[Speakers]
Adversary Village at
DEF CON 34

Mauro Eldritch

Leader @ Bitso Quetzal Team

Mauro Eldritch is an Argentine hacker, Leader of Bitso Quetzal Team. He has spoken at various events, including DEF CON (15 times). He is passionate about Threat Intelligence and Biohacking.

Haetae: An Agent to Takedown North Korean C2 Servers

11:30-12:00 PDT | Friday, Aug 7th 2026 | DEF CON Creator Stage 3, Las Vegas Convention Center
Talk

Co-presented with: Nelson Rafael Colón Merán

Abstract

In this talk, we introduce Haetae, an agent designed to profile, identify, and exploit C2 frameworks used by North Korean malware.


Haetae supports both automated and interactive modes, allowing analysts to map and understand adversary infrastructure with different levels of control. It is built around a flexible rule-based system, enabling users to extend and refine detections as new patterns and frameworks emerge.


In this first release, we will walk through real-world cases where Haetae was used to identify and take down infrastructure associated with Mach-O Man and POWerful Armadillo.


We will also release a safe emulator of both malware C2 servers, allowing researchers and newcomers to experiment with Haetae in realistic, controlled environments without risk.


This is a highly technical talk but can be enjoyed by both beginners and seasoned threat hunters.

Talk outline

Haetae – Detailed Outline


0. Opening / Hook


- What Haetae is: profiling, identifying and exploiting DPRK C2 frameworks
- Why it matters: repeatable patterns lead to repeatable takedowns
- What we will show: real cases, real infrastructure, live demos


A) Who we are and Lazarus overview
- Brief introduction and prior work on DPRK campaigns
- Lazarus as an ecosystem, not a single group
- Why their infrastructure is a viable target


B) Common Lazarus techniques
- Reuse of C2 frameworks across campaigns
- Weak validation, exposed endpoints and predictable routes


C) Haetae agent design
- Agent for C2 profiling and exploitation
- Automatic mode for fast fingerprinting at scale
- Interactive mode for manual exploration and validation
- Rule-based engine covering endpoints, headers, responses and artifacts
- Extensible by users to refine detections
- Separation of identification, validation and exploitation


D) POWerful Armadillo
- Rework of Digit Stealer
- C2 structure and communication model
- Identifiable traits including endpoints, response formats and weak validation
- What can be fingerprinted remotely


E) Demo – POWerful Armadillo
- Live demo of detection and exploitation using Haetae


F) GoLangGhost new iteration
- Updated variant of GoLangGhostRAT
- Changes compared to previous versions
- C2 behavior and exposed surfaces
- Profiling opportunities


G) Demo – GoLangGhost
- Live demo of detection and exploitation using Haetae


H) Mach-O Man
- macOS-focused malware kit
- Differences from typical DPRK tooling
- C2 design and communication patterns
- Unique fingerprinting angles


I) Demo – Mach-O Man
- Live demo of detection and exploitation using Haetae


J) Release and resources
- Haetae download links
- Rule sets and examples
- Safe C2 emulators for GoLangGhost, POWerful Armadillo and Mach-O Man
- How to get started


K) Questions and answers
- Open discussion
- Use cases, limitations and extensions

Agency.


Join Adversary Village Discord Server.

Join Adversary Village official Discord server to connect with our amazing community of adversary simulation experts and offensive security researchers!