BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Hacking the Hackers who Hack Hackers: Supply-Chain B
 ackdoors\n   in Underground VPN Infrastructure\n   Tags: DEF CON Official 
 Talk\n   When: Friday\, Aug 7\, 15:00 - 15:59 PDT\n   Where: LVCCW Level 1
  Hall 3 903 (Main Track 5) and DCTV-5 - [1]Map\n\n   Description:\n\n   Un
 derground VPN and tunneling ecosystems are widely used to monetize\n   com
 promised servers and sell “free internet” access through SSH\,\n   SOC
 KS\, and multi-protocol tunnels. These operations rely heavily on\n   open
 -source infrastructure management tools deployed on rented or\n   hacked L
 inux servers. But what happens when the tools themselves are\n   weaponize
 d?\n\n   In this talk we dissect FirewallFalcon Manager\, a VPN/SSH server
 \n   management toolkit widely promoted in Telegram communities. While it\
 n   presents itself as a legitimate open-source platform\, our analysis\n 
   reveals a multi-layered supply-chain attack targeting the very\n   opera
 tors who deploy it.\n\n   FirewallFalcon silently installs backdoors\, inj
 ects a rogue TLS root\n   certificate\, hijacks DNS resolution\, and redir
 ects proxy traffic\n   through attacker-controlled infrastructure to enabl
 e large-scale\n   Man-in-the-Middle interception. Earlier versions also de
 ployed a\n   Telegram reconnaissance bot and a universal SSH backdoor gran
 ting root\n   access to infected servers.\n\n   Using reverse engineering\
 , GitHub history analysis\, DNS infrastructure\n   mapping\, and large-sca
 le internet scanning\, we uncovered hundreds of\n   active servers inside 
 this compromised ecosystem. This talk exposes a\n   new class of supply-ch
 ain attacks: hackers hacking the infrastructure\n   used by other hackers.
 \n\n   SpeakerBio:  Assaf Morag\, Flare\n\n   Assaf Morag is a Cybersecuri
 ty Researcher and Threat Intelligence\n   Consultant\, working with variou
 s companies on research focused on\n   underground ecosystems\, attacker i
 nfrastructure\, and the evolving\n   cyberthreat landscape. His work trans
 lates adversary activity from\n   open\, deep\, and dark-web sources into 
 actionable intelligence for\n   security teams and the software developmen
 t life cycle. Previously\,\n   Assaf served as Director of Threat Intellig
 ence at Aqua Security and\n   held senior intelligence roles at BlueVoyant
  and IBM Security. His\n   research has been featured in leading cybersecu
 rity publications and\n   presented at major industry conferences. He cont
 ributed to the MITRE\n   ATT&CK® Container Framework and authored an O'Re
 illy course on\n   cloud-native cyber threat intelligence.\n\n   '\n\n   1
 . #LVCCW_Level1_Hall3\n\n\n
DTEND:20260807T225900Z
DTSTART:20260807T220000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5
SUMMARY:Hacking the Hackers who Hack Hackers: Supply-Chain Backdoors in Und
 erground VPN Infrastructure
END:VEVENT
END:VCALENDAR
