From pocket to Pwn: How we hacked a multinational corp for $200 with what's in our pockets

Tim Shipp

BSides NYC 2025 (0x05) · Day 1 · Tech - Red

In this compelling BSides NYC talk, Tim Shipp, CTO and co-founder of Threat Lights, unveils a highly effective, low-cost attack methodology that successfully compromised a multinational corporation. Titled "From pocket to Pwn: How we hacked a multinational corp for $200 with what's in our pockets," the presentation details a red team engagement where traditional, sophisticated attack vectors proved ineffective against a well-defended target. The core of the strategy involved leveraging readily available, inexpensive hardware to perform a physical proximity attack, bypassing robust endpoint detection and response (EDR) and security operations center (SOC) capabilities by targeting an often-overlooked attack surface: employee-owned mobile devices and company vehicles.

AI review

A well-executed red team war story with genuine field creativity — $90 hardware, Bluetooth jamming, Flipper Zero masquerade, ADB-over-TCP pivot chain. The attack chain is clever and the BYOD/mobile blind-spot angle is real. But it's a BSides-tier talk doing BSides-tier things: the individual pieces (Flipper Zero BadUSB, Metasploit Android shells, ADB persistence, ESXi evasion) are all documented elsewhere, and the synthesis, while cute, doesn't break new ground at the technique level.

Watch on YouTube