DEF CON 33 - Inside Look at a Chinese Operational Relay Network - Michael Torres, Zane Hoffman

DEF CON 33 - Inside Look at a Chinese Operational Relay Network - Michael Torres, Zane Hoffman

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 33:34

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Researchers discovered a PRC-based operational relay network after scanning Docker containers for secrets, exposing how cloud services are exploited for proxy infrastructure 0:55.

Key Takeaways:
• The research began after a Defcon demo on Docker exploitation framework, leading to scanning containers for "whited-out" data (files thought deleted but still present) 6:24
• They discovered 1,500 containers exposing private git repositories, including security vendors and Apache enterprise branches 13:27
• The network used predictable password patterns (AB[characters]@[username_initial]) across email, domain management, and social media accounts 22:59
• The infrastructure included browser fingerprinting for session impersonation, social media management tools, and a malicious Python package 24:50
• Actors used AI tools like Cursor and OpenAI to develop the infrastructure, bypassing Chinese restrictions through their own proxy network 30:27

The researchers found widespread security issues across cloud platforms, with DockerHub, GitHub, and GitLab unresponsive to their vulnerability reports 32:41.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

We're doing the 11:00 talk. Uh these two guys right here the and the talk is basically Whoops. Inside look at a Chinese operational relay network um with MTU and Earl. All right, guys. Kick it off. >> Awesome. Thanks. [Applause] >> All right. Hello everyone. As he just said, uh we're going to be going over what we call meeting Mac or the longer name. an inside look at a PRC based operational relay network. A quick overview. Uh we're going to obviously introduce ourselves and what we did. We're going to talk about some secrets discovery in Docker, which was the source of all of our stuff. Uh we're going to talk about the finding that we found super interesting. Go through all of their databases, uh access keys, passwords, all that good stuff. how they made their infrastructure work and what…