How Nation-State Hackers Turn Human Error into Catastrophic Failures

N Case, J McCoy

DEF CON 33 · Day 1 · Main Stage

Overview

In this DEF CON talk, "How Nation-State Hackers Turn Human Error into Catastrophic Failures," speakers N Case and J McCoy pull back the curtain on the insidious tactics employed by nation-state adversaries to compromise critical infrastructure systems. Far from the dramatic, explosive "boom" scenarios often depicted, the speakers reveal a more chilling reality: sophisticated, long-term campaigns designed to silently infiltrate, collect intelligence, and subtly manipulate systems, often with devastating, unnoticeable consequences. The core message is a stark warning that human error, complacency, and a lack of fundamental security hygiene provide the most fertile ground for these advanced threats.

Watch on YouTube

Visual summary for How Nation-State Hackers Turn Human Error into Catastrophic Failures by N Case, J McCoy
Visual summary for How Nation-State Hackers Turn Human Error into Catastrophic Failures by N Case, J McCoy

Key moments

  1. 0:00 Introduction and critical infrastructure definition
  2. 1:30 Event 1: The danger of shared apartment Wi-Fi
  3. 4:00 Why attackers exploit shared Wi-Fi for government targets
  4. 4:30 Event 2: Malware in signed artifacts via bastion hosts
  5. 6:30 The 'best' bastion host was the only one compromised
  6. 7:00 Unused, unpatched bastion hosts and false security

How Nation-State Hackers Turn Human Error into Catastrophic Failures

Speakers: N Case, Incident Responder; J McCoy, Security Planner

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=77AixFQKwVI

Overview

In this DEF CON talk, "How Nation-State Hackers Turn Human Error into Catastrophic Failures," speakers N Case and J McCoy pull back the curtain on the insidious tactics employed by nation-state adversaries to compromise critical infrastructure systems. Far from the dramatic, explosive "boom" scenarios often depicted, the speakers reveal a more chilling reality: sophisticated, long-term campaigns designed to silently infiltrate, collect intelligence, and subtly manipulate systems, often with devastating, unnoticeable consequences. The core message is a stark warning that human error, complacency, and a lack of fundamental security hygiene provide the most fertile ground for these advanced threats.

The presentation delves into four real-world incidents, each illustrating how seemingly minor security oversights or deeply ingrained human behaviors are weaponized to achieve strategic objectives against vital sectors like communications, medical manufacturing, and government. These case studies highlight the myth of the "air gap," the dangers of unmanaged supply chain risk, and the persistent vulnerability introduced by basic human fallibility. Case and McCoy emphasize that the most effective attacks often bypass complex technical defenses by exploiting the simplest, most overlooked weaknesses in an organization's security posture and its people.

Ultimately, the talk serves as a critical call to action for security professionals to shift their focus from reactive incident response ("right of boom") to proactive planning, detection, and prevention ("left of boom"). By dissecting specific attack vectors—from shared apartment Wi-Fi to compromised CI/CD pipelines and social engineering—the speakers urge a fundamental re-evaluation of security assumptions, particularly regarding third-party trust, endpoint hygiene, and the pervasive illusion of isolation in interconnected environments.

Background

▶ Watch: Introduction and critical infrastructure definition (0:00)

The concept of critical infrastructure underpins modern society, encompassing sectors like energy, water, healthcare, communications, and manufacturing. These systems are essential for daily life, and their disruption can lead to widespread societal collapse. Consequently, they represent prime targets for sophisticated adversaries, particularly nation-state actors, who seek to gain strategic advantage, collect intelligence, or exert influence. The inherent complexity, legacy systems, and often fragmented ownership within critical infrastructure environments create unique security challenges.

A central theme of the talk is the distinction between "left of boom" and "right of boom" in security. "Right of boom" refers to the aftermath of a security incident—the "crater" of damage that incident responders (like speaker N Case) are called in to clean up. In contrast, "left of boom" signifies the proactive measures taken before an incident occurs, focusing on planning, prevention, and early detection (as advocated by speaker J McCoy). The speakers argue that the industry's predominant focus on "right of boom" is a dangerous misconception, especially when dealing with nation-state adversaries who often aim for subtle, long-term compromise rather than immediate, destructive impact. Their goal is not always to break something, but to collect intelligence, maintain persistence, or slowly degrade capabilities without immediate detection.

This problem is exacerbated by several common, yet flawed, assumptions:

  1. Implicit Trust: Organizations often implicitly trust external services, cloud providers, and even internal systems without sufficient due diligence or ongoing monitoring.
  2. The Myth of the Air Gap: The belief that isolating critical systems from external networks provides absolute security, ignoring physical and human vectors of compromise.
  3. Neglect of Basic Hygiene: Fundamental security practices like patching, strong authentication, and endpoint protection are frequently overlooked or poorly implemented, creating easily exploitable vulnerabilities.
  4. Human Fallibility: Underestimating the susceptibility of individuals to social engineering and the impact of seemingly innocuous human errors (e.g., using an infected USB drive, connecting an unauthorized device).

These assumptions create a fertile ground for nation-state hackers, who patiently exploit these gaps to achieve deep, persistent access, often remaining undetected for years. The talk aims to dismantle these assumptions by presenting real-world scenarios where these very weaknesses led to catastrophic, albeit silent, failures.

Key Findings

▶ Watch: Why attackers exploit shared Wi-Fi for government targets (4:00)

The talk meticulously dissects four distinct real-world incidents, each revealing critical vulnerabilities stemming from human error and systemic security failures, particularly within critical infrastructure contexts:

  1. Shared Wi-Fi as a Nation-State Entry Point: The first finding illustrates how common, unsegregated Wi-Fi networks in apartment complexes can be weaponized by nation-state actors. By infecting personal devices in these shared environments, attackers establish a beachhead that can then be carried into sensitive government or corporate networks when employees bring their compromised laptops to work. This highlights a critical, often overlooked supply chain vulnerability at the individual level.
  1. Compromised Bastion Hosts and CI/CD Pipelines: The second incident exposes the dangers of neglected security hygiene within development and deployment environments. A bastion host, intended as a secure gateway, became the point of compromise due to poor patching and shared, unpassphrased SSH keys. This allowed adversaries to inject malware into a CI/CD pipeline and artifact repo, leading to the deployment of signed, yet malicious, code into production systems of a major communications company, bypassing standard security checks.
  1. Outsourced CI/CD as a Multi-Client Attack Vector: The third finding demonstrates a sophisticated supply chain attack targeting an outsourced SaaS CI/CD provider. Instead of directly attacking the target company, nation-state actors compromised the third-party service itself, then leveraged internal vulnerabilities within the provider to jump between client environments. This allowed them to silently infect a specific high-value target for an extended period (approximately three years), bypassing traditional perimeter defenses by being a "trusted" source.
  1. Social Engineering and Air Gap Bypass in Medical Manufacturing: The final, and arguably most alarming, finding details a multi-year social engineering campaign against a medical manufacturing company. This culminated in the bypass of an "air-gapped" system through the use of an unauthorized Wi-Fi hotspot by an unsuspecting employee. The attack aimed to subtly alter the manufacturing process of life-saving medicine, turning it into an inert "sugar pill" to achieve a long-term, population-level strategic goal, underscoring the severe consequences of human vulnerability and the fallacy of isolation.

These findings collectively underscore that nation-state attacks often prioritize stealth, persistence, and the exploitation of human and systemic weaknesses over brute-force technical exploits. The "boom" is often silent, with long-term, devastating effects that are difficult to detect until it's too late.

Technical Deep Dive

▶ Watch: Event 2: Malware in signed artifacts via bastion hosts (4:30)

The talk provides a granular look at how these nation-state attacks unfold, leveraging both technical vulnerabilities and human factors.

Event 1: Shared Wi-Fi and Government Compromise

The first scenario highlights the insidious nature of shared Wi-Fi networks in residential settings, particularly apartment complexes. Many apartment buildings offer communal Wi-Fi, effectively creating a single Local Area Network (LAN) for all tenants. As N Case explains, this setup, while convenient, means "sharing is caring" also applies to malware. An attacker can easily compromise one device on this shared LAN, then laterally move to other tenant devices. The critical pivot occurs when an employee of a government organization or other sensitive entity brings their now-infected personal laptop home to this shared network, or, more commonly, back to their workplace.

The adversary's strategy here is simple yet effective: rather than a direct, high-profile attack on a government target in a location like Virginia, they target the softer underbelly of an employee's home network. Once the laptop is infected, it acts as a trojan horse, carrying the malware past perimeter defenses when reconnected to the corporate or government network. This vector relies entirely on the lack of segregation in residential Wi-Fi and the common practice of employees using personal devices for work-related activities or connecting infected personal devices to work networks. Detection is often absent, as "no one would have ever have detected that apartment complex being hijacked if one of us hadn't been staying there for a weekend."

Event 2: The Peril of Bastion Host 3 and CI/CD Supply Chain

This incident exposes critical flaws in managing bastion hosts and securing CI/CD pipelines. A bastion host is designed as a hardened gateway to internal networks, but in this case, a major European communications company had multiple, poorly managed bastion hosts. The critical flaw was that only "Bastion Host 3" was regularly used and, puzzlingly, kept patched. The other hosts (1, 2, 4, 5) were unpatched and unused. It was later discovered that "Bastion Host 3" was being patched not by an internal team member, but by the adversaries themselves—"the Russians."

The compromise began with a simple, yet persistent, human error: an employee picked up a USB drive labeled "Tommy's homework" in the parking lot and plugged it into a system. This infected a development environment. The malware then leveraged the compromised Bastion Host 3, which had access to the artifact repo and the CI/CD pipeline. Even though artifacts were signed, the malware was injected before signing, leading to the deployment of signed, malicious code into production. The attackers used the "most stable" bastion host to connect to production, infecting the entire CI/CD pipeline. The speakers emphasize the critical hygiene failures: neglected patching, poor asset management, and especially the sharing of SSH keys without passphrases in a publicly accessible folder on Bastion Host 3. This allowed the adversaries to maintain persistent access and deploy malicious artifacts, turning a trusted deployment mechanism into an attack vector.

Event 3: Outsourced CI/CD Provider Compromise

This scenario illustrates a sophisticated supply chain attack targeting an outsourced Software-as-a-Service (SaaS) CI/CD provider used by a critical infrastructure company (one "we all drink from"). The target company employed a standard three-tiered architecture (internet, application, database) and relied on an external CI/CD service for application deployment. They trusted this provider implicitly, based on documentation and SLAs, effectively "skipping the firewall" for deployments.

The nation-state actor didn't directly attack the end-user company. Instead, they compromised the outsourced CI/CD provider itself, likely months before detection. This allowed them to gain access to the provider's internal systems and then "jumped client to client to client based on internal issues in that CI/CD provider" until they found their preferred target. This long-term persistence (the hack took about three years to find) meant the malicious application was being built and pushed to the target environment from a seemingly legitimate, trusted source. This bypasses traditional ingress checks, as the external CI/CD system is considered a "trusted provider." The technical implications are profound: if a trusted third party is compromised, all its clients become vulnerable, potentially without any direct interaction with the initial attacker.

Event 4: Social Engineering and "Air Gap" Bypass in Medical Manufacturing

This was a multi-faceted attack against a medical manufacturer, demonstrating the fallacy of air-gapped systems and the power of persistent social engineering. The campaign began with a long-term (five years) social engineering effort targeting an individual, "Jane Smith," a "documentation specialist" at the company. Attackers used fake LinkedIn profiles (identifiable by perfectly aligned AI-generated eyes) to build rapport, enticing Jane with fake job offers to double her salary. They performed geospatial analysis of her Wi-Fi and conducted war dialing to identify internal systems, including fire and security systems.

The defenders initially anticipated an attack on Jane's laptop, setting up tripwires. However, the true attack vector was far more subtle. The manufacturing facility's critical laboratory equipment, which was supposed to be air-gapped and cut off from external networks, operated on a large, physically expansive network. For convenience, Wi-Fi was introduced to this "air-gapped" environment. The attackers exploited this by identifying "Bob," a manufacturing updates guy. They waited for Bob to perform an update. Instead of a direct network hack, Bob simply walked in with an unauthorized hotspot and plugged it into the supposedly isolated laboratory equipment to facilitate his work. This direct, physical connection through a human vector completely bypassed the "air gap."

The immediate detection was a massive anomaly: 32,000 DNS requests over five minutes from the laboratory equipment, with no corresponding network connectivity to other internal systems. This indicated exfiltration to an external destination. The data was sent to AWS US East 1, a common cloud region, making it difficult to block without disrupting legitimate operations. This highlights how attackers leverage common cloud services to blend in. The talk also revealed widespread exposure of Industrial Control Systems (ICS): Shodan showed 84,991 Modbus systems (common in the US) and 505,575 MQTT systems (common in Europe/Asia) directly exposed to the internet, further underscoring the vulnerability of critical manufacturing and industrial environments.

The motivation behind this medical manufacturing attack was chilling: to subtly alter the production of medicine, turning it into an inert "sugar pill" that would slowly kill 500,000 people in a specific region, enabling the nation-state to acquire resources in that area. This demonstrates the "silent boom" – a catastrophic outcome without any obvious destructive event.

Demo / Proof of Concept

▶ Watch: The 'best' bastion host was the only one compromised (6:30)

While the talk did not feature live, interactive demonstrations or traditional proof-of-concept code execution, the speakers effectively presented four detailed, real-world case studies that served as narrative demonstrations. Each incident was described with sufficient technical depth and contextual information to illustrate the attack vectors, the mechanisms of compromise, and the resulting impact. The "demo" was in the form of a forensic reconstruction of these nation-state attacks, providing a practical understanding of how theoretical vulnerabilities manifest in complex critical infrastructure environments. The speakers walked the audience through the attacker's methodology and the defender's often-mistaken assumptions, highlighting the critical points of failure and detection.

Defensive Implications

▶ Watch: Unused, unpatched bastion hosts and false security (7:00)

The detailed incidents presented by Case and McCoy offer crucial insights for defenders, demanding a fundamental shift in security strategy:

  1. Acknowledge the Myth of the Air Gap: The concept of a truly air-gapped system is largely a fallacy. Whether through physical cables, USB drives, or unauthorized Wi-Fi hotspots, human convenience will invariably bridge the gap. Defenders must assume that critical systems will eventually be connected and implement robust internal segmentation, monitoring, and detection capabilities accordingly. Focus on detecting anomalies within supposedly isolated networks.
  1. Prioritize Basic Security Hygiene: Many sophisticated attacks exploit fundamental, neglected security practices.
  • USB Port Control: Strictly control and monitor USB port usage on all endpoints, especially those connected to critical systems. Recognize that USB drives remain a potent and widely used vector (52% of cyber threats to ICS systems used USBs).
  • SSH Key Management: Implement strong SSH key hygiene. This includes using passphrases, never sharing keys, storing them securely, and regularly auditing access. Publicly accessible, unpassphrased SSH keys are an open invitation to adversaries.
  • Patching and Configuration Management: Ensure consistent and timely patching of all systems, especially bastion hosts and development environments. Implement robust asset management to prevent "shadow IT" or forgotten systems.
  1. Rethink Third-Party and Supply Chain Risk: Implicit trust in third-party providers, especially SaaS CI/CD platforms, is a critical vulnerability.
  • Due Diligence & Continuous Monitoring: Treat third-party providers with the same scrutiny as internal systems. Conduct thorough due diligence, negotiate strong security clauses in SLAs, and, crucially, implement continuous logging, monitoring, and tracking of their interactions with your environment.
  • Control over External Interactions: If a third party can mutate your production environment, ensure you have robust controls, auditing, and detection mechanisms in place for their access and activities. Don't grant them carte blanche simply because they're a "professional partner."
  1. Enhance Visibility and Anomaly Detection: Attackers often aim for stealth and long-term persistence, making anomaly detection paramount.
  • Network Monitoring: Implement comprehensive network monitoring to detect unusual traffic patterns, such as 32,000 DNS requests in five minutes from an unexpected source. This level of visibility is non-negotiable for critical infrastructure.
  • Endpoint Detection and Response (EDR): Deploy robust EDR solutions to monitor for suspicious processes, PowerShell scripts, and communication attempts, even if they appear to be benign (e.g., connecting to common cloud regions like AWS US East 1).
  1. Invest in Human-Centric Security: People are consistently the weakest link and the most effective attack vector.
  • Social Engineering Training: Conduct regular, realistic social engineering training that goes beyond simple phishing tests. Educate employees about sophisticated tactics like long-term rapport building, fake job offers, and the use of AI-generated profiles (e.g., the "eye alignment" trick on LinkedIn).
  • Awareness of Personal Device Risks: Educate employees about the risks of shared Wi-Fi, infected USB drives, and unauthorized hotspots, especially when their personal devices interact with work environments or critical systems.
  1. Shift to "Left of Boom" Planning: Move away from a reactive "right of boom" mindset.
  • Threat Modeling: Engage in proactive threat modeling to identify potential attack paths and vulnerabilities before they are exploited.
  • Proactive Defense: Focus resources on prevention and early detection, rather than solely on incident response and cleanup after a catastrophic, silent failure has occurred. The goal is to detect the initial infection or unauthorized access, not just the eventual, devastating outcome.
  1. Secure Industrial Control Systems (ICS) / Operational Technology (OT): The widespread exposure of Modbus (84,991 systems) and MQTT (505,575 systems) on Shodan is unacceptable.
  • Network Segmentation: Strictly segment OT networks from IT networks and the internet.
  • Secure Remote Access: Implement highly secure and monitored remote access solutions for OT, avoiding unauthorized hotspots or direct internet exposure.
  • Update Procedures: Establish secure, air-gapped (where physically possible and rigorously enforced) update procedures for critical equipment, mitigating the risk of "Bob with a hotspot."

Key Takeaways

  • Human Error is the Primary Vector: Nation-state attackers frequently exploit basic human error, complacency, and a lack of fundamental security hygiene to gain initial access and maintain persistence, often bypassing advanced technical controls.
  • The Air Gap is a Myth: No system is truly air-gapped. Physical connections, USB drives, and unauthorized wireless access points will inevitably bridge the gap. Assume connectivity and implement layered defenses, robust internal segmentation, and continuous monitoring.
  • Supply Chain Attacks are Critical: Trusting third-party providers, especially for core functions like CI/CD, introduces significant risk. Adversaries will target these providers to gain access to multiple clients, necessitating rigorous due diligence, continuous monitoring, and strong controls over external integrations.
  • Basic Security Hygiene Remains Paramount: Overlooked fundamentals like USB port control, proper SSH key management (passphrases, no sharing), and consistent patching are often the weakest links that nation-state actors readily exploit.
  • Shift to "Left of Boom" Detection: The focus must move from reactive incident response ("right of boom") to proactive planning, early detection, and prevention ("left of boom"). Nation-state attacks aim for silent, long-term compromise with delayed, insidious consequences, making early anomaly detection crucial.
  • Visibility and Monitoring are Non-Negotiable: Comprehensive logging and monitoring of all network traffic and endpoint activity are essential to detect the subtle indicators of compromise, such as unusual DNS requests or connections to unexpected cloud regions, before they escalate into catastrophic failures.

About the Speaker(s)

N Case (Nathan Casease) is an experienced incident responder. His role in the field involves being called into action when security incidents have already occurred, often at 2 AM, to investigate and remediate breaches. His professional experience provides him with firsthand accounts of the "right of boom" scenarios discussed in the talk, giving him a unique perspective on the real-world impact of security failures.

J McCoy (John McCoy) is presented as a security planner in the context of the talk. His role contrasts with Case's, focusing on proactive measures and strategizing to prevent incidents from happening—the "left of boom" aspect of security. Together, their combined expertise offers a comprehensive view of both the reactive and proactive elements of cybersecurity, particularly against advanced threats to critical infrastructure.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent war-story talk built around four real-world nation-state incidents with decent operational detail, but it never escapes the gravitational pull of well-worn lessons. The case studies are engaging, the left-of-boom framing is useful, but nothing here will surprise a seasoned defender — it's a good on-ramp talk, not a field-advancer.

Heather Calloway (CISO) — SOLID

Competent case-study work that covers real ground — supply chain risk, air gap mythology, CI/CD pipeline compromise — but stays in the technical lane and never fully crosses into institutional accountability or operator-level decision frameworks. Worth watching for defenders and practitioners, but it won't change how a CISO governs their program.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33