{"id":66207,"date":"2026-08-26T12:17:21","date_gmt":"2026-08-26T10:17:21","guid":{"rendered":"https:\/\/www.secuinfra.com\/event\/bsides-berlin-2026\/"},"modified":"2026-08-26T12:17:21","modified_gmt":"2026-08-26T10:17:21","slug":"bsides-berlin-2026","status":"publish","type":"tribe_events","link":"https:\/\/www.secuinfra.com\/en\/event\/bsides-berlin-2026\/","title":{"rendered":"BSides Berlin 2026"},"content":{"rendered":"<p>What does a real APT attack look like when you don\u2019t just consider it theoretically, but analyze it yourself step by step? At <strong>BSides Berlin 2026<\/strong>, we\u2019ll do just that: In our interactive, hands-on workshop <strong>\u201cA Phishing Trip with Fancy Bear \u2013 Let\u2019s Analyze APT Malware Together!\u201d<\/strong> we\u2019ll take participants on a technical journey through <strong>Fancy Bear<\/strong> \u2019s <strong>(APT28\/GRU)<\/strong> attack chain\u2014from the initial phishing attempt to command-and-control communication. <\/p>\n<p>Using real-world artifacts, we\u2019ll work together to examine phishing email headers, a rigged RTF document, malware samples, and a C2 implant. A custom-developed interactive training platform guides you through five sequential chapters: <strong>Threat Actor Background, Payload Delivery, Exploitation, Persistence &#038; Installation, and Command &#038; Control<\/strong>. Integrated analysis exercises and quiz questions make insights and progress immediately visible\u2014practical, easy to follow, and suitable even for beginners in APT analysis.  <\/p>\n<p>Technically, we go into great detail: We extract Indicators of Compromise from email headers, analyze tampered Office documents and MIME type mismatches, examine the misuse of <strong>OLE\/COM objects in connection with CVE-2026-21509<\/strong>, and track persistence techniques ranging from file staging and scheduled tasks to <strong>LSB steganography in PNG files<\/strong>. Using <strong>CyberChef<\/strong>, we decrypt simple XOR and Base64 obfuscation and use the <strong>Covenant C2 framework<\/strong> as an example to demonstrate how attackers exploit legitimate open-source tools and trusted cloud services for their operations, thereby blending into seemingly normal network traffic. <\/p>\n<p>All of the tools used and demonstrated in the workshop\u2014including <strong>oletools, CyberChef, and Covenant<\/strong> \u2014are free and open source. This means the analysis methods presented can be directly applied in your own security practice. The workshop offers a tangible look at the traces left behind by modern APT campaigns\u2014and how these can be systematically investigated\u2014especially for organizations looking to further develop their detection and response capabilities.  <\/p>\n<p>We look forward to helping shape BSides Berlin 2026 and, together with the community, delving deeply into the analysis of a sophisticated APT attack.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What does a real APT attack look like when you don\u2019t just consider it theoretically, but analyze it yourself step by step? At BSides Berlin 2026, we\u2019ll do just that: [&hellip;]<\/p>\n","protected":false},"author":33,"featured_media":66206,"template":"","meta":{"_acf_changed":false,"_tribe_events_status":"","_tribe_events_status_reason":"","dpc_author_order":[],"footnotes":""},"tags":[],"tribe_events_cat":[],"class_list":["post-66207","tribe_events","type-tribe_events","status-publish","has-post-thumbnail","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/tribe_events\/66207","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/tribe_events"}],"about":[{"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/types\/tribe_events"}],"author":[{"embeddable":true,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/users\/33"}],"version-history":[{"count":0,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/tribe_events\/66207\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/media\/66206"}],"wp:attachment":[{"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/media?parent=66207"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/tags?post=66207"},{"taxonomy":"tribe_events_cat","embeddable":true,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/tribe_events_cat?post=66207"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}