From pocket to Pwn: How we hacked a multinational corp for $200 with what's in our pockets
Tim Shipp
BSides NYC 2025 (0x05) · Day 1 · Tech - Red
In this compelling BSides NYC talk, Tim Shipp, CTO and co-founder of Threat Lights, unveils a highly effective, low-cost attack methodology that successfully compromised a multinational corporation. Titled "From pocket to Pwn: How we hacked a multinational corp for $200 with what's in our pockets," the presentation details a red team engagement where traditional, sophisticated attack vectors proved ineffective against a well-defended target. The core of the strategy involved leveraging readily available, inexpensive hardware to perform a physical proximity attack, bypassing robust endpoint detection and response (EDR) and security operations center (SOC) capabilities by targeting an often-overlooked attack surface: employee-owned mobile devices and company vehicles.
AI review
A well-executed red team war story with genuine field creativity — $90 hardware, Bluetooth jamming, Flipper Zero masquerade, ADB-over-TCP pivot chain. The attack chain is clever and the BYOD/mobile blind-spot angle is real. But it's a BSides-tier talk doing BSides-tier things: the individual pieces (Flipper Zero BadUSB, Metasploit Android shells, ADB persistence, ESXi evasion) are all documented elsewhere, and the synthesis, while cute, doesn't break new ground at the technique level.