Your credentials were leaked, so what?
Everyday, our mailboxes are flooded with phishing emails that impersonate well-know brands or make the victim uncomfortable (hack, data-leak, risk of data loss, ...). Hopefully, most of us just delete them but... what happens with the credentials you left by mistake on a fake login page? We developed a tool that is an advanced honeypot. First, our bot will visit the fake pages and fill forms with randomly-generated credentials. Then, we will track them expecting them to be used by threat actors against our honeypots (portal, VPN, RDP, VNC, etc). Because credentials are unique, we can link them to threat acts and track them. The presentation will be contain a presentation of the research, the tool we build and of course some statistics gathered from our huge list of malicious URLs!
Speaker


Xavier Mertens
Malware Enthusiast
Xavier Mertens is a freelance security consultant running his own company based in Belgium (Xameco). With 20+ years of experience in information security, Xavier finds “blue team” activities more attractive. Therefore, his day job focuses on protecting his customers' assets by providing services like incident handling, malware analysis, forensic investigations, log management, security visualization, and OSINT). Besides his day job, Xavier is also a Senior Handler at the SANS Internet Storm Cent... read more