Home / Series / DEF CON / Aired Order / Season 32 / Episode 147

MFT: Malicious Fungible Tokens

In this technical talk, we will uncover a new aspect of NFTs: using them as attack vectors to relay C2 commands. Fingerprinting a system? Exfiltrating information? Encrypting and wiping data? Executing arbitrary commands? Of course! But with a dark twist: deployed NFTs are blockchain-backed assets immune to takedowns. Imagine having your own “immortal” C2 Server for less than $10 dollars in $ETH. For this, we will introduce “mFT” an open-source tool that automates the creation of malicious payloads and provide sample harmless NFTs, allowing attendees to explore this novel attack vector on their own machines safely. This talk is the spiritual successor of "Everything is a C2 if you're brave enough".

English
  • Originally Aired August 9, 2024
  • Runtime 30 minutes
  • Created August 26, 2024 by
    Subscriber-2473783
  • Modified August 26, 2024 by
    Subscriber-2473783