BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Cloud-Native C2: Weaponizing Trusted Infrastructure 
 for\n   Initial Access\n   Tags: Red Team Village | Misc\n   When: Friday\
 , Aug 7\, 14:00 - 15:59 PDT\n   Where: LVCCW Level 1 Hall 1 309 (Red Team 
 Village) Tactic Table 1 -\n   [1]Map\n\n   Description:\n\n   Traditional 
 command and control infrastructure faces constant\n   detection pressure f
 rom network defenders. This research presents two\n   novel proof-of-conce
 pt frameworks that demonstrate how seemingly\n   benign cloud services can
  be weaponized for covert operations. MeetC2\n   leverages Google Calendar
  API to transform calendar events into a\n   bidirectional C2 channel\, wh
 ile XRayC2 repurposes AWS X-Ray's\n   distributed tracing service for comm
 and execution and data\n   exfiltration.\n\n   Both frameworks exploit fun
 damental assumptions about trusted\n   services: calendar synchronization 
 traffic appears as routine business\n   operations\, while X-Ray traces bl
 end seamlessly with legitimate\n   application monitoring. Our implementat
 ions showcase practical\n   techniques including command encoding in calen
 dar event metadata\,\n   response embedding in trace annotations\, and bea
 con patterns that\n   mimic normal service behavior. The frameworks suppor
 t cross-platform\n   implants with minimal footprint\, requiring only API 
 credentials rather\n   than traditional malware persistence.\n\n   I will 
 demonstrate how these channels bypass traditional security\n   controls\, 
 as encrypted HTTPS traffic to Google and AWS endpoints\n   rarely triggers
  alerts. The research reveals critical blind spots in\n   cloud security m
 onitoring and provides actionable detection\n   strategies\, including API
  usage anomalies\, unusual trace patterns\, and\n   calendar event behavio
 ral analysis. This work aims to help defenders\n   understand emerging clo
 ud-native threats and implement appropriate\n   monitoring for their cloud
  environments.\n\n   As organizations increasingly adopt cloud services\, 
 attackers have\n   evolved their tactics to abuse these trusted platforms 
 for malicious\n   purposes. Cloud service APIs present an attractive optio
 n for\n   establishing command and control infrastructure because they off
 er\n   high availability\, encrypted communications by default\, and traff
 ic\n   that blends with legitimate business operations. This research\n   
 explores how adversaries can weaponize standard cloud APIs to create\n   s
 ophisticated C2 channels that circumvent traditional security\n   controls
 .\n\n   This research presents two functional C2 frameworks for initial ac
 cess\n   that abuse legitimate cloud APIs: MeetC2 leveraging Google Calend
 ar\n   for command and control\, and XRayC2 weaponizing AWS X-Ray distribu
 ted\n   tracing.\n\n   SpeakerBio:  Dhiraj Mishra\n\n   An active speaker 
 who has discovered multiple zero-days in modern web\n   browsers and an op
 en-source contributor. He is a trainer at Blackhat\,\n   BruCON\, 44CON an
 d presented in conferences such as Ekoparty\, NorthSec\,\n   Hacktivity\, 
 PHDays\, Hack in Paris & HITB. In his free time\, he blogs\n   at www.inpu
 tzero.io/www.fuzzing.at and tweets on @RandomDhiraj.\n\n   '\n\n   1. #LVC
 CW_Level1_Hall1\n\n\n
DTEND:20260807T225900Z
DTSTART:20260807T210000Z
LOCATION:Red Team Village - LVCCW Level 1 Hall 1 309 (Red Team Village) Tac
 tic Table 1
SUMMARY:Cloud-Native C2: Weaponizing Trusted Infrastructure for Initial Acc
 ess
END:VEVENT
END:VCALENDAR
