BSides Munich 2026

On November 7, 2026, Munich will become the gathering place for the cybersecurity community: At BSides Munich 2026, we at SECUINFRA will take current cyber threats from theory and put them directly into practice. In our interactive, hands-on workshop “A Phishing Trip with Fancy Bear – Let’s Analyze APT Malware Together!” we’ll take participants on a journey through the entire attack chain of a real Fancy Bear campaign (APT28/GRU)—from the first phishing email to command-and-control communication.
In five chapters that build on one another, we will examine real-world artifacts together and demonstrate how modern APT attacks work from a technical perspective and how they can be systematically analyzed. The agenda includes, among other things, the analysis of email headers and indicators of compromise, the examination of a weaponized RTF document—including MIME type mismatches and OLE/COM abuse to exploit CVE-2026-21509— persistence via file staging and scheduled tasks, as well as LSB steganography in PNG files. In addition, we will decrypt simple XOR and Base64 obfuscation using CyberChef and demonstrate how attackers abuse legitimate open-source tools such as the Covenant C2 Framework and trusted cloud services to conceal their activities within normal network traffic.
A custom-developed interactive training platform guides participants through each step of an attack, makes progress in the analysis immediately visible, and allows participants to directly test their own insights using targeted questions. The workshop is beginner-friendly and consistently hands-on. All tools used—including oletools, CyberChef, and Covenant—are free and open source. This means the analysis techniques demonstrated can be immediately replicated after the event and applied to your own security practices.
For us, effective cyber defense means not only being aware of attacks, but truly understanding their mechanisms. This is exactly the kind of understanding we want to convey at BSides Munich 2026 —practical, technically sound, and based on a threat actor that vividly demonstrates the challenges modern security teams must face.
We’re looking forward to BSides Munich 2026 and to taking a closer look at Fancy Bear together with the community.
