UNO Reverse Card: Exposing C2 Operators Through Their Own Logs

Estelle Ruellan (Threat Intelligence Researcher · Flare)

NorthSec 2025 · Day 1 · Salle de bal · Conference

Overview

Flare CTI analyst Estelle Ruellan presented a structured analysis of infostealer logs in which the infected devices belonged not to ordinary victims, but to the criminals operating the C2 infrastructure. Through four case studies — two with weak OPSEC ("NoobSecs") and two with sophisticated countermeasures ("skip tracer's nightmares") — the talk demonstrates how stealer log analysis can reverse-attribute threat actor identity, infrastructure, and tactics. The talk doubles as a sardonic OPSEC primer delivered as a classroom lecture. ---

Watch on YouTube

Visual summary for UNO Reverse Card: Exposing C2 Operators Through Their Own Logs by Estelle Ruellan
Visual summary for UNO Reverse Card: Exposing C2 Operators Through Their Own Logs by Estelle Ruellan

Key moments

  1. 3:09 C2 operator infected by own malware, revealing real identity
  2. 7:00 Criminal used same credentials across 300 corporate instances
  3. 14:10 File pumping evades AV scanning on BitBucket payloads
  4. 13:29 Threat actor used 'Windows' as password for all encrypted ZIPs
  5. 14:59 192 domains tied to CryptBot; 25 new C2 instances discovered
  6. 17:51 4-stage malware chain: loader, stealer, infostealer, backdoor
  7. 8:40 Sophisticated operators use dedicated devices per criminal role
  8. 13:10 Threat actor stored passwords in Notepad, linking to C2 repos

UNO Reverse Card: Exposing C2 Operators Through Their Own Logs

Speaker: Estelle Ruellan — Flare

Conference: NorthSec 2025 — May 15–16, 2025, Marché Bonsecours, Montreal

Watch on YouTube: https://www.youtube.com/watch?v=y4mPoN3Z2Yk

Reading time: ~7 minutes

TL;DR

Flare CTI analyst Estelle Ruellan presented a structured analysis of infostealer logs in which the infected devices belonged not to ordinary victims, but to the criminals operating the C2 infrastructure. Through four case studies — two with weak OPSEC ("NoobSecs") and two with sophisticated countermeasures ("skip tracer's nightmares") — the talk demonstrates how stealer log analysis can reverse-attribute threat actor identity, infrastructure, and tactics. The talk doubles as a sardonic OPSEC primer delivered as a classroom lecture.

Introduction

Infostealers are commodity malware distributed primarily through cracked software and malvertising campaigns. After execution on a victim's device, they collect credentials, browser data, cookies, and crypto wallets, then exfiltrate the entire package to a C2 server. The resulting "stealer logs" are packaged and sold — or leaked — across Telegram channels and underground forums. This data feeds fraud, account takeovers, and ransomware pre-positioning operations.

Flare's Estelle Ruellan turned this analysis pipeline on a population that is rarely examined: the C2 operators themselves. Her research found that infostealer operators frequently fall victim to the same class of malware they deploy, most often by downloading laced tools — checkers, cracked software — from the same underground ecosystems they participate in. The resulting logs expose their real devices, credentials, infrastructure accesses, and sometimes their actual identities.

The talk was structured as an OPSEC class for "first-year threat actors," using four real case studies drawn from Flare's log analysis pipeline. Each case illustrates a different level of tradecraft and a different set of failures.

▶ Watch: Introduction and infostealer mechanics (0:00)

The NoobSecs: Poor OPSEC, Rapid Attribution

Quinn — Gaming and Social Media Account Hijacker

Quinn's device was infected by RedLine after he downloaded a credential checker from a cybercrime forum — a tool used to test stolen credentials at scale and identify valid accounts. His log contained access to four cybercrime forums, ten stressor services, and ten suspicious IPs. Browser data revealed unauthorized access to Snapchat, Epic Games, and Steam accounts.

From the log, Ruellan's team extracted his government name, date of birth, home address, driving school enrollment, social media profiles, GitHub account, and several other personal identifiers. The breadth of personal data in a single log record underscores how thoroughly infostealers capture a device's browsing and autofill history.

The lesson Ruellan drew: "Infostealers do not discriminate. Even if you operate some kind of malware, if your OPSEC is not on point, you will get infected."

▶ Watch: Quinn case study (2:00)

Yu — Corporate Developer with Dual-Use Device

Yu, located in Hong Kong, was infected by the Meta infostealer via a LinkedIn checker. He had accessed a RicePro C2 IP with two credential sets and several Instagram accounts belonging to third parties — a Korean company, a French student, an Indian immigration firm — along with a PayScale panel from a South African company, suggesting credential harvesting across unrelated targets.

The more significant finding was on his machine: an extensive corporate software environment consistent with a developer workstation at a Beijing-based technology company. The log contained an email address matching the company's public domain and administrative access to more than 150 private subdomains and more than 140 internal subnet IPs — all authenticated with just three credential sets.

"He used the same corporate-issued device for shady and corporate business," Ruellan noted. "As if that was not enough, he used the same credentials for both." The case demonstrates why credential reuse across corporate and criminal operations is catastrophically self-exposing when the device is compromised.

▶ Watch: Yu case study (4:00)

The Skip Tracer's Nightmares: Sophisticated OPSEC, Still Cracked

The second category — subjects Ruellan called "skip tracer's nightmares" — used deliberate identity obfuscation. Where NoobSecs had hundreds of mixed personal and criminal credentials, these subjects had 30–50 credentials, all restricted to malicious or suspicious infrastructure. They used dedicated devices, separating criminal activity from personal browsing. Attribution required substantially more analytical effort.

Menya — The Traffer

Menya's device appeared to be based in Germany but ran on the Moscow timezone, suggesting Eastern European origin. His autofill data contained three US addresses — Oregon, New Hampshire, and Florida — but none resolved to an active resident; two were properties that had been on the market for years, and one address was entirely fabricated. Autofill payment names included Ryan Gosling, Morgan Freeman, and Jimmy Carter.

Despite these obfuscation layers, Menya's activity logs pointed to a live BitBucket repository containing 81 unique filenames distributed across more than 600 media file URLs, 47 BitBucket repos, and 12 Dropboxes. The repository owner matched a username found in Menya's autofills. Across those BitBucket repositories, the files had accumulated more than 12,000 downloads.

The files were password-protected, and Menya appeared to use a password manager — but investigators found a Notepad file with a name matching the Russian word for "ID and documents." Its contents held the archive passwords. The first entry from a standard 12,000-entry wordlist cracked every zip: Windows. Inside, one executable was already identified on VirusTotal; the other was not — because it had been artificially inflated in size to prevent automated antivirus scanning at upload, a technique known as file pumping.

Domain access patterns linked Menya to more than 500 domains, 192 of which matched known CryptBot infrastructure. Additional accesses to ad services, video platform management panels, and user behavior analytics tools indicated Menya's role as a traffer — an operator who drives traffic to malicious content through malvertising and cracked software distribution rather than directly operating the malware.

▶ Watch: Menya case study and traffer profile (10:00)

Xhisa — The Multi-Malware Ecosystem Operator

Xhisa's log contained access to Raccoon infostealer admin panels — specifically the /logs and /regs endpoints used to view data from infected victims, which are not publicly accessible. This placed him unambiguously as a Raccoon operator rather than merely a buyer of logs. Admin credentials recovered from the log matched IPs associated with three additional malware families: Mystic stealer, PrivateLoader, and the Asuka Trojan. Each IP contained a hashed component in its path, consistent with C2 panel naming conventions that hash victim identifiers for internal tracking.

Xhisa was therefore operating at least four concurrent malware families at once: a stealer (Raccoon), another stealer (Mystic), a loader (PrivateLoader), and a remote access trojan (Asuka). This structure represents the high end of the infostealer ecosystem — a vertically integrated criminal operation using a loader to deliver additional payloads, extracting credentials and system information while maintaining persistent access.

▶ Watch: Xhisa multi-malware ecosystem (16:00)

OPSEC Lessons Extracted

Ruellan structured her findings as six explicit OPSEC lessons, presented as classroom instruction for the fictional "first-year threat actor":

  1. No one is safe. Infostealers do not discriminate against operators of other malware.
  2. OPSEC is not included with the malware toolkit. Acquiring a credential checker does not confer immunity to the same distribution vector.
  3. Do not cross the streams. Use separate physical devices for criminal and legitimate activity.
  4. Dedicated devices are the new gloves. A dedicated device limits the scope of exposure when compromised.
  5. Hide well; mislead first. Effective obfuscation requires plausible false trails, not just the absence of real data.
  6. Use a password manager — actually use it. Storing passwords in a Notepad text file labeled "ID and documents" is not equivalent.

▶ Watch: OPSEC lessons summary (8:00)

Notable Quotes

"Infostealers do not discriminate, so even if you operate some kind of malware, if your OPSEC is not on point, you will get infected and thus handed your Uno Reverse card." — Estelle Ruellan

"He had admin access to more than a hundred and fifty private domains of the company and more than a hundred and forty admin accesses through private and subnet IPs. However, we only find three sets of credentials across those three hundred corporate and private domains." — Estelle Ruellan

"Do not put your passwords in a Notepad. Menya, you disappointed us — you made us believe you use a password manager, and then we find a Notepad with the passwords." — Estelle Ruellan

Key Takeaways

  1. Stealer logs contain attributable intelligence on operators. When a threat actor's device is compromised, the resulting log can expose C2 admin panel access, criminal forum memberships, and operational infrastructure in a single artifact.
  1. Credential checkers and cracked tools are a primary infection vector for criminals. Downloading tools from underground forums to test stolen credentials is itself a common source of infostealer infection — a feedback loop that consistently exposes threat actors.
  1. Credential reuse between criminal and corporate environments is catastrophic. A single compromised device used for both purposes can expose an entire corporate network's internal architecture, especially if the same credentials authenticate to both.
  1. File pumping is an active AV evasion technique. Inflating file sizes beyond automated scanning thresholds on platforms like VirusTotal delays detection windows, allowing freshly generated malware payloads to remain undetected for extended periods.
  1. Multi-malware ecosystem operators are the high-value targets. Subjects operating stealers, loaders, and RATs simultaneously represent the most capable actors in the infostealer ecosystem — and their OPSEC failures, when they occur, expose correspondingly more infrastructure.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Flare CTI analyst Estelle Ruellan demonstrates how infostealer logs collected from threat actors' own compromised devices enable threat actor attribution, infrastructure mapping, and identity disclosure. Four case studies — two weak OPSEC (NoobSecs) and two sophisticated (skip tracer's nightmares) — including a multi-malware ecosystem operator running concurrent Raccoon, Mystic stealer, PrivateLoader, and Asuka Trojan operations. Framed as a sardonic OPSEC classroom lecture.

Heather Calloway (CISO) — STRONG ACCEPT

Estelle Ruellan documented that infostealer operators are getting infected by the same class of malware they deploy, and the logs they generate expose their real identities, infrastructure, and in one case the entire internal network of their corporate employer. The credential reuse case — a developer using the same device and credentials for criminal activity and corporate access — is the governance finding that should concern every CISO in a sector with a known threat actor presence.

→ Top-rated talks at NorthSec 2025

All talks from NorthSec 2025