Responding to Breaches, Ransomware, and State Sponsored Threat Actors
Panel
DEF CON 32 Creator Stage · Day 1 · Creator Stage
Overview
This DEF CON 32 panel, titled "Responding to Breaches, Ransomware, and State Sponsored Threat Actors," brought together a distinguished group of cybersecurity experts to discuss the evolving landscape of advanced persistent threats (APTs), ransomware, and nation-state activities. The panel aimed to illuminate the tactics, techniques, and procedures (TTPs) employed by formidable adversaries and provide insights into effective defensive strategies. With speakers representing organizations at the forefront of threat intelligence, incident response, and cybersecurity frameworks, the session offered a multifaceted perspective on managing the complex challenges posed by highly motivated and well-resourced attackers.

Key moments
- 0:00 Panel host ABX introduces Defcon Advisory Village
- 0:50 Adam Pennington introduces Miter ATT&CK framework
- 1:25 Striker on Black Point Cyber's MDR and threat intel
- 2:15 Ken on AI and White House Presidential Innovation Fellow
- 2:45 Nikhil Mittal introduces Auto Security and red teaming
- 3:15 Adam discusses Miter ATT&CK tracking state actors
- 3:40 Historical overview of state hacking awareness and trends
- 4:15 Threat actors' sophistication and evasion techniques
Responding to Breaches, Ransomware, and State Sponsored Threat Actors
Speakers: Panel
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=Q-rGVE9xCKw
Overview
This DEF CON 32 panel, titled "Responding to Breaches, Ransomware, and State Sponsored Threat Actors," brought together a distinguished group of cybersecurity experts to discuss the evolving landscape of advanced persistent threats (APTs), ransomware, and nation-state activities. The panel aimed to illuminate the tactics, techniques, and procedures (TTPs) employed by formidable adversaries and provide insights into effective defensive strategies. With speakers representing organizations at the forefront of threat intelligence, incident response, and cybersecurity frameworks, the session offered a multifaceted perspective on managing the complex challenges posed by highly motivated and well-resourced attackers.
The discussion underscored the critical importance of understanding adversary behavior, moving beyond the notion of "sophistication" to recognize the targeted and adaptive nature of attacks. Panelists emphasized that while headlines often focus on complex zero-day exploits, many successful breaches leverage simpler, less monitored pathways. The talk highlighted emerging trends such as the exploitation of network infrastructure, security devices, and embedded systems, which often fall outside the scope of traditional endpoint detection and response (EDR) solutions, creating significant blind spots for defenders.
This panel is particularly relevant in today's interconnected world, where organizations of all sizes, from critical infrastructure to small businesses, face persistent threats from state-sponsored actors and sophisticated criminal groups. The insights shared are crucial for cybersecurity professionals looking to enhance their threat intelligence capabilities, improve their defensive posture, and develop more resilient incident response plans against an adversary that continuously adapts its approach to achieve its objectives, whether it be espionage, disruption, or financial gain.
Background
▶ Watch: Panel host ABX introduces Defcon Advisory Village (0:00)
The threat of state-sponsored hacking and sophisticated cyberattacks is not a recent phenomenon, with its roots tracing back decades. As Adam Pennington from the MITRE Corporation highlighted, the public eye has been aware of such activities since at least the 1980s, referencing historical events like "The Cuckoo's Nest," in which MITRE itself played a role. Over the years, major incidents have progressively raised global awareness, including the APT1 report that shed light on Chinese state-sponsored espionage, the pervasive Russian hacking campaigns impacting elections, and the rise of North Korean ransomware operations. These incidents collectively underscore a long-standing and escalating challenge in the cybersecurity domain.
MITRE, through its MITRE ATT&CK framework, has been at the forefront of tracking publicly available threat intelligence on various adversary groups since its inception between 2013 and 2015. This framework provides a globally accessible knowledge base of adversary tactics and techniques based on real-world observations, serving as a critical resource for defenders. Pennington emphasized that the information discussed in the panel is derived entirely from open-source intelligence (OSINT), highlighting the importance of shared knowledge in the security community.
A key point of discussion revolved around the often-misunderstood concept of adversary "sophistication." While the term frequently appears in media and even panel descriptions, Pennington cautioned against its broad application. He asserted that most threat actors, particularly state-sponsored ones, are "exactly as sophisticated as they need to be in a given situation." This pragmatic approach means adversaries will typically opt for the path of least resistance, only deploying their "big guns" or highly advanced exploits when absolutely necessary. As defenses have improved across traditional network and endpoint monitoring, adversaries have been compelled to adapt, seeking out less monitored and less protected segments of an organization's digital footprint. This constant evolution creates a dynamic challenge for defenders, requiring a shift in focus from merely protecting endpoints to securing the entire attack surface, including often-overlooked infrastructure components.
Key Findings
▶ Watch: Striker on Black Point Cyber's MDR and threat intel (1:25)
The panel identified several critical trends and findings regarding the current state of cyberattacks, particularly those involving state-sponsored actors and ransomware groups. These findings highlight a strategic shift in adversary tactics in response to improved conventional defenses:
- Exploitation of Unmonitored Infrastructure: A predominant trend observed by the panelists is the increasing focus of adversaries on exploiting devices and systems that often lack robust security monitoring. Adam Pennington specifically noted a surge in attacks targeting routers, system security devices, VMware ESX servers, and even security cameras. These devices frequently operate with minimal security controls, are rarely subjected to the same level of scrutiny as endpoints or servers, and often do not support traditional endpoint detection and response (EDR) agents, creating significant blind spots.
- The "Sophistication" Fallacy: As previously mentioned, a core finding was the debunking of the myth that all advanced threat actors are inherently "sophisticated" in every attack. Adam Pennington reiterated that adversaries are "exactly as sophisticated as they need to be." This means they will use the simplest effective method to achieve their objectives. If a basic phishing attack or an exploit against an unpatched, common vulnerability works, they will use it. This highlights that many successful breaches are not the result of cutting-edge zero-days, but rather persistent exploitation of known weaknesses in overlooked systems.
- Supply Chain as a Primary Vector: Striker from Black Point Cyber highlighted the significant role of supply chain attacks, particularly those targeting Managed Service Providers (MSPs). Black Point Cyber, as an MDR provider, observes attacks directly against MSPs and then subsequently against their end clients, ranging from healthcare and critical infrastructure to small businesses. This demonstrates how compromising a single MSP can provide a gateway to a vast network of downstream clients, amplifying the impact of a successful breach.
- Persistence through Evasion: State actors, unlike many ransomware groups, often seek long-term presence within a network for intelligence gathering or sustained disruption. This requires them to not get caught, or at least not get completely caught, for months or even years. Their pivot to less monitored infrastructure is a direct response to improved EDR and network monitoring on traditional endpoints, making detection significantly harder.
- Ubiquity of Vulnerable IoT/Edge Devices: The mention of "crappy Linux devices" like security cameras underscores the pervasive security risk posed by the proliferation of Internet of Things (IoT) and other embedded devices. These devices often have minimal built-in security, receive infrequent updates, and are difficult to secure or monitor effectively, making them ideal entry points or pivot points for adversaries.
These findings collectively paint a picture of an adversary that is highly adaptive, opportunistic, and strategic in its targeting, constantly seeking out the weakest links in an organization's defense perimeter rather than always resorting to the most complex tactics.
Technical Deep Dive
▶ Watch: Nikhil Mittal introduces Auto Security and red teaming (2:45)
The technical core of the panel's discussion revolved around the specific types of infrastructure and devices that adversaries are increasingly targeting, and the inherent challenges these present for detection and defense. Adam Pennington detailed several key areas:
- Routers and System Security Devices:
- Adversary Focus: A significant trend observed last year (referring to the year prior to the conference) was adversaries gaining access to routers. These devices are critical network choke points and, if compromised, can provide deep network access, facilitate traffic redirection, or serve as persistent command and control (C2) channels.
- Exploitation Method: Attackers are actively finding and exploiting zero-days in these devices, including those "we actually bought to protect our networks." This highlights a profound irony and a major vulnerability: the very tools intended to secure an environment can become its weakest link if compromised. These devices often run specialized operating systems, making traditional security agent deployment impossible.
- Impact: Once compromised, routers and security devices can be used as pivot points to move deeper into the network, bypass internal segmentation, or launch further attacks against internal systems. Their compromise can also lead to a loss of visibility and control for defenders.
- VMware ESX Servers:
- Adversary Focus: Gaining access to VMware ESX servers has become a popular trend. These hypervisors are foundational to many modern IT infrastructures, hosting numerous virtual machines (VMs) that run critical applications and services.
- Detection Challenge: A primary reason for their appeal to attackers is that EDR solutions are typically not supported on ESX hypervisors themselves. This means that even if the VMs running on ESX have EDR agents, the underlying hypervisor, which controls everything, remains unmonitored by these tools. This lack of visibility makes it extremely difficult for defenders to detect malicious activity occurring directly on the hypervisor level.
- Impact: A compromised ESX server grants an adversary control over all hosted VMs, allowing them to manipulate, exfiltrate data from, or disrupt numerous systems simultaneously, often without triggering alerts from traditional security tools.
- Security Cameras and "Crappy Linux Devices":
- Adversary Focus: A recent trend involves adversaries targeting security cameras and other similar Internet of Things (IoT) or embedded devices. These are often characterized as "crappy Linux devices" due to their minimal hardware resources, simplified operating systems, and often neglected security postures.
- Security Deficiencies: These devices typically have no security built-in, and there's no way of adding security through conventional means (e.g., installing agents or robust security software). They often ship with default credentials, unpatched vulnerabilities, and limited update mechanisms.
- Impact: While seemingly low-value, compromised cameras can provide adversaries with persistent access to a network, serve as initial access points, or be used as stepping stones for lateral movement. They can also be leveraged to monitor physical environments, gather intelligence, or participate in botnets. The challenge lies in the sheer volume and distributed nature of these devices, making comprehensive monitoring and securing an insurmountable task for many organizations.
The overarching technical challenge highlighted by these trends is the increasing difficulty of detecting adversary activity in "places that we don't watch." As defenders improve monitoring on conventional endpoints and servers, attackers are simply shifting their focus to the less visible and less protected layers of the IT stack. This necessitates a fundamental re-evaluation of security architectures, monitoring strategies, and incident response capabilities to encompass these emerging blind spots. The panel underscored that relying solely on EDR for endpoint protection is insufficient when adversaries are operating "more and more buried into the system" in environments where EDR cannot reach.
Demo / Proof of Concept
▶ Watch: Adam discusses Miter ATT&CK tracking state actors (3:15)
This panel discussion focused on broad trends, strategic insights, and defensive implications regarding breaches, ransomware, and state-sponsored threat actors. As such, no specific technical demonstration or proof of concept was presented or discussed during the session. The content was primarily analytical and observational, drawing from the panelists' extensive experience and threat intelligence data.
Defensive Implications
▶ Watch: Threat actors' sophistication and evasion techniques (4:15)
The insights shared by the panel carry significant defensive implications, urging organizations to re-evaluate their security strategies and expand their visibility beyond traditional boundaries. Responding effectively to modern adversaries, especially state-sponsored ones and sophisticated ransomware groups, requires a proactive and adaptive approach:
- Expand Monitoring to Unwatched Spaces: The most critical implication is the urgent need to extend security monitoring to devices and infrastructure components that are currently underserved by traditional security tools. This includes:
- Network Routers and Switches: Implement robust logging, network traffic analysis (NTA), and behavioral analytics on network devices. Monitor for unusual configurations, unauthorized access attempts, and anomalous traffic patterns that could indicate compromise.
- Security Appliances: Recognize that security devices themselves are targets. Ensure these systems are rigorously patched, configured with strong access controls, and their logs are integrated into a central security information and event management (SIEM) system for analysis.
- Virtualization Infrastructure (e.g., VMware ESX): Develop strategies for monitoring the hypervisor layer. This might involve leveraging hypervisor-level APIs for telemetry, implementing network-based detection around ESX hosts, or exploring specialized security solutions designed for virtualization environments. The goal is to detect activity that bypasses guest OS-level EDR.
- IoT and Embedded Devices (e.g., Security Cameras): Segment these "crappy Linux devices" onto isolated networks. Implement strict access controls, regularly review their configurations, and monitor their network communications for any unusual outbound connections or activity indicative of compromise or use as a pivot point. Consider solutions that provide network-level visibility and anomaly detection for these devices.
- Rethink "Sophistication": Defenders should move past the notion that all attacks will be highly sophisticated. Instead, focus on a comprehensive defense-in-depth strategy that addresses both common vulnerabilities and advanced TTPs. Prioritize patching known vulnerabilities, enforcing strong authentication (especially MFA), and implementing basic security hygiene, as adversaries will exploit the easiest path. The anecdote about the executive whose personal Google Chrome account synced corporate credentials highlights how simple misconfigurations or user errors can be exploited.
- Strengthen Supply Chain Security: Given the prevalence of supply chain attacks, especially through MSPs, organizations must implement rigorous vendor risk management programs. This includes:
- Due Diligence: Thoroughly vet third-party providers, especially those with privileged access to your network.
- Contractual Requirements: Mandate specific security controls, regular audits, and incident reporting protocols in contracts with MSPs and other critical vendors.
- Monitoring Third-Party Access: Implement strict monitoring and access controls for all third-party connections to the network, treating them with the same scrutiny as internal users.
- Leverage Threat Intelligence: Utilize frameworks like MITRE ATT&CK to understand adversary TTPs, map defensive capabilities, and identify gaps. This helps defenders anticipate how adversaries might operate and where to focus detection and prevention efforts. Adam Pennington's role in MITRE ATT&CK underscores its utility in providing actionable intelligence from open-source intelligence (OSINT).
- Focus on Detection and Response Beyond Prevention: While prevention is crucial, assume that breaches are inevitable. Invest in robust detection capabilities that can spot adversaries operating quietly for extended periods. This includes behavioral analytics, threat hunting, and a well-practiced incident response plan that can effectively contain and eradicate threats from complex environments. The goal for state actors is often not to get caught at all or not completely caught, necessitating long-term detection strategies.
By adopting these defensive postures, organizations can significantly enhance their resilience against a threat landscape characterized by adaptive adversaries who continuously seek out the path of least resistance, often in the blind spots of traditional security.
Key Takeaways
- Adversaries Adapt to Defensive Improvements: As traditional endpoint and network defenses improve, state-sponsored actors and sophisticated threat groups are increasingly targeting less monitored infrastructure like routers, security devices, VMware ESX servers, and IoT devices (e.g., security cameras).
- "Sophistication" is Contextual: Threat actors are pragmatic; they employ tactics only as sophisticated as necessary to achieve their objectives, often opting for simpler methods if effective. Defenders should focus on comprehensive hygiene rather than only preparing for "big guns."
- Supply Chain Attacks are a Major Vector: Managed Service Providers (MSPs) and other third-party vendors represent significant supply chain risks, offering adversaries a pathway to multiple client environments.
- Visibility Gaps are Critical Blind Spots: Environments where EDR solutions are not supported (e.g., hypervisors like VMware ESX) or where devices lack inherent security (e.g., "crappy Linux devices") create crucial blind spots that adversaries readily exploit for persistence and lateral movement.
- Proactive Monitoring Beyond Endpoints is Essential: Organizations must expand their security monitoring and logging to cover network infrastructure, virtualization layers, and embedded devices to detect adversary activity in these previously "unwatched" places.
- Leverage Threat Intelligence for Strategic Defense: Frameworks like MITRE ATT&CK, built on open-source intelligence, provide invaluable insights into adversary TTPs, enabling defenders to anticipate attacks and prioritize defensive investments effectively.
About the Speaker(s)
The panel was moderated by Abhijit Baburajan Renuka (ABX), who leads the Advisory Village at DEF CON, a role he has held for approximately 4-5 years, offering talks and workshops to the community.
Adam Pennington is with the MITRE Corporation, a nonprofit organization, where he runs the MITRE ATT&CK cybersecurity framework. He has a long history with MITRE, having contributed to gathering data for the original ATT&CK framework through honeypots interacting with state actors, giving him extensive experience in observing these threats.
Striker serves as the Head of Security Communications and Planning at SCP, and is also part of the Adversary Pursuit Group, the threat intelligence and research unit within Black Point Cyber. As an MDR (Managed Detection and Response) provider, Black Point Cyber gains significant insights from a diverse range of client environments, from healthcare and critical infrastructure to small businesses, observing both supply chain attacks against MSPs and direct attacks on end clients. Striker is also an admin at the Lonely Hackers Club and involved with the XR Village.
Ken is the VP of AI for Omni Federal. Prior to this role, he served for four years as a White House Presidential Innovation Fellow, where he gained firsthand experience with various significant cyberattacks.
Nikhil Mittal is the founder of Auto Security, an organization specializing in training individuals in red teaming for on-premise and Azure environments. His expertise lies particularly in Microsoft security.