{"id":66207,"global_id":"www.secuinfra.com\/en\/?id=66207","global_id_lineage":["www.secuinfra.com\/en\/?id=66207"],"author":"33","status":"publish","date":"2026-08-26 12:17:21","date_utc":"2026-08-26 10:17:21","modified":"2026-08-26 12:17:21","modified_utc":"2026-08-26 10:17:21","url":"https:\/\/www.secuinfra.com\/en\/event\/bsides-berlin-2026\/","rest_url":"https:\/\/www.secuinfra.com\/en\/wp-json\/tribe\/events\/v1\/events\/66207","title":"BSides Berlin 2026","description":"<p>What does a real APT attack look like when you don\u2019t just consider it theoretically, but analyze it yourself step by step? At <strong>BSides Berlin 2026<\/strong>, we\u2019ll do just that: In our interactive, hands-on workshop <strong>\u201cA Phishing Trip with Fancy Bear \u2013 Let\u2019s Analyze APT Malware Together!\u201d<\/strong> we\u2019ll take participants on a technical journey through <strong>Fancy Bear<\/strong> \u2019s <strong>(APT28\/GRU)<\/strong> attack chain\u2014from the initial phishing attempt to command-and-control communication. <\/p>\n<p>Using real-world artifacts, we\u2019ll work together to examine phishing email headers, a rigged RTF document, malware samples, and a C2 implant. A custom-developed interactive training platform guides you through five sequential chapters: <strong>Threat Actor Background, Payload Delivery, Exploitation, Persistence &#038; Installation, and Command &#038; Control<\/strong>. Integrated analysis exercises and quiz questions make insights and progress immediately visible\u2014practical, easy to follow, and suitable even for beginners in APT analysis.  <\/p>\n<p>Technically, we go into great detail: We extract Indicators of Compromise from email headers, analyze tampered Office documents and MIME type mismatches, examine the misuse of <strong>OLE\/COM objects in connection with CVE-2026-21509<\/strong>, and track persistence techniques ranging from file staging and scheduled tasks to <strong>LSB steganography in PNG files<\/strong>. Using <strong>CyberChef<\/strong>, we decrypt simple XOR and Base64 obfuscation and use the <strong>Covenant C2 framework<\/strong> as an example to demonstrate how attackers exploit legitimate open-source tools and trusted cloud services for their operations, thereby blending into seemingly normal network traffic. <\/p>\n<p>All of the tools used and demonstrated in the workshop\u2014including <strong>oletools, CyberChef, and Covenant<\/strong> \u2014are free and open source. This means the analysis methods presented can be directly applied in your own security practice. The workshop offers a tangible look at the traces left behind by modern APT campaigns\u2014and how these can be systematically investigated\u2014especially for organizations looking to further develop their detection and response capabilities.  <\/p>\n<p>We look forward to helping shape BSides Berlin 2026 and, together with the community, delving deeply into the analysis of a sophisticated APT attack.<\/p>","excerpt":"","slug":"bsides-berlin-2026","image":{"url":"https:\/\/www.secuinfra.com\/wp-content\/uploads\/MKA-108-VA-Header-Linkedin-Creative-Bsides-MUC-BER.png","id":66206,"extension":"png","width":1080,"height":600,"filesize":608702,"sizes":{"medium":{"width":800,"height":444,"mime-type":"image\/png","filesize":280872,"url":"https:\/\/www.secuinfra.com\/wp-content\/uploads\/MKA-108-VA-Header-Linkedin-Creative-Bsides-MUC-BER-800x444.png"},"thumbnail":{"width":300,"height":300,"mime-type":"image\/png","filesize":89018,"url":"https:\/\/www.secuinfra.com\/wp-content\/uploads\/MKA-108-VA-Header-Linkedin-Creative-Bsides-MUC-BER-300x300.png"},"medium_large":{"width":768,"height":427,"mime-type":"image\/png","filesize":264243,"url":"https:\/\/www.secuinfra.com\/wp-content\/uploads\/MKA-108-VA-Header-Linkedin-Creative-Bsides-MUC-BER-768x427.png"}}},"all_day":true,"start_date":"2026-11-12 00:00:00","start_date_details":{"year":"2026","month":"11","day":"12","hour":"00","minutes":"00","seconds":"00"},"end_date":"2026-11-12 23:59:59","end_date_details":{"year":"2026","month":"11","day":"12","hour":"23","minutes":"59","seconds":"59"},"utc_start_date":"2026-11-11 23:00:00","utc_start_date_details":{"year":"2026","month":"11","day":"11","hour":"23","minutes":"00","seconds":"00"},"utc_end_date":"2026-11-12 22:59:59","utc_end_date_details":{"year":"2026","month":"11","day":"12","hour":"22","minutes":"59","seconds":"59"},"timezone":"Europe\/Berlin","timezone_abbr":"CET","cost":"","cost_details":{"currency_symbol":"\u20ac","currency_code":"","currency_position":"","values":[]},"website":"https:\/\/bsides.berlin\/","show_map":false,"show_map_link":false,"hide_from_listings":false,"sticky":false,"featured":false,"categories":[],"tags":[],"venue":[],"organizer":[{"id":58473,"author":"33","status":"publish","date":"2025-05-14 14:45:29","date_utc":"2025-05-14 12:45:29","modified":"2025-05-14 14:45:29","modified_utc":"2025-05-14 12:45:29","url":"https:\/\/www.secuinfra.com\/de\/organizer\/bsides\/","organizer":"BSides","slug":"bsides","json_ld":{"@type":"Person","name":"BSides","description":"","url":"","telephone":"","email":"","sameAs":""},"global_id":"www.secuinfra.com\/en\/?id=58473","global_id_lineage":["www.secuinfra.com\/en\/?id=58473"]}],"custom_fields":[],"json_ld":{"@context":"http:\/\/schema.org","@type":"Event","name":"BSides Berlin 2026","description":"&lt;p&gt;What does a real APT attack look like when you don\u2019t just consider it theoretically, but analyze it yourself step by step? At BSides Berlin 2026, we\u2019ll do just that: [&hellip;]&lt;\/p&gt;\\n","image":"https:\/\/www.secuinfra.com\/wp-content\/uploads\/MKA-108-VA-Header-Linkedin-Creative-Bsides-MUC-BER.png","url":"https:\/\/www.secuinfra.com\/en\/event\/bsides-berlin-2026\/","eventAttendanceMode":"https:\/\/schema.org\/OfflineEventAttendanceMode","eventStatus":"https:\/\/schema.org\/EventScheduled","startDate":"2026-11-12T00:00:00+01:00","endDate":"2026-11-12T23:59:59+01:00","organizer":{"@type":"Person","name":"BSides","description":"","url":"","telephone":"","email":"","sameAs":""},"performer":"Organization"}}