Killing Killnet

Alex Holden

DEF CON 33 · Day 1 · Main Stage

In a captivating talk at DEF CON, Alex Holden, a cybersecurity veteran and founder of Hold Security, unveiled an extraordinary tale of cyber warfare and unconventional disruption. Titled "Killing Killnet," the presentation detailed a bold, multi-faceted operation to dismantle Killnet, a notorious pro-Russian hacktivist group. This wasn't a story of traditional network defense, but rather an intricate intelligence-led campaign that targeted the group's financial and operational lifelines through an unexpected vector: a major Russian dark web drug marketplace.

AI review

Holden presents a genuinely novel intelligence operation with real-world consequences — not a framework, not a product pitch, not a retrospective sanitized for LinkedIn. The chain from a PHP help request to persistent backdoor to charity redirect to full source dump is specific, documented, and actually happened. Minor gap is that the technical escalation chain (SSH keys → Ansible → Zabbix) is described but not demonstrated at a level that lets a practitioner reproduce the methodology.

Watch on YouTube