BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Below the Threshold: Real-World APT Tradecraft for\n
    Full-Spectrum Compromise\n   Tags: Red Team Village | Misc\n   When: Sa
 turday\, Aug 8\, 17:00 - 17:59 PDT\n   Where: LVCCW Level 1 Hall 1 309 (Re
 d Team Village) Workshop Stage 2 -\n   [1]Map\n\n   Description:\n\n   Thi
 s talk aims to demonstrate the modus operandi of an APT focused on\n   ful
 l organizational compromise\, revealing how such operations actually\n   f
 unction in practice â€” not through isolated tools or techniques\, but\n  
  through the decision-making model that guides every action over time.\n\n
    Rather than focusing on direct exploitation or individual methods\,\n  
  this session shows how advanced operators structure their actions\n   aro
 und continuity\, predictability\, and behavioral alignment with the\n   ta
 rget environment. Attacks are not treated as disruptive events\, but\n   a
 s controlled sequences of decisions designed to remain coherent and\n   be
 low the threshold of attention.\n\n   The presentation walks through a rea
 l RedOps engagement from a\n   strategic perspective\, highlighting how ea
 ch step is evaluated in\n   terms of detection probability\, behavioral de
 viation\, and operational\n   impact\, ensuring the operation remains stab
 le and does not generate\n   relevance over time.\n\n   Instead of teachin
 g specific techniques\, the talk focuses on analyzing\n   how and why cert
 ain strategies are chosen\, revealing the underlying\n   principles that d
 rive advanced operations in complex environments.\n\n   The narrative is b
 uilt around three distinct operational tracks\n   conducted within the sam
 e organization\, which\, when combined\, enabled\n   full compromise:\n\n 
     * CloudOps â€” decisions and paths that led to the compromise of\n    
    cloud resources\, including external dependencies and supply chain\n   
     vectors\;\n\n     * HybridOps â€” integration of physical\, human\, an
 d logical layers\,\n       including physical intrusion and contextual exp
 loitation of the\n       corporate environment\;\n\n     * FinancialOps â€
 ” understanding of financial and operational\n       processes that enable
 d the execution of validated fraud without\n       generating meaningful a
 lerts\;\n\n   Across these three domains\, the session demonstrates how cl
 oud\,\n   physical\, and financial layers can be exploited in a coordinate
 d\n   manner while maintaining consistency with expected system behavior.\
 n\n   As a central part of the session\, a real operation conducted by our
 \n   company will be presented\, in which an organization was fully\n   co
 mpromised through a coordinated\, multi-layered approach. The\n   scenario
  includes:\n\n     * exploitation of a 0day in a physical intrusion contex
 t\, enabling\n       continuous presence within the environment for 30 day
 s without\n       detection\, including a 0-click account takeover scenari
 o\;\n\n     * progression from an initial phishing vector to full compromi
 se of\n       cloud assets\, including resource abuse within well-mapped\n
        compromised accounts\;\n\n     * analysis of critical business serv
 ices and processes\, resulting in\n       confirmed financial fraud throug
 h the exploitation of a\n       client-side trust model in a payment syste
 m\, with direct\n       reputational impact\;\n\n   In this case\, there w
 as no single event that defined the attack\, but\n   rather a sequence of 
 controlled and coherent actions that blended into\n   normal operations\, 
 enabling full control without triggering\n   traditional detection mechani
 sms.\n\n   The goal of this talk is to provide security professionals with
  a\n   practical and structured understanding of how APTs actually operate
 \,\n   offering deeper insight into how decisions are made throughout a\n 
   real-world operation.\n\n   The key takeaway is that APT operations are 
 not effective because they\n   are invisible\, but because they do not beh
 ave like something that\n   deserves attention.\n\n   Speakers:Jonathan Co
 radi\,Oliveira Junior\n\n   SpeakerBio:  Jonathan Coradi\n\n   Jonathan Co
 radi is a RedOps Tech Lead at Hakai Offensive Security\,\n   with over 7 y
 ears of experience in offensive security. He has led\n   offensive operati
 ons across industrial\, financial\, and banking sectors\n   in Brazil\, sp
 ecializing in advanced penetration testing\, Red Team\n   simulations\, an
 d physical intrusion engagements. Jonathan is also an\n   elite Bug Bounty
  Hunter â€” currently ranked Top 1 on BugHunt â€” and\n   has reported cri
 tical vulnerabilities to companies like Microsoft\,\n   Uber\, and Mercado
  Livre\, among others.\n\n   SpeakerBio:  Oliveira Junior\n\n   Oliveira L
 ima is the founder of Hakai and has over 15 years dedicated\n   to the fie
 ld of cybersecurity\, focusing on penetration testing and Red\n   team ope
 rations. As a researcher\, he has reported numerous\n   vulnerabilities in
  large companies such as Trend Micro\, CISCO\, Dlink\,\n   etc. Additional
 ly\, he has registered more than 40 CVEs. Oliveira\n   continues to be par
 t of the team leading Red team operations.\n\n   '\n\n   1. #LVCCW_Level1_
 Hall1\n\n\n
DTEND:20260809T005900Z
DTSTART:20260809Z
LOCATION:Red Team Village - LVCCW Level 1 Hall 1 309 (Red Team Village) Wor
 kshop Stage 2
SUMMARY:Below the Threshold: Real-World APT Tradecraft for Full-Spectrum Co
 mpromise
END:VEVENT
END:VCALENDAR
