Botconf 2026

LT05 - One day in the life of a threat actor targeting Kazakhstani diplomatic entities
2026-04-16 , Amphitheater

Earlier this year, we identified 2 DLL samples impersonating legitimate products and tools uploaded from Kazakhstan to a popular online file analysis platform. These DLLs notably provide an operator with command execution and file download capabilities, and rely on Telegram for C2 communication.

In this lightning talk, we will present the operators' activity journal that we were able to retrieve from the Telegram channels.

Threat researcher at HarfangLab.