Speaker Details

Piotr Bienias

Piotr Bienias

Adversary Researcher @ Atos Threat Research Center

Piotr Bienias is Adversary Researcher in Atos Threat Research Center with 5 years of experience in incident response, malware analysis, and threat hunting. He has led and supported complex investigations involving advanced threats, detection evasion, and large-scale security incidents, combining deep hands-on analysis with detection engineering and applied security research. His work regularly contributes to technical reports and conference-grade publications focused on real-world attacker tradecraft.

Trusted Distribution, Untrusted Outcome: Malicious Proxyware via Microsoft Store Applications

Friday, 13 November 2026, 12:00 - 12:20

Microsoft Store applications are often perceived as trustworthy because they undergo a certification process and are distributed through an official software marketplace. This presentation examines a malicious proxyware campaign that abused this trust model by distributing seemingly legitimate utility applications that contained a hidden proxyware payload.

The session follows the investigation from campaign discovery through technical analysis, showing how Electron-based MSIX applications loaded a Go-based payload using the Node.js FFI library koffi, achieved persistence through MSIX Startup Tasks, and ultimately transformed victim systems into residential proxy nodes. The presentation also discusses why the campaign avoided detection by traditional security controls, including the absence of Microsoft Defender for Endpoint alerts and limited antivirus detections, and concludes with key lessons learned from investigating malicious functionality operating within trusted application ecosystems.