When malware tries to disappear, it leaves a trail
At the 38th Annual FIRST Conference in Denver, VMRay Labs’ Patrick Staubmann presented two sessions on how attackers hide, inside trusted SaaS platforms and from the sandbox itself, and how defenders can turn both into detection.
DENVER, 28.06.2026. Two of the most effective things malware does are also two of the hardest to catch: it hides inside the legitimate services defenders use every day, and it tries to detect when it is being analyzed and go quiet. At the 38th Annual FIRST Conference, Patrick Staubmann, who leads the Threat Analysis team at VMRay Labs, gave two talks built on the same idea. Each of those moves, the hiding and the evasion, leaves a trace, and that trace is a detection opportunity.
FIRST is a fitting room for the argument. The Forum of Incident Response and Security Teams is an international, not-for-profit association of trusted incident response teams founded in 1990, now spanning more than 800 member teams across over 100 countries. Its annual conference is one of the field’s most established venues for the people who handle security incidents for a living, exactly the audience both talks were written for.
Living off the SaaS land
Staubmann’s first session, “Sliding into the Enemy’s DMs: Detecting SaaS-Backed Malware C2,” examined a shift that quietly undermines a lot of traditional detection. Rather than maintaining their own command-and-control infrastructure, many active e-crime families now “live off the SaaS land,” abusing well-known collaboration and gaming platforms such as Telegram, Discord, and Steam as covert C2 channels, exfiltration paths, and dead-drop resolvers. When malware talks to its operator through the same services employees rely on all day, IP- and domain-based detection loses much of its edge. The malicious traffic looks, at a glance, like everyone else’s.
The research behind the talk uses a malware sandbox with full visibility into decrypted TLS traffic, which lets analysts see not just which endpoints a sample contacts but the actual content and structure of what it sends. That visibility is what turns an evasive design back into a detectable pattern. In keeping with the talk’s TLP:AMBER designation, the specific detection logic, message formats, and rules were shared with the operational incident-response audience in the room rather than published openly, so they cannot be used by the very actors they are meant to catch. The takeaway for defenders was the broader one: where blocking these platforms outright is not realistic, the path forward is visibility clear enough to separate normal use from abuse, and to operationalize that signal inside incident-response workflows.
Turning evasion against the malware
The second session, “Stop Hitting Yourself: Turning Evasion Techniques Against Malware,” took on a tactic that rarely gets the coverage it deserves. Evasion is among the most damaging things malware can do, because a sample that successfully detects analysis and stays dormant never reveals its behavior at all. Staubmann traced the evolution of these techniques, from rudimentary registry and file-artifact checks to sophisticated virtual-machine and hardware-aware evasion that reflects deep knowledge of operating-system internals. He also drew a distinction that matters operationally: some malware borrows its tricks wholesale from public proof-of-concept toolkits like Pafish and Al-Khaser, while a smaller set of skilled actors do genuine original research, and telling the two apart changes how you respond.
The talk’s organizing frame split evasion into two families. One actively checks for virtual environments or monitoring tools and terminates when it finds them. The other uses stealth to keep running while staying under the radar. The defensive insight cuts across both: an evasion check is itself a signal. When a sample probes for a sandbox, that probe is a tell, and it can be turned into a detection rule. Staubmann’s practical lessons followed from that, including why tracking open-source evasion toolchains is as important as tracking threat actors, and why analysts have to keep rethinking assumptions as techniques evolve. The session balanced retrospective field examples, including a few instructive failures, with forward-looking trends.
The through-line
Both talks make the same case from opposite directions. Whether malware hides in plain sight on a trusted platform or tries to vanish from the sandbox, the attempt to disappear is observable, and observation is where detection begins. That is the work VMRay Labs does continuously: studying how the threat landscape actually behaves, and turning what is observed into something defenders can use.
Draft quote for Patrick’s approval: “When malware checks whether it’s being watched, that check is itself a signal. The moment it tries to hide is often the moment it tells you what it is.” — Patrick Staubmann, Team Lead, Threat Analysis, VMRay Labs
Key takeaways
- Many active e-crime families now use legitimate SaaS platforms for command-and-control, which weakens IP- and domain-based detection.
- A sandbox with visibility into decrypted TLS traffic can reveal the structure of that hidden communication, turning an evasive design into a detectable pattern.
- Malware evasion falls broadly into techniques that detect analysis and quit, and techniques that stay stealthy while running.
- An evasion check is a detection opportunity. The act of probing for a sandbox is itself a signal defenders can use.
- Tracking the open-source toolkits attackers borrow from is as valuable as tracking the actors themselves.
FAQ
What does “living off the SaaS land” mean? It describes malware that abuses legitimate software-as-a-service platforms, such as messaging or gaming services, for malicious purposes like command-and-control or data theft, instead of using its own dedicated infrastructure. This helps it blend in with normal traffic.
Why does abusing SaaS platforms make malware harder to detect? Traditional detection often relies on flagging suspicious IP addresses and domains. When malware communicates through a trusted, widely used service, there is no obviously malicious address to flag.
How can an evasion technique become a detection opportunity? When malware actively checks whether it is running in a sandbox or alongside security tools, that check is a distinctive behavior. Defenders can detect the check itself, using the attacker’s attempt to hide as a signal.
What is the Traffic Light Protocol? A standard for classifying how sensitive information may be shared. TLP:CLEAR can be shared publicly, while more restricted designations like TLP:AMBER limit material to a trusted operational audience, which is why the most sensitive detection detail from the first talk was not published openly.
About Patrick Staubmann
Patrick Staubmann joined VMRay in 2019 as a threat researcher and has led the Threat Analysis team for over two years. His work focuses on the evolving threat landscape and in-depth malware analysis, with interests in reverse engineering, low-level system security, and exploitation. He also lectures at university on network security, system exploitation, and low-level programming.
About VMRay
VMRay helps security teams detect and analyze novel, evasive, and targeted malware and phishing threats, with the accuracy and clarity they need to automate with confidence, respond faster, and build threat intelligence they can trust. Headquartered in Bochum, Germany, VMRay is trusted by enterprises, government organizations, and managed security providers worldwide.
Media contact: Fatih Cam, Corporate Communications & Brand Manager, fcam@vmray.com