Image
Image

Silent Thief: Uncovering an 18-Month Infostealer Infiltration Targeting the Czech Republic

The cybersecurity of Czech healthcare facilities has long been under threat, endangering not only data confidentiality but also the very delivery of healthcare services. Existing conditions—where budgets and staffing are often limited—further complicate the effective implementation of security strategies, especially compared to the private sector.

This talk will walk you through the analysis of a real-life incident at a Czech hospital, where an infostealer malware specifically targeting the Czech Republic remained undetected for more than 18 months. The malware was only identified during the deployment of an EDR solution, at which point the attack escalated. The malware immediately reacted by attempting to hide its activities, disable security software, establish persistence, and rapidly exfiltrate collected data.

The presentation will offer a detailed breakdown of the attack, what information the infostealer managed to steal, the unusual method it used to exfiltrate data to C&C servers, and a timeline of the incident, including technical details of the attack and the hospital IT team’s response to the crisis. We will also share the lessons learned, highlighting common shortcomings in organizations that often struggle with limited resources.


David Pecl

David Pecl graduated in Information Security from the Faculty of Electrical Engineering and Communication at Brno University of Technology. During his studies, he began working at AEC a.s., initially focusing on the implementation and technical support of antivirus and EDR technologies, later moving on to other projects primarily in endpoint protection and vulnerability management, where he also led the team executing these projects. Throughout his career in security, he has primarily focused on endpoint protection against modern attack techniques and the field of vulnerability and patch management.

In 2022, he joined Security Avengers as a Security Consultant, where he participates in designing solution architectures, their implementation, integration with other tools, system hardening, and security training. His expertise continues to focus on endpoints and related technologies, vulnerability management, securing privileged accounts, and security in containerized environments.

Matej Kačic

Matej Kačic is a graduate of the Faculty of Information Technology at Brno University of Technology, where he specialized in IT and cybersecurity. During his studies, he conducted research in the field of network security and, in 2017, successfully defended his dissertation, "Analysis of Attacks on Wireless Networks," earning his Ph.D. He remains an active member of the Security@FIT group at BUT, lectures at the university, and engages in publishing activities.

Since 2013, Matej has worked as a security architect at AEC in the technology division, which he later went on to lead.

Since 2022, he has been working as a security consultant, manager, security solutions architect, and founder of Security Avengers. He seeks out complex and challenging cybersecurity problems and is a strong advocate of innovation and automation, believing in their potential to provide both immediate and preventive security benefits.