Inside the Information Stealer Ecosystem: From Compromise to Countermeasure @FIRSTdotorg
Inside the Information Stealer Ecosystem: From Compromise to Countermeasure  @FIRSTdotorg
Uploaded August 2025 | Updated September 2026, 5 hours ago
Olivier Bilodeau (Flare, CA)

Olivier Bilodeau, a principal researcher at Flare, brings 12+ years of cutting-edge infosec expertise in honeypot operations, binary reverse-engineering, and RDP interception. Passionate communicator, Olivier spoke at conferences like BlackHat, DEFCON, SecTor, Derbycon, and more. Invested in his community, he co-organizes MontrèHack, is NorthSec's President, and runs its Hacker Jeopardy.
--
Modern information stealers have evolved far beyond simple credential harvesters into sophisticated tools that capture complete digital fingerprints of their victims. This technical deep-dive unveils groundbreaking research into stealer architecture, attack chains, and defensive countermeasures. Through analysis of real-world compromise scenarios, including desktop screenshots captured at infection moments, we reveal how threat actors leverage compromised ad networks and trojanized software for mass deployment. The presentation examines the Operation Magnus takedown, a collaborative effort with ESET and law enforcement, demonstrating the complex infrastructure behind professional criminal enterprises.Building on hands-on experience with stealer log analysis, we detail how modern threats bypass multi-factor authentication, compromise password managers, and extract cryptocurrency wallets. We examine Chrome's application-bound encryption and why, although already circumvented, it creates new detection opportunities. The session concludes with practical defensive strategies and the release of two community resources: a PowerShell framework for automated credential testing against Entra ID and a curated dataset of stealer logs for security research.This presentation equips security practitioners with concrete insights and tools to defend against one of today's most consequential yet underexamined threats.
Inside the Information Stealer Ecosystem: From Compromise to CountermeasureImproving Security Across Nations with FIRST: Tom Millar, FIRST TLP SIG Co-chairDraugnet: Anonymous Threat Reporting That Actually WorksAutomated ATT&CK Technique ChainingPanel: The CVE Supplier ADP (SADP) Pilot: Am I Affected byUpstream?Establishing a Global Community of Practice on Coordinated Vulnerability Disclosure (CVD)Lazarus Group Evolved Their Infection Chain with Old and New MalwareAI Interpretability as a Security Control: Introducing the CIRCUIT FrameworkFrom Dork to Diplomat: Communicating Coherently for Vulnerability & Incident ResponseBroken Seals, Broken Trust: Flaws and Defences in the Certificate EcosystemBringing Chronological Context to Disparate Artifacts: Accelerating Digital ForensicsQuantifying Swiss Cheese, the Bayesian Way
FIRST |

Inside the Information Stealer Ecosystem: From Compromise to Countermeasure

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER