SAINTCON 26 · Session
So You Want to Build Malicious Infrastructure: A Field Guide to Adversary TTPs
Building malicious infrastructure is harder than it looks. Adversaries run into the same architectural decisions any engineer does, including where to host, how to register domains without leaving a trail, what tools to use, how to route traffic, and how to keep systems online when they are being actively disrupted. This talk walks through those decisions using real examples from APT groups, ransomware affiliates, phishing kit operators, and large scale fraud networks. At each step, the same choices that make infrastructure work also make it discoverable. We look at how consistent patterns reveal careful actors, what renting a phishing kit does to operational security, and how defenders can follow breadcrumbs from a single domain back to a larger identity.