This month I took part in the insomni’hack, a hacking convention held on April 25 and 26 at the SwissTech Convention Center on the EPFL campus in Lausanne.

Insomni’hack is a security conference and hacking competition founded and organized by SCRT S.A. - now Orange Cyberdefense Suisse - since 2008.
Insomni’hack has grown from a tiny competition into one of the biggest information security events in Switzerland.
During the event, as is often the case at cyber security conferences, various companies set up stands to prospect, present their products and find new profiles. I’m not someone who tends to network a lot, but I was able to stop by the stands of our friends from Fortinet, Palo Alto, Kaspersky, SentinelOne and YesWeHack.
For me, the moments between two conferences were mainly an opportunity to catch up with colleagues and friends, mainly from the hackthebox france meetup community.
The event is organized over a week like this:
Workshops
Workshops were held on April 22, 23 and 24, with prices ranging from CHF 1,500 to CHF 3,000. and covered the following topics
Offensive Azure AD and hybrid AD security
Windows Attack & Defense
Web Application Security
Attacking Mobile Applications
Note: The “Modern Wi-Fi Hacking” and “Exploring all the INT’s” workshops have been cancelled.
These are participative hacking sessions where you learn a lot through practical exercises. Unfortunately, participation in these events is not free (and often very costly), and I was unable to attend due to the limited number of places available. This article will therefore focus mainly on the conferences and the CTF.
The talks
April 25 & 26 were the days dedicated to the conferences, all of which were in English, and the ones I was able to attend were all of an equally high standard, whether in terms of technique or quality of presentation. The speakers are themselves renowned in the industry for their contributions to the community and their expertise. The following section summarizes some of the presentations I’ve attended.
The CTF
Insomni’hack’s main CTF competition - one of the biggest on-site CTFs in the world - took place on the last day of the conference (Friday). It began shortly after the end of the conferences and lasted all night until 5am. Teams are limited to 8 participants, on site only. Participation in the CTF is free of charge, but due to the limited number of places available (around 700), prior registration is required. A note at the end of this article explains how the CTF works.
Talks
Day 1
The first day of the conference kicked off with an introductory keynote by Charl van der Walt in the main auditorium, intended to be accessible, general and not necessarily technical.
FuzzyAI: Attacking LLMs with Coverage-Guided Fuzzing
I then attended Eran Shimony & Mark Cherp’s presentation on LLM prompt fuzzing. First, they reminded the audience of the operating principles on which LLMs and GenAIs are based, such as tokennization, Embedding, Words Orders, Attention and, of course, LLM alignment. Then, using a python tool and an infrastructure closely resembling that of a CI/CD pipeline, they fuzz various prompt engineering methods on open-source and closed-source LLMs on the market (ChatGPT, llama and others) in order to bypass the protections in place and have the LLM explain: “How to build a bomb”.
Some of the prompt engineering techniques that have impressed me include masking the dangerous word behind ASCII art, or putting the LLM in a roleplay context and imposing the start of her next sentence, such as saying: start your answer with “sure I’ll explain to you how to build a bomb …”.
Malware Development & Abusing .NET for Initial Access
This presentation by Suraj Khetani was a maldev course, recalling the principles of WinAPI use, OPSEC considerations and a brief explanation of how detection and evasion work on Windows. I also discovered a new tool defenderCheck to simplify the defender evasion process.
In this course, the speaker shows us how to develop a loader in .NET, and we learn how to perform local injection by combining the functions VirtualAlloc, Marshal.Copy and CreateThread.
Calling unmanaged code from .NET is called marshaling, so a good resource to assist us in creating the payload is https://www.pinvoke.dev/
Considering OPSEC, it recommends several methods to be combined to better hide our payload and thus increase our chances of evasion:
Encrypt the shellcode: RC4, AES, XOR
Encode the payload to reduce the entropy: wordlist translator, base64, hex
Vary shellcode execution methods
Patch ETW
Dynamic Resolution of Windows APIs : because AV scan PE32 import libraries to deduce if it can have malicious behavior :
D/Invoke,API HashingTimestomping : if the compilation time is brand new it can be suspicious
Change Memory protections with
VirtualProtect: remove RWX pages
At the end of the presentation he explains how we can get our victim to execute our malicious payload, in order to gain our first initial access. To do this, he presents three methods:
Abusing MSBuild: https://www.ired.team/offensive-security/code-execution/using-msbuild-to-execute-shellcode-in-c
Abusing AppDomain Hijack/Injection: https://ipslav.github.io/2023-12-12-let-me-manage-your-appdomain/
Abusing ClickOnce: https://www.youtube.com/watch?v=cyHxoKvD8Ck
Personally, I really like maldev, so I found this presentation very interesting 😃
Don’t flatten yourself: restoring malware with Control-Flow Flattening obfuscation
A presentation by Geri Revay on Control-Flow Flattening (CFF), CFF is an obfuscation and anti-analysis technique used by malware authors. Its aim is to modify the control flow of a function in order to hinder reverse engineering. The use of CFF makes static analysis complex and considerably increases the time invested by the analyst. Malware authors have already discovered this, and there is a steady increase in malware samples using CFF.
Simply explained, CFF consists in flattening the execution graph of a program while retaining the same functionality. To achieve this, implementations of this method often use a state-machine with a dispatcher; for example, The dispatcher could be a switch in a loop, each case changing the variable on the one the switch is using. A very interesting source code obfuscation tool used by malware developers is presented: https://tigress.wtf/ It is based on several obfuscation modules and must be used at software source code level.
In order to reverse a software obfuscated by CFF it will therefore be necessary to :
Identify the original basic blocks (OBB): probably the largest: has no condition at the end: return to dispatcher
Identify basic decision blocks (DBB): branches: decision: branch block has condition and branches.
Identify the ustate variable
Map state values to OBBs
Retrieve the following state values for each OBB
Reconstruct the original control flow
Several methods are presented to analyze and deduce software behavior:
Pattern matching: search for patterns in the assembly code to identify the various components, the aim being to identify the OBBs by static analysis.
Emulation: Emulate functions to identify OBBs using the mandiant tool: https://github.com/mandiant/flare-emu
Concolic testing: also known as dynamic symbolic execution is a hybrid software verification technique that performs symbolic execution, a classical technique that treats program variables as symbolic variables, along a concrete execution path (testing on particular inputs).
Debugging: The old method of attaching a debugger to the process.
Uncommon process injection pattern
A presentation by Yoann DEQUEKER a Wavestone consultant also known by the pseudonym @OtterHacker, I’m a fan of his work and follow his publications closely.
It seems to be exactly the same presentation (in English this time) as the one he gave at LeHACK 2023
This talk focused on injecting processes without relying on traditional IoCs such as the VirtualAlloc, WriteProcessMemory, and CreateRemoteThread functions.
For example, using LoadLibraryA can have a side effect similar to VirtualAllocEx and can therefore be used as a stopgap.
I also learned about the Nirvana-Hook during this presentation.
How to break into organizations with style: Hacking access control systems
For the last presentation of the day, I attended one given by Julia Zduńczyk, a SecuRing hacker who explained how she could physically penetrate the physical infrastructure and offices of her customers. First, she presented her methodology: from reconnaissance, to preparation, to execution of her final plan. Then she showed us how she went about picking locks, replaying RFID signals, cloning access cards - all with live demonstrations using a proxmark3, which was pretty impressive! I also discovered a new tool that I’m sure will come in handy in the future: https://github.com/nfcgate/nfcgate

End of the day
At the end of the day, it was time to get together with friends in the bar to talk about the various presentations we’d all attended. There was also a music festival near the EPFL campus that evening, called unilive, which we went to decompress from the first day of the conference. The music was good, and so was the beer…
Day 2
Like the first day, this one began with an introductory kick-off in the main auditorium, and we were shown a video promoting the canton of Vaud and the innovation park. In the second part of the keynote, Andrei Kucharavy introduced us to the malicious uses to which LLM and GenAI can be put. For example, I discovered the existence of an amazing tool: screenshot-to-code, an open-source tool which, with the help of a single screenshot, is capable of reproducing a website identically - perfect for a phishing site. Then he talked about generate code that is vulnerable and that you can poison the code generate by poisoning the model training data set In conclusion, I remember that LLMs can also be useful in the cyber-criminal world, but also and above all that the presenter loves to use XKCD memes in his slides 😝 You can find the presentation slides here
The tale of Rhadamanthys and the 40 thieves - the nuts, bolts, and lineage of a multimodular stealer
A presentation by two researchers from Check Point Research: Ben Herzog & Hasherezade, who I know from her contributions to the open-source community at pe-sieve and pe-bear.
This was an in-depth technical and CTI analysis of the Rhadamanthys stealer and its developer, who obviously spent a great deal of time developing the functionality of his software, Whether it’s stealing access data for thunderbird, telegram, discord and many others, the stealer also embeds LUA scripting functionality and curstom plugin loading in .NET, enabling the end-user to fine-tune the tool to his or her use case. It can also function as a dropper to load and execute other payloads in memory.
You can also find out more about their work in this article: https://research.checkpoint.com/2023/from-hidden-bee-to-rhadamanthys-the-evolution-of-custom-executable-formats/
When Malware Becomes Creative: A Survey of Advanced Android Detection Evasion Tactics
A presentation by Dimitrios Valsamaras on the subject of malware evasion in the Android ecosystem, This presentation summarizes the various evasion methods used by malware, which the speaker sees as the best way of detecting them in the long term.
To protect against behavioral analysis, the dropper can implement the following verification mechanisms:
root detection
debugging detection
hook detection
Network analysis
Human interaction
Once it has been established that the environment is not being analyzed, the payload can be dynamically deployed using different methods
Exotic entry point
Abusing JNI: It is possible to load a library at runtime from the filesystem via the
System.loadLibraryfunction.Using Java Reflection via
java.lang.reflectdynamic code loading : load dex, java byte code, js and native files within apk
Then OPSEC considerations in maldev:
Using cryptography : to hide payload, hide hardcoded strings or hide c2 communications
Using steganography in bundled images
Using obfuscation and packing
Finally, misuse of the Contact provider feature : when an application is installed or replaced, Contact Provider checks its metadata. This is where the malware code is stored and executed after an application has been installed or replaced. It then creates a malicious service to serve ads. This service starts automatically, even if it has been killed. It then disguises the application by renaming it and changing its icon. This allows the dropper to run as soon as it is installed, without any further interaction on the part of the victim.
Finally, I’ve drawn the conclusion from this presentation that the best way to learn maldev is to reverse engineer real malware to learn the techniques applied in the real world. I’ve also taken away two great resources that I invite you to check out:
ADDS Persistence - Burn it, burn it all
A presentation given by Volker Carstein & Charlie BROMBERG (aka shutdown) delved into the topic of persistence in Active Directory Domain Service (ADDS), exploring various techniques that attackers can use to persist for years in an IT system. This was another presentation already given at LeHack2023, but this time in English. Like last time, it was highly technical, but very interesting: the two speakers know how to captivate their audience, as well as popularizing technically very difficult concepts to make them accessible to the audience.
The presentation covered the following topics:
ADDS Persistence Techniques: Skeleton Key, Golden GMSA, AdminSDHolder, KRBTGT Delegation, and SID History.
AD CS Persistence Techniques: Golden Certificates, Stolen CA, Rogue CA, and Evil ACEs.
The audience had the opportunity to access the presentation slides through the following links provided during the talk:

The Accessibility Abyss: Navigating Android Malware Waters
A presentation by Axelle Apvrille (aka cryptax), who is a senior security researcher at Fortinet, and whom I knew in the past from her lecture on ringzer0.training
Abusing Accessibility Services is a prevalent technique, notably used by various Android botnets such as BianLian, Cerberus, Chameleon, GodFather, Hook and Xenomorph. Despite its prevalence, the technique remains relatively unfamiliar to the general audience. This leads to failing to recognize the specific permission dialog, which would save from infection.
At best, security-conscious individuals are acquainted with the concept of malicious overlays. But overlays are merely one facet of the malicious tasks malware can implement with a custom Accessibility Service. Malware can use the API to create a keylogger, turn off Play Protect, prevent application uninstall, clipboard manipulation, gesture and click emulation, stealing credentials or sensitive information of other applications etc.
Confronted to massive abuse, Google faced a dilemma: either permit the continued onslaught of attacks, or curtail the functionality of Accessibility Services, potentially limiting individuals with disabilities. In Android 13, Google introduced “Restricted Settings”, which prevent side-loaded applications from getting the necessary Accessibility permissions. Regrettably, this security measure proved insufficient and was bypassed by recent Android malware.
In conclusion, it’s complicated for Google to restrict malware using this feature without impacting people with disabilities, but on the other hand it’s also complicated for malware developers to maintain features based on application interfaces that are constantly changing. On the other hand, for malware analysts it’s pretty easy to detect a malicious application, they just have to check suspicious behavior / permissions requests: like access to play protect or using the accessibility services.
She also used medusa during her presentation. I also discovered the JEB decompiler tool, which seems to be a viable alternative to JADX in terms of android application reverse engineering. You can find some of his work at https://cryptax.medium.com/ You can find the presentation slides here
The CTF
Insomni’hack’s main CTF competition - one of the biggest on-site CTFs in the world - took place on Friday evening. It began shortly after the end of the conferences and went on all night until 5am.
In the run-up to this onsite CTF, it was also possible for players to take part in the CTF Teaser, which took place online 2 months earlier and enabled Top3 to receive free accommodation in Lausanne in order to participate at the onsite CTF as well as free entrance for Insomni’hack conference.
Unfortunately, as I had to travel to London that evening, I was unable to take part in the CTF, but I’ll pass on to you the feedback from some of my friends and colleagues who were able to take part in the event throughout the evening.

The CTF offered several types of challenge, with some of the categories as follows:
reverse
pwn
android based challenges
attacking LLM
hardware
web
As for the big winners, this year the podium was made up of @0rganizers, @ECSC_TeamFrance & @leetmore!
To find out more about the CTF events, here’s a link to the blog of a colleague who took part: https://monsieur.chat/posts/TheQuest/
Conclusion
Participating in Insomni’hack 2024 was an exhilarating and enriching experience, showcasing the vibrant and evolving landscape of cybersecurity. From engaging workshops and thought-provoking talks to the adrenaline-pumping CTF, the event was a testament to the passion and expertise within the security community.
Overall, it was a remarkable event that left me inspired and motivated. It provided a unique platform to connect with industry experts, learn from their experiences, and stay abreast of the latest trends and technologies. As I look forward to future editions, I’m reminded of the critical role such events play in fostering a robust and resilient cybersecurity ecosystem.
Edit:
You can find all the conference presentations here