The cookie is a lie: Handing Canarytoken sessions to infostealers

by Will & Jacob | - 11:45am

Infostealer malware is on the rise–as MFA rollouts increase, stealing sessions (instead of usernames and passwords) is the new hotness. Once your information is stolen, what then? That’s what we set out to answer. Join Will and Jacob as they purposely infect themselves with malware and “deploy” their long-lasting session cookies into the malware operators’ databases. We created a new type of Canarytoken (session cookies) and gave out free samples to all the infostealer malware folks we could find. Then we watched to see what happened… (come to this talk if you want to find out–we’re not going to spoil it in the talk synopsis)

About Will & Jacob

Will runs Restealer, a free and ethical infostealer monitoring solution. Alongside Restealer, Will works as a pentester for Bastion Security Group, with a focus on pentesting web applications, APIs, and more recently, AI/LLM solutions. You can find his other stuff at https://wpf.nz. Jacob is the Head of Labs at Thinkst Applied Research (the Canary folks). Prior to that he managed the HW/FW/VMM security team at AWS, and was a Program Manager at DARPA’s Information Innovation Office (I2O). At DARPA he managed a cyber security, AI/ML, and analytics R&D portfolio. Jacob has been a technical and keynote speaker at conferences around the world, from BlackHat, to SysCan, to TROOPERS and many more.

Other talks