{"id":66089,"date":"2026-08-12T12:47:18","date_gmt":"2026-08-12T10:47:18","guid":{"rendered":"https:\/\/www.secuinfra.com\/event\/bsides-frankfurt-2026\/"},"modified":"2026-08-12T12:50:15","modified_gmt":"2026-08-12T10:50:15","slug":"bsides-frankfurt-2026","status":"publish","type":"tribe_events","link":"https:\/\/www.secuinfra.com\/en\/event\/bsides-frankfurt-2026\/","title":{"rendered":"BSides Frankfurt 2026"},"content":{"rendered":"<p>On  <strong>September 10 and 11, 2026 <\/strong> <strong>BSides Frankfurt<\/strong> brings together the cybersecurity community at Goethe University Frankfurt. The community conference is known for its technical depth, open exchange of knowledge, and practical security insights, and we\u2019ll be there with our own hands-on workshop. <\/p>\n<h3>A Phishing Trip with Fancy Bear \u2013 Let&#8217;s Analyze APT Malware Together!<\/h3>\n<p><strong>Friday, September 11, 2026 | 2:00 p.m. | Room 1<\/strong><\/p>\n<p>How does a targeted phishing attack unfold, from the initial contact to active command-and-control communication? In Marius Genheimer\u2019s beginner-friendly, hands-on workshop, participants will trace the entire attack chain of a realistic <strong>Fancy Bear campaign (APT28\/GRU)<\/strong> \u2014step by step and using real artifacts. <\/p>\n<p>Using a custom-developed interactive training platform <strong>,<\/strong> we work together to analyze <strong>phishing email headers, a weaponized RTF document, malware samples, and a C2 implant<\/strong>. Five chapters that build on one another cover everything from the threat actor\u2019s background to payload delivery, exploitation, and persistence, all the way through to installation and command &#038; control. Integrated quizzes immediately highlight progress in analysis and ensure that even complex attack techniques remain easy to understand.  <\/p>\n<p>In this technical deep dive, we\u2019ll show you, among other things, how to <strong>extract Indicators of Compromise from email headers<\/strong>, detect tampered Office documents and <strong>MIME type mismatches<\/strong>, and investigate <strong>OLE\/COM object abuse related to CVE-2026-21509<\/strong>. We\u2019ll analyze persistence techniques such as <strong>file staging and scheduled task abuse<\/strong>, uncover <strong>LSB steganography in PNG files<\/strong>, and decrypt simple <strong>XOR and Base64 obfuscation using CyberChef<\/strong>. <\/p>\n<p>In addition, we take a look at how professional threat actors misuse legitimate open-source technologies, such as the <strong>Covenant C2 Framework<\/strong>, and leverage trusted cloud services to conceal malicious communications within normal network traffic. For security professionals in particular, this analysis provides a very concrete illustration of the challenges modern cyber defense teams face in detecting sophisticated attacks. <\/p>\n<p>Best of all: The tools used and demonstrated in the workshop\u2014including <strong>oletools, CyberChef, and Covenant<\/strong> \u2014are free and open source. This means the analysis methods shown can be immediately understood, replicated, and applied to your own security practices. <\/p>\n<p>Wir freuen uns auf Sie.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On September 10 and 11, 2026 BSides Frankfurt brings together the cybersecurity community at Goethe University Frankfurt. The community conference is known for its technical depth, open exchange of knowledge, [&hellip;]<\/p>\n","protected":false},"author":33,"featured_media":66088,"template":"","meta":{"_acf_changed":false,"_tribe_events_status":"","_tribe_events_status_reason":"","dpc_author_order":[],"footnotes":""},"tags":[],"tribe_events_cat":[],"class_list":["post-66089","tribe_events","type-tribe_events","status-publish","has-post-thumbnail","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/tribe_events\/66089","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/tribe_events"}],"about":[{"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/types\/tribe_events"}],"author":[{"embeddable":true,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/users\/33"}],"version-history":[{"count":1,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/tribe_events\/66089\/revisions"}],"predecessor-version":[{"id":66092,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/tribe_events\/66089\/revisions\/66092"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/media\/66088"}],"wp:attachment":[{"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/media?parent=66089"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/tags?post=66089"},{"taxonomy":"tribe_events_cat","embeddable":true,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/tribe_events_cat?post=66089"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}