The Intelligence War: Nation-State Cyber Threats
John Fokker (Head of Threat Intelligence · Trellix)
RSA Conference 2025 · Day 2 · West Stage · Keynote
Overview
John Fokker, a former Dutch Marine and cybercrime investigator turned Trellix's Head of Threat Intelligence, delivered one of RSA 2025's most operationally grounded keynotes: a real-time case study of Black Basta, the ransomware organization whose leaked internal communications revealed not just criminal tradecraft but what appears to be direct protection from a nation-state government. The session reframed the threat landscape — the boundary between financially motivated cybercriminals and state-sponsored actors has not merely blurred; in many cases, it has effectively dissolved. ---

Key moments
- 1:07 Fokker led actual police raid arresting CTB Locker affiliates
- 5:44 Nation-states now use cybercriminals as proxies for dirty work
- 7:09 200,000+ Black Basta internal Telegram chats leaked publicly
- 8:51 Black Basta HQ resembled The Office — normal staff, cafeterias
- 9:11 Black Basta leader 'Oleg' escaped Armenia via Russian official
- 12:45 Cybercrime projected as third-largest economy at $10 trillion
- 13:34 Black Basta attacked US healthcare org; Oleg admitted mistake
- 14:33 Encryption tool corrupted healthcare data, broke ransomware business model
The Intelligence War: Nation-State Cyber Threats
Speaker: John Fokker (Head of Threat Intelligence, Trellix)
Event: RSA Conference 2025 — April 28–May 1, 2025, Moscone Center, San Francisco
Watch: YouTube
Reading time: ~8 minutes
TL;DR
John Fokker, a former Dutch Marine and cybercrime investigator turned Trellix's Head of Threat Intelligence, delivered one of RSA 2025's most operationally grounded keynotes: a real-time case study of Black Basta, the ransomware organization whose leaked internal communications revealed not just criminal tradecraft but what appears to be direct protection from a nation-state government. The session reframed the threat landscape — the boundary between financially motivated cybercriminals and state-sponsored actors has not merely blurred; in many cases, it has effectively dissolved.
Introduction
Most keynote speakers at RSA Conference have a slide deck and a podium. John Fokker opened with a video clip of himself participating in a police raid in Romania, arresting affiliates of the CTB Locker ransomware gang. The contrast was intentional. While much of the cybersecurity industry's discourse engages with threat actors as abstract entities — assigned codenames, tracked in dashboards, organized into threat intelligence frameworks — Fokker has spent a career treating them as the human beings they are: people who can be arrested, interrogated, and eventually caught making mistakes.
As Head of Threat Intelligence for Trellix and a key figure in the company's Advanced Research Center, Fokker brings a distinctive perspective to a discipline sometimes accused of over-intellectualizing its adversaries. Before joining the private sector, he served in the Dutch Marine Corps, then spent years at the National High Tech Crime Unit of the Dutch National Police — an organization he described, with practiced self-deprecation, as "one of the best cybercrime units in the world. I'm a bit biased." He led intelligence operations there before moving to Trellix.
At RSA 2025, he did not come with predictions or frameworks. He came with a case.
The Blurring Lines: When Ransomware Gangs Work for Governments
The central argument of Fokker's keynote is that the traditional taxonomy of cyber threats — hacktivists, criminals, and nation-state actors operating in distinct lanes — has broken down in ways that have profound implications for defenders.
▶ Watch: The blurring lines between cybercrime and nation-states (6:00)
"In the past, you had very clear lanes of demarcation," he told the Moscone audience. "Hacktivists caused disruption, cybercrime actors were after financial gain, and nation states were focused on IP theft and espionage." The exception had long been North Korea, whose state-sponsored groups also stole money. But that exception has expanded into a broader pattern. Nation states are now using private-sector companies as proxies — as seen in the iSoon case, which was linked to the Salt Typhoon intrusion campaign — and cultivating relationships with criminal organizations that can be activated, ignored, or protected as circumstances require.
To illustrate how concrete these connections have become, Fokker walked the audience through a real and ongoing investigation: the February 2025 leak of more than 200,000 internal chat messages from Black Basta, one of the most prolific ransomware organizations of the past three years.
Inside Black Basta: More Like The Office Than a Lair
Black Basta emerged from the wreckage of Conti — the ransomware empire whose own internal chats were leaked in what Fokker called "the Panama Papers of ransomware." Fokker and his team, alongside numerous industry peers, analyzed the Black Basta leaks and concluded with high confidence that the communications are authentic.
▶ Watch: Black Basta internal structure and the leader Oleg (8:00)
The picture that emerged from those chats confounded most people's mental image of ransomware operations. Black Basta ran from a conventional office building. It had an HR department, a vacation policy, scheduled work hours, entry-level employees, middle managers, and a C-suite. The cafeterias — Fokker noted the team identified their exact floors — were apparently a point of organizational pride.
The organization's leader operates under the alias "Gigi" but his real name is Oleg — a detail Fokker repeated deliberately. "I'm not calling him Gigi or Tramp or anything else for that matter. He's a real person and his name is Oleg." The practice of assigning aliases to threat actors, he argued, inadvertently mythologizes them, transforming ordinary criminals into shadowy figures beyond reach. Fokker's insistence on using real names when they are known is a form of resistance to that mythology.
Oleg, it turns out, is a wanted man. He is on a U.S. law enforcement wanted list. And last June, he traveled from Moscow to Armenia, where he was arrested. Three days later, he was back in Russia.
The Green Corridor: Evidence of State Protection
What happened in those three days between Oleg's arrest in Armenia and his return to Moscow is the most operationally significant section of Fokker's keynote.
▶ Watch: Oleg's escape from Armenia — the green corridor (10:00)
In chat messages after his return, Oleg described the escape to an associate named Chuck. He said that authorities had secured a "green corridor" — Fokker interpreted this as code for an orchestrated escape route — and that government officials had personally traveled to Armenia to ensure his safe return. Most significantly, Oleg claimed that the intervention was only possible because "number one" — widely understood as a reference to a senior government official — had been made aware of his arrest and acted on his behalf.
"So just to recap for everybody at home keeping score," Fokker said: "The leader of a ransomware gang was arrested in Armenia and then mysteriously vanished, bailed out of custody because of a high-placed government official."
Fokker was careful to note the evidential limitations. These are self-reported claims in leaked chat logs; Oleg may have been embellishing for an audience. But the pattern is not an isolated anomaly. Conti had established ties to the same government circles. Evil Corp has demonstrated similar connections. The Black Basta case is, in Fokker's telling, not an outlier but an example of a systemic arrangement — one in which criminal ransomware operations function as deniable instruments of state power, protected from accountability as long as they remain useful.
The financial scale underpinning this arrangement is staggering. If cybercrime were a sovereign economy, it would rank as the third largest in the world. In 2025, it is expected to generate over ten trillion dollars globally. For nation-states willing to tolerate or direct criminal proxies, the arrangement is both strategically valuable and financially lucrative.
How Attackers Make Mistakes — and How Defenders Exploit Them
The second operational case study Fokker presented involved a Black Basta ransomware attack against a U.S. healthcare provider — a miscalculation, Oleg himself later admitted in the leaked chats.
▶ Watch: The healthcare attack mistake and Black Basta's business model (12:02)
Ransomware organizations operate two main levers: availability (encrypting systems to force payment for decryption) and confidentiality (threatening to publish stolen data). The healthcare attack failed on the availability side — Black Basta's encryption tool corrupted the systems it was meant to lock, leaving no functional decryption key to offer. "Without it, they're stuck," Fokker said. "If you cannot offer a functional decryption key, you're just another wiper, and nobody is paying you a single dime."
The gang pivoted to the confidentiality lever, threatening to publish patient records. They ultimately released the broken decryption key as a face-saving gesture, but the damage to their business model — and their reputation among potential ransomware buyers — was done.
The point was not just that Black Basta failed. It was that even sophisticated, state-adjacent criminal organizations operate under human constraints: time pressure, technical errors, strategic miscalculations. "They are thugs who happen to be good at writing code and breaking into organizations," Fokker said. "They are beatable, even at their own highly sophisticated game."
The Power of TTPs and Collective Intelligence
The final section of the keynote shifted from specific cases to structural conclusions about how the security community should respond.
▶ Watch: TTP mapping and the pyramid of pain (16:00)
Fokker argued that the most durable form of intelligence is not knowledge of specific malware samples or infrastructure — both of which can be changed quickly — but knowledge of tactics, techniques, and procedures (TTPs). In the "pyramid of pain" framework familiar to threat intelligence practitioners, TTPs sit at the apex: the hardest category for adversaries to change, and therefore the most valuable thing for defenders to understand.
When Trellix and its community of researchers mapped Black Basta's TTPs across their malware, their campaigns, and their internal communications, the resulting graph revealed structural patterns that no surface-level indicator of compromise could provide. Crucially, those patterns will persist even if the group rebrands — which Oleg, in the leaked chats, indicated was likely. "Once we've mapped out their playbook, any code tweaks, quick rebrands won't mask their underlying behavior," Fokker said. "Once we know how they operate at the TTP level, we can spot them the moment they launch the next offensive."
▶ Watch: The community as collective harness — closing call to action (18:00)
That insight only exists because of collective effort: incident responders sharing what they see, malware researchers publishing their findings, CISOs disclosing enough to let analysts connect dots, law enforcement coordinating across jurisdictions. Fokker closed with a mountain-climbing analogy. Intelligence, he argued, functions like a safety harness — not a device that prevents falls, but one that allows climbers to attempt harder routes with more confidence, knowing the community will hold if they slip.
"Let's keep building, keep collaborating, keep climbing together," he said, "because when we work as one community, there is no question, we will reach the top."
Notable Quotes
"Take it from me as an ex-cop: a cyber criminal will always prefer a victim with weak passwords, bad patching, and no MFA, as opposed to having to leverage the latest and greatest in AI."
— John Fokker
"I'm not calling him Gigi or Tramp or anything else for that matter. He's a real person and his name is Oleg."
— John Fokker
"If cybercrime were a legitimate industry, it would be the world's third largest economy. It is expected to generate over ten trillion US dollars this year."
— John Fokker
"Once we've mapped out their playbook, any code tweaks, quick rebrands won't mask their underlying behavior. Once we know how they operate at the TTP level, we can spot them the moment they launch the next offensive."
— John Fokker
"Intelligence acts like a skilled mountain guide, navigating treacherous terrain, spotting hidden dangers, and helping organizations chart the safest and most efficient path forward."
— John Fokker
Key Takeaways
- The nation-state / cybercriminal divide is no longer analytically useful. The Black Basta case is one of several examples demonstrating that ransomware organizations operate with degrees of state awareness, protection, and occasionally direction. Defenders who treat these as separate threat categories will misread the risk.
- Threat actors are human beings who make mistakes. Black Basta's botched healthcare attack — corrupted encryption, no viable decryption key, strategic overreach — illustrates that even sophisticated, protected criminal organizations are vulnerable to their own operational errors.
- The basics still matter most. Fokker's bluntest line — that attackers always prefer weak passwords, poor patching, and no MFA over AI exploitation — is a reminder that fundamental hygiene remains the highest-leverage defensive investment.
- TTP-level intelligence is the most durable asset. Malware signatures and infrastructure indicators expire quickly; understanding how an adversary thinks and moves operationally does not. Investing in TTP mapping yields intelligence that survives the rebrands and pivots that ransomware groups use to evade attribution.
- Collective intelligence is not optional. The depth of insight Trellix and its research community achieved on Black Basta was only possible through information sharing. Organizations that hoard threat intelligence weaken the harness that protects everyone.
- Demystify the adversary. Treating threat actors as human criminals — with real names, real mistakes, and real accountability — is both analytically accurate and strategically useful. Mythology is the adversary's best defense.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
Fokker opens with footage of his own police raid and does not let up — the Black Basta case study is the most operationally specific, evidence-grounded threat intelligence session Zero has seen on an RSA main stage in years. The state-protection-of-ransomware-operators argument is not new but the specificity here — leaked chats, real names, the Armenian arrest and 'green corridor' extraction — puts it in a different evidentiary category. This is what a threat intel keynote should look like.
Heather Calloway (CISO) — MUST SEE
Trellix's John Fokker authenticated 200,000+ leaked Black Basta chat messages and traced the group's leadership to an individual arrested in Armenia who was back in Moscow in three days via a 'green corridor' involving a senior Russian government official. The distinction between cybercriminal and state actor dissolves under examination.