Loading…
ATLSECCON 2026 has ended
Friday April 10, 2026 9:15am - 10:00am ADT
This presentation provides an in-depth technical analysis of SleepyMutagen, a sophisticated shellcode-based Remote Access Tool (RAT) leveraged by MUTANT SPIDER in the targeting healthcare organizations. SleepyMutagen demonstrates advanced evasion techniques including temporal cryptographic key derivation that renders payloads undecryptable outside two-day execution windows, runtime function encryption using dual XOR keys to evade memory scanning, and covert DNS-over-HTTPS command-and-control communications through Cloudflare using custom Base36 transcoding algorithms. SleepyMutagen implements pseudo-random sleep algorithms to defeat temporal C2 fingerprinting while providing comprehensive remote administration capabilities including token impersonation, in-memory payload execution, and file system operations. This presentation details SleepyMutagen's sophisticated infection chain, multi-stage PowerShell loaders, runtime protection mechanisms, and comprehensive command framework, providing security professionals with technical insights into cutting-edge malware development trends and practical detection methodologies for defenders.
Speakers
avatar for Lilly Chalupowski

Lilly Chalupowski

Malware Reverse Engineer, CrowdStrike
I started my career after I hit rock bottom being a single mom who moved back to live with my parents. After dropping out of computer science, one professor told me I would not be able to work with computers. I lost my passion for computers at this point. Later, I worked with my case... Read More →
Friday April 10, 2026 9:15am - 10:00am ADT
Argyle Suite 2

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link