In this talk, we introduce Haetae, an agent designed to profile, identify, and exploit C2 frameworks used by North Korean malware.
Haetae supports both automated and interactive modes, allowing analysts to map and understand adversary infrastructure with different levels of control. It is built around a flexible rule-based system, enabling users to extend and refine detections as new patterns and frameworks emerge.
In this first release, we will walk through real-world cases where Haetae was used to identify and take down infrastructure associated with Mach-O Man and POWerful Armadillo.
We will also release a safe emulator of both malware C2 servers, allowing researchers and newcomers to experiment with Haetae in realistic, controlled environments without risk.
This is a highly technical talk but can be enjoyed by both beginners and seasoned threat hunters alike.
Presented at Malware Village — DEF CON 2026