Spycraft 2.0: Hunting Dead Drops in Web Applications

Jonathan Fuller

BSides NYC 2025 (0x05) · Day 1 · Tech - Blue

In "Spycraft 2.0: Hunting Dead Drops in Web Applications," Jonathan Fuller, CISO at the United States Military Academy and an assistant professor specializing in forensics and malware analysis, delves into cutting-edge techniques for disrupting botnets by turning adversaries' own code against them. The talk addresses the persistent challenge of botnet takedowns, which often resemble a "beheading a hydra" scenario, with new command and control (C2) infrastructure quickly emerging after disruptions. Fuller introduces a novel, proactive approach that leverages an understanding of malware's internal logic to identify and neutralize C2 mechanisms, particularly the emerging threat of **Dead Drop Resolvers (DDRs)**.

AI review

Fuller brings a legitimate research contribution: a concolic analysis framework for extracting de-manipulation recipes from Dead Drop Resolver malware, backed by a 100K-sample study with concrete numbers — 9% DDR prevalence, 25% blockchain-based C2, 57% detection improvement, 80% remediation success. The work is original, the methodology is reproducible, and the blockchain sinkholing angle alone is worth the slot.

Watch on YouTube