BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//bsides-tallinn-2026//speaker//LMC9QL
BEGIN:VTIMEZONE
TZID:Europe/Helsinki
BEGIN:DAYLIGHT
DTSTART:20250925T000000
TZNAME:EEST
TZOFFSETFROM:+0300
TZOFFSETTO:+0300
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T040000
RDATE:20261025T040000
TZNAME:EET
TZOFFSETFROM:+0300
TZOFFSETTO:+0200
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T040000
RDATE:20270328T040000
TZNAME:EEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0300
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Iranopasmigirim - Unmasking an ever-evolving GitHub-Hosted Espiona
 ge Campaign Against Iranian Dissidents - Evgen Blohm
DTSTART;TZID=Europe/Helsinki:20260925T130000
DTEND;TZID=Europe/Helsinki:20260925T134500
DTSTAMP:20260926T112158Z
UID:pretalx-bsides-tallinn-2026-CDEHNZ@pretalx.com
DESCRIPTION:What began as routine triage of low-detection malware from Mal
 wareBazaar quickly revealed a full-fledged campaign targeting dissidents\,
  using Custom-built tooling with no meaningful overlap with known malware 
 families\, pointing to a dedicated\, well-resourced developer rather than 
 a repurposed off-the-shelf toolkit.\n\nThis talk walks through the investi
 gation from that first sample to a fuller picture of the Threat Actor\, wh
 ich has focused on espionage-motivated targeting connected to Iran. We det
 ail the malware's architecture and capabilities\, and show how pivoting on
  code artefacts\, unique behavioural fingerprints\, and network indicators
  allowed us to cluster additional\, previously unattributed samples under 
 the same actor. \n\nThis talk shows the ever-changing TTPs and Malware bei
 ng used\, from C++-based malware\, over Nim and Go\, to finally Rust. \n\n
 Attendees will leave with a concrete case study in threat actor discovery 
 starting from minimal initial evidence\, practical pivoting techniques for
  connecting sparse indicators into a coherent cluster\, and a set of detec
 tion opportunities and indicators for identifying this activity. This talk
  is aimed at a broad security audience and requires no prior familiarity w
 ith the actor\, offering both a compelling investigative narrative and act
 ionable takeaways for threat hunters\, analysts\, and defenders alike.
LOCATION:Stage A
URL:https://pretalx.com/bsides-tallinn-2026/talk/CDEHNZ/
END:VEVENT
END:VCALENDAR
