The Party Isnt Over: Uncovering Konfetys Novel Evil Twin Technique @FIRSTdotorg
The Party Isnt Over: Uncovering Konfetys Novel Evil Twin Technique  @FIRSTdotorg
Uploaded August 2025 | Updated September 2026, 3 hours ago
Lindsay Kaye (HUMAN Security, US), Gavin Reid (HUMAN Security, US)

Lindsay Kaye is the Vice President of Threat Intelligence at HUMAN Security. Her technical specialty spans the fields of malware analysis and reverse engineering, with a keen interest in dissecting custom cryptographic systems. Prior to her work at HUMAN, Lindsay served as Senior Director of Advanced Reversing, Malware, Operations and Reconnaissance as part of the Insikt Group at Recorded Future. She has proposed, won funding for and led research projects, particularly during her time at The MITRE Corporation. Outside of work, Lindsay writes articles on complex cybersecurity issues including data and trends analysis, technical pieces on reverse engineering and TTPs, and discussions on the business of the cybercriminal underground. Lindsay is an internationally-recognized cybersecurity speaker and author. She holds a BS in Engineering with a Concentration in Computing from Olin College of Engineering and an MBA from Babson College.

Gavin Reid serves as the CISO for HUMAN Security, a cybersecurity company specialising in safeguarding enterprises from digital attacks while preserving digital experiences for users. Gavin began his cybersecurity career in information security at NASA’s Johnson Space Center. He later went on to create Cisco’s Security Incident Response Team (CSIRT), Cisco’s Threat Research and Communications (TRAC), and Fidelity’s Cyber Information Group (CIG). Before joining HUMAN, Gavin was the CSO for Recorded Future, responsible for ensuring the protection, integrity, confidentiality, and availability of all customer-facing services, internal operational systems, and related information assets. For over 20 years, Gavin has managed every aspect of security for large enterprises.
--
Evil twins can be the topic of science fiction, tales of mystery and... advertising fraud? We uncovered a sophisticated ad fraud campaign, that we dubbed Konfety, involving over 250 Android apps in which each benign app distributed via the Play Store had an "evil twin" adware app counterpart - and its corresponding infrastructure. We will explain how Konfety was able to effectively create its own malicious ecosystem, from their ad SDK to their malicious infrastructure that could be started and scaled to support the evil twins at the press of a button to reselling ad inventory to make money, and provide a technical overview of how they did it. While Konfety is an ad fraud campaign, at its core, the distribution of the malicious twin applications was done via drive-by malvertising, broadening the scope and impact of the campaign past the mobile ecosystem. During this talk, we will also explain how we conducted this investigation, and others like it, including how we discovered the novel "evil twin" technique, and provide insight into our investigative framework. We will also provide guidance for how to incorporate threat intelligence and threat hunting investigation techniques into your own organization, even without having a threat intelligence team.
The Party Isnt Over: Uncovering Konfetys Novel Evil Twin Technique2026 FIRST CTI Conference - Day 2 Plenary Sessions - Live StreamImproving Security Across Nations with FIRST: Ken van Wyk, FIRST MemberTabletop Lessons from 3 Decades and 2 ContinentsUncovering the Whispers of an APT Targeting Specific Industries in South AsiaOperational Efficiency in CTI: A Blueprint for SMEs Using Open-Source AI and Cognitive AutomationMalicious Code-signing at Scale: How Attackers Impersonate Thousands of Real BusinessesDiving into the CVSS Base Score Metrics - An Exploratory Analysis Bridging Product Security...EU Cyber Resilience Act - A Product Owner’s ApproachContextual SBOMs: Unlocking Precise Vulnerability Management with Build-Time Content IntelligenceThe AI Arms Race in Vulnerability Management, Who’s Winning?Disparate Data, Distorted Decisions: Vendor Data Bias in CTI
FIRST |

The Party Isn't Over: Uncovering Konfety's Novel "Evil Twin" Technique

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER