BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.bsidescbr.com.au//bsides-canberra-2026//speaker//Z7
 3MCN
BEGIN:VTIMEZONE
TZID:Australia/Sydney
BEGIN:STANDARD
DTSTART:20250924T000000
TZNAME:AEST
TZOFFSETFROM:+1000
TZOFFSETTO:+1000
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20251005T030000
RDATE:20261004T030000
TZNAME:AEDT
TZOFFSETFROM:+1000
TZOFFSETTO:+1100
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20260405T030000
RDATE:20270404T030000
TZNAME:AEST
TZOFFSETFROM:+1100
TZOFFSETTO:+1000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Tearing Down a DPRK-Linked macOS Crypto Stealer - Tonmoy Jitu
DTSTART;TZID=Australia/Sydney:20260924T143000
DTEND;TZID=Australia/Sydney:20260924T150500
DTSTAMP:20260807T131623Z
UID:pretalx-bsides-canberra-2026-BPDAWE@cfp.bsidescbr.com.au
DESCRIPTION:This talk presents a technical analysis of a multi-stage macOS
  attack chain attributed with moderate-high confidence to the Lazarus/Blue
 Noroff cluster\, targeting cryptocurrency users across a broad range of bl
 ockchain ecosystems.\n\nThe sample is notable for a few reasons. The deliv
 ery mechanism is deliberately designed to sidestep macOS Gatekeeper withou
 t relying on stolen certificates or notarization bypasses. The credential 
 theft component demonstrates detailed knowledge of Chromium internals acro
 ss all three major platforms. And an operational security failure on the s
 erver side left the C2's full API schema publicly accessible\, providing a
 n unusually complete picture of the operator workflow without requiring an
 y server-side access.\n\nThe talk covers the full attack chain from droppe
 r to exfiltration\, the tradecraft decisions that make this campaign effec
 tive against modern macOS defences\, infrastructure attribution\, and dete
 ction opportunities for defenders.
LOCATION:Off-Main Track
URL:https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/BPDAWE/
END:VEVENT
END:VCALENDAR
