
DEF CON 33 - Inside Look at a Chinese Operational Relay Network - Michael Torres, Zane Hoffman
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 33:34
Researchers discovered a PRC-based operational relay network after scanning Docker containers for secrets, exposing how cloud services are exploited for proxy infrastructure 0:55.
Key Takeaways:
• The research began after a Defcon demo on Docker exploitation framework, leading to scanning containers for "whited-out" data (files thought deleted but still present) 6:24
• They discovered 1,500 containers exposing private git repositories, including security vendors and Apache enterprise branches 13:27
• The network used predictable password patterns (AB[characters]@[username_initial]) across email, domain management, and social media accounts 22:59
• The infrastructure included browser fingerprinting for session impersonation, social media management tools, and a malicious Python package 24:50
• Actors used AI tools like Cursor and OpenAI to develop the infrastructure, bypassing Chinese restrictions through their own proxy network 30:27
The researchers found widespread security issues across cloud platforms, with DockerHub, GitHub, and GitLab unresponsive to their vulnerability reports 32:41.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
We're doing the 11:00 talk. Uh these two guys right here the and the talk is basically Whoops. Inside look at a Chinese operational relay network um with MTU and Earl. All right, guys. Kick it off. >> Awesome. Thanks. [Applause] >> All right. Hello everyone. As he just said, uh we're going to be going over what we call meeting Mac or the longer name. an inside look at a PRC based operational relay network. A quick overview. Uh we're going to obviously introduce ourselves and what we did. We're going to talk about some secrets discovery in Docker, which was the source of all of our stuff. Uh we're going to talk about the finding that we found super interesting. Go through all of their databases, uh access keys, passwords, all that good stuff. how they made their infrastructure work and what…