
DEF CON 33 - Ghost Calls - Abusing Web Conferencing for Covert Command & Control - Adam Crosser
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 42:05
This presentation explores how web conferencing platforms can be abused for covert command and control (C2) channels in red team operations 0:15. The speaker demonstrates how to leverage trusted infrastructure like Zoom and Microsoft Teams to create high-throughput, low-latency communication channels that bypass many security controls 6:01.
Key Takeaways:
• Web conferencing platforms are ideal for covert C2 due to their low latency, high throughput design and trusted status in enterprise environments 6:01
• The tool "TurnTunneler" exploits TURN server credentials to create covert channels through Zoom and Teams infrastructure without requiring client software 19:51
• These channels enable SOCKS proxying, local/remote port forwarding, and decentralized C2 for offensive operations 22:47
• Splitting short-term and long-term C2 channels helps avoid detection when large amounts of data need to be transferred 19:40
The research highlights how legitimate architectural requirements of web conferencing platforms create opportunities for covert channels that are difficult to detect and block 7:43.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
And I guess with no further ado, um, Adam Crosser is going to talk about covert channels in web conferencing. So let's hear for Adam. >> All right. Uh, happy to be here today, everyone. Thank you for coming to my presentation. Uh, this is ghost calls abusing web conferencing for covert command and control. To start off with just a brief introduction, I'm Adam Crosser. I'm a staff security engineer at Ptorian. I do a lot of different things from uh vulnerability research to helping to build offensive security tooling that we can use on things like red team engagements. [Music] And to to start things off, I just want to create a bit of a common terminology that we can use on the different types of command and control channels and how I typically think about them. And so the the first type is…