the community and not written by me, this task may be achieved by a lot of security people without even any skills in reverse engineering.

Finally I will try to summarize these threats by giving to the participants a clear view of what is available in the field.

Speakers
avatar for Paul Jung

Paul Jung

Senior security consultant, Excellium Services
Paul Jung is since a long time a security enthusiast. He works in the security field in Luxembourg since more than a decade. During this time, Paul has covered operations as well as consulting within various industries. He possesses a wide range of skills and experiences that enable... Read More →


Friday December 8, 2017 10:10 - 10:40 CET
Corum