How to Become One of Them: Deep Cover Ops

Sean Jones (Senior Manager · Groupsense), Kaloyan Ivanov

Recon Village @ DEF CON 33 · Day 1 · Recon Village

Overview

In an era increasingly dominated by automated tools, artificial intelligence, and vast Open-Source Intelligence (OSINT) scraping, the human element in cyber threat intelligence often feels overlooked. This talk, "How to Become One of Them: Deep Cover Ops," presented by Sean Jones and Robert Rosio of Groupsense at Recon Village, challenges this perception by advocating for the indispensable role of Human Intelligence (HUMINT) in understanding and preempting cyber threats. The speakers meticulously outline the full lifecycle of deep cover operations within cyber criminal communities, arguing that while technology can gather data, it cannot build the trust necessary to penetrate closed networks, understand adversary intent, or access high-value, pre-public intelligence.

Watch on YouTube

Visual summary for How to Become One of Them: Deep Cover Ops by Sean Jones, Kaloyan Ivanov
Visual summary for How to Become One of Them: Deep Cover Ops by Sean Jones, Kaloyan Ivanov

Key moments

  1. 0:00 Introduction to Deep Cover Ops and HUMINT's value
  2. 2:00 The enduring relevance of Human Intelligence in CTI
  3. 2:20 Overview of the deep cover operation lifecycle
  4. 6:00 Practical approach to engaging darknet initial access brokers
  5. 8:00 Real-world example: Threat actors revealing pre-market access

How to Become One of Them: Deep Cover Ops

Speakers: Sean Jones, Senior Manager, Groupsense; Robert Rosio, Threat Intelligence Analyst, Groupsense

Conference: Recon Village

YouTube: https://www.youtube.com/watch?v=aSOiPxOBs1E

Overview

In an era increasingly dominated by automated tools, artificial intelligence, and vast Open-Source Intelligence (OSINT) scraping, the human element in cyber threat intelligence often feels overlooked. This talk, "How to Become One of Them: Deep Cover Ops," presented by Sean Jones and Robert Rosio of Groupsense at Recon Village, challenges this perception by advocating for the indispensable role of Human Intelligence (HUMINT) in understanding and preempting cyber threats. The speakers meticulously outline the full lifecycle of deep cover operations within cyber criminal communities, arguing that while technology can gather data, it cannot build the trust necessary to penetrate closed networks, understand adversary intent, or access high-value, pre-public intelligence.

The presentation delves into the intricate tradecraft required to operate undercover, from crafting believable personas and maintaining rigorous operational security to ethically navigating the complex moral landscape of engaging with threat actors. Jones and Rosio highlight that cybercriminals are, at their core, human beings driven by motivations, fears, and social dynamics that automated systems simply cannot discern. By embedding within these communities, intelligence analysts can uncover critical information about imminent attacks, victim targeting, and vulnerabilities long before they manifest in public feeds or technical indicators. This talk is crucial for anyone involved in cyber threat intelligence, national security, or corporate defense seeking to enhance their understanding of adversary operations at a fundamental, human level.

Background

▶ Watch: Introduction to Deep Cover Ops and HUMINT's value (0:00)

The landscape of cyber threat intelligence (CTI) has seen a dramatic evolution, with a significant emphasis placed on technical collection methods. Tools for OSINT scraping, Artificial Intelligence (AI) for data analysis, and automated Indicator of Compromise (IOC) aggregation have become standard practice. While these technologies are powerful for processing vast amounts of publicly available or technically observable data, they inherently suffer from a critical limitation: they cannot access closed-source environments or establish trust with human adversaries. Threat actors frequently operate within small, insular, and often invitation-only communities on the dark web, private messaging platforms, and encrypted forums. These closed networks are beyond the reach of conventional automated collection.

This gap creates a blind spot for defenders, who often only see the aftermath of an attack or indicators that are already public. Historically, across the broader intelligence community, HUMINT has consistently been regarded as one of the highest-impact collection methods, capable of providing insights into intent, motivations, and future actions that technical means cannot. Cyber threat intelligence is no exception. As Robert Rosio emphasizes, "Everything at the base level is humans... These are real people in the real world who do who are doing things and they're secretive people." The problem of closed-source threats necessitates a human approach to penetrate these secretive circles. Prior work in CTI has often focused on analyzing leaked data, malware samples, or network traffic, but rarely on the direct, deep-cover engagement with the individuals orchestrating these threats. This talk posits HUMINT as the missing piece, enabling organizations to "go behind the indicators" and understand "intent" before an attack even materializes. It's about filling the interstitial gaps that automated tools fail to capture, providing proactive, rather than reactive, intelligence.

Key Findings

▶ Watch: The enduring relevance of Human Intelligence in CTI (2:00)

The core finding of this talk is the unmatched efficacy of deep cover HUMINT operations in providing high-confidence, pre-public cyber threat intelligence. Sean Jones and Robert Rosio articulate several critical insights derived from their experience:

  1. HUMINT Closes Critical Intelligence Gaps: Automated tools and scrapers are inherently incomplete. They cannot penetrate closed, insular communities where threat actors plan and execute operations. HUMINT allows analysts to "fill in what's in between" the technical indicators, providing a holistic view of adversary operations, including their intent and targeting, before attacks occur.
  2. Pre-Public, High-Confidence Intelligence: Direct engagement with threat actors allows for the collection of intelligence that is unavailable through public feeds. Examples include "pre-market access" where actors like "Intel Broker" advertise upcoming sales of breaches or access, or private offerings of databases to potential buyers. This intelligence is not only timely but also offers opportunities for threat validation and context gathering that automation cannot provide.
  3. Deeper Understanding of Intent and Targeting: Beyond merely identifying vulnerabilities or stolen data, HUMINT provides insight into why certain targets are chosen, how actors plan to exploit access, and their underlying motivations. This deep understanding is crucial for strategic defense, allowing organizations to anticipate threats rather than merely react to them.
  4. Trust as the Gateway to High-Value Intel: The most significant contribution of HUMINT is its ability to build trust. Unlike technical tools, a human persona can establish credibility within criminal forums, leading to invitations to private chats, early access to tools or data, and direct engagement with respected users. This trust is the "gateway to the intelligence extractions," enabling access to information that is shared casually or through subtle conversation, which would never be explicitly posted on public channels.
  5. Challenges and Risks are Significant but Manageable: The talk thoroughly outlines the substantial operational, technical, legal, ethical, and psychological challenges inherent in deep cover HUMINT. These include navigating legal gray zones, risks of detection and doxing, the time-intensive nature of building credibility, the need for meticulous operational consistency, and the emotional toll on analysts. However, the speakers argue that with careful planning, robust governance, long-term investment, and experienced analysts, these risks can be weighed against the significant intelligence payoff.

In essence, the talk posits that while technology provides breadth, HUMINT provides depth, offering an unparalleled view into the human-centric world of cybercrime.

Technical Deep Dive

▶ Watch: Overview of the deep cover operation lifecycle (2:20)

The technical deep dive into deep cover operations is less about code and more about tradecraft – the systematic methodology and meticulous execution required to operate effectively and securely within hostile environments. The speakers delineate a comprehensive lifecycle, emphasizing precision, patience, and consistency.

1. Source Selection and Prioritization

The initial phase involves identifying potential human sources. This process is guided by concepts like access and placement, asking: "Where is this person sitting and what do they have access to?" Criteria for prioritization include:

  • Reputation: On forums, reputation is currency. Analysts assess a potential source's activity, who they interact with, what they sell, and who they sell to.
  • Network Effect: A source is not just valuable for what they know, but "who they know," serving as a segue into new networks.
  • Risk Analysis: Higher-level sources often carry higher risk. The payout must justify the risk.
  • Alignment with PIRs: All source selection must align with Priority Intelligence Requirements (PIRs) – what specific information is needed.

2. Persona Crafting and Backstopping

This is the foundational element of any deep cover operation. A persona is an entirely artificial online personality, distinct from a physical cover. Key aspects include:

  • Plausible Backstory: The persona must be grounded in a believable narrative, considering their background, origin, and motivations. Inconsistencies are a dead giveaway. The advice: "If you tell all of these different lies, then at some point they might actually have to be true," highlighting the need for a simple, consistent story.
  • Supporting Infrastructure (Backstopping): This involves creating the necessary digital footprint and demonstrable skills to support the persona. If posing as an experienced hacker or access broker, the analyst must possess the requisite knowledge and demonstrate understanding of the tradecraft. This prevents basic questions from exposing the lack of genuine expertise.
  • Basic Level Indicators:
  • Account Creation: Establish accounts for the persona across multiple relevant forums.
  • Alias Consistency: Use the same alias across platforms to build verifiable reputation over time.
  • Passive Engagement: Start by passively listening and observing, mimicking the language, lingo, and "inside jokes" of the community. This allows the persona to integrate naturally.
  • Understanding Ecosystem and Hierarchy: Learn the specific dynamics of each forum, including geographic locations, time zones, linguistic nuances (e.g., "doubt" vs. "question"), and internal hierarchies (admins, moderators, cliques).
  • Operational Security (OpSec): Maintaining OpSec is paramount. A sudden change in posting behavior (frequency, language, time zones) can raise suspicion. Any OpSec failure can lead to doxing or blacklisting from critical communities. Consistency in all aspects – time zone, language, technical claims, background story – is non-negotiable.

3. Building Trust and Credibility

Once the persona is established, the focus shifts to integration and trust-building:

  • Observation and Context Building: Monitor community behavior, trending topics, active users, and social norms (dos and don'ts) to plan entry points and avoid early mistakes.
  • Low-Risk Interactions: Start with seemingly innocuous engagements such as asking technical questions, requesting advice, commenting on tools, or sharing minor, harmless tips. The goal is to show value without trying to "impress."
  • Consistency over Flash: Credibility is built through consistent, sustained, and humble engagement, not by trying to dominate discussions or appear overly confident.
  • Community Alignment: Vouching for trusted users or referencing publicly accepted tools that align with community norms helps solidify the persona's place.
  • Reputational Systems: Many forums use trust scoring, transactional histories, or other milestones. Understanding and navigating these systems is key.
  • Avoiding Pitfalls: Do not post too frequently or too confidently, dominate discussions, mismatch language or slang, or ask too much too soon.

4. Intelligence Extraction

With credibility established, the next phase is intelligence collection without compromising cover:

  • Passive Gathering: Initially, this involves monitoring threads, downloading attachments, and archiving discussions to build context.
  • Direct Engagement: Once trust is high, direct interaction with threat actors becomes possible. This requires subtle social engineering:
  • Subtle Conversation Starters: Instead of direct questions, use shared curiosity or fake collaboration. Examples: "What is the usual threat vector you guys prefer for this?" or "I'm curious, do you test your stuff on corporate networks before selling it?"
  • Peer Presentation: Present oneself as a peer, not an investigator, to encourage open sharing.
  • Data Analysis: If data is passed (e.g., Word or Excel files), analyze it offline for metadata that might reveal valuable clues about attribution or technical indicators. Discussions about tools, vulnerabilities, or targeting logic can also yield insights.
  • Proof of Access/Samples: Requesting proof of access or samples, then analyzing them offline, can provide critical technical indicators.
  • Relationship Building: Remember details from previous conversations, reference shared forum culture or jokes, and offer small favors (e.g., code reviews, sharing resources) in exchange for information.
  • Verification and Documentation:
  • Verification: All received information must be verified against external sources (OSINT, internal telemetry) to counter exaggeration or lies from threat actors who are "just trying to make the sale."
  • Structured Documentation: Save all logs, screenshots, and artifacts in a structured, secure format. Tag and timestamp conversations for timeline reconstruction and correlate with OSINT to validate authenticity and identify patterns, campaigns, tools, and Tactics, Techniques, and Procedures (TTPs).
  • Maintaining Cover: Avoid over-asking, breaking forum rules (even in private messages), or asking technical questions that a persona "should not know how to ask." Interactions should be brief, friendly, and always leave room for future engagement.

This detailed methodology underscores that deep cover HUMINT is a deliberate, nuanced, and highly disciplined process, where tradecraft always outmatches tooling.

Demo / Proof of Concept

▶ Watch: Practical approach to engaging darknet initial access brokers (6:00)

While the talk did not feature a live, interactive demonstration or a traditional proof of concept involving code execution, Sean Jones and Robert Rosio effectively illustrated their methodology through real-world examples and screenshots of actual interactions within cyber criminal forums.

One notable example highlighted the practice of "pre-market access" where a well-known threat actor, Intel Broker, would "pre-advertise" upcoming sales of data or access within forum chats. This demonstrates how embedded personas can gain advance notice of significant breaches before they are officially posted for sale or become public knowledge. Another example showcased a private message exchange where a threat actor offered access to a database of a large company, attempting to sell it directly to the Groupsense persona.

The speakers also recounted a specific instance where a client was concerned about access to critical controlled environments being sold online. Their HUMINT team made contact with the threat actor, who passed them information claiming to be legitimate access. Upon validation, it was discovered that the threat actor had simply taken publicly available information about the client and misrepresented it as proprietary access. This anecdote serves as a crucial "proof of concept" for the verification step in HUMINT, underscoring the necessity of external validation to counter threat actor exaggeration and outright lies, preventing wasted resources or misinformed defensive actions.

These examples, while not a live technical demo, serve to validate the premise that direct engagement through deep cover operations yields unique, actionable intelligence and demonstrates the types of interactions and information flows that are only accessible through human presence and trust.

Defensive Implications

▶ Watch: Real-world example: Threat actors revealing pre-market access (8:00)

The insights gleaned from "How to Become One of Them: Deep Cover Ops" carry profound defensive implications for organizations and security teams seeking to enhance their resilience against cyber threats. Understanding the adversary's perspective and methods from the "inside" allows for more proactive and strategic defense.

  1. Proactive Threat Intelligence: The most significant implication is the shift from reactive to proactive threat intelligence. By understanding adversary intent, targeting, and TTPs before attacks are launched, defenders can implement preventative measures. This means identifying potential victims, hardening specific systems, or deploying targeted detections based on information obtained from criminal forums, rather than waiting for IOCs to appear in public feeds.
  2. Enhanced Vulnerability Management: Knowledge of what types of accesses or vulnerabilities are being sought or sold by threat actors can inform and prioritize vulnerability management efforts. If a specific type of database access or a particular software exploit is trending in criminal communities, defenders can focus on patching or securing those assets immediately.
  3. Improved Incident Response Preparation: Understanding the full lifecycle of a deep cover operation, from initial access brokering to data exfiltration and sale, provides critical context for incident response planning. Defenders can better anticipate adversary moves, understand potential exfiltration vectors, and prepare appropriate containment and eradication strategies.
  4. Informing Security Architecture and Controls: Insights into how threat actors validate access (e.g., asking for proof of access or samples) or what information they look for in initial breaches can help organizations design more robust security architectures. This could involve strengthening internal segmentation, enhancing logging and monitoring capabilities for specific data types, or improving access control mechanisms.
  5. Understanding Adversary Motivation and Psychology: The talk emphasizes that threat actors are human. This understanding allows defenders to move beyond purely technical countermeasures to consider the psychological and motivational aspects driving attacks. This can inform security awareness training (e.g., understanding social engineering tactics used by threat actors) and help in predicting future adversary behavior.
  6. Developing Internal HUMINT Capabilities (with Caution): For larger organizations or those with high-value targets, the talk provides a blueprint for potentially developing internal HUMINT capabilities, or at least understanding what to look for when contracting with third-party threat intelligence providers. However, the speakers explicitly caution about the legal, ethical, and psychological complexities, stressing the need for clear internal policies, legal counsel, and experienced analysts. Organizations must weigh the risks and rewards carefully and establish robust governance frameworks.
  7. Validation of Technical Intelligence: HUMINT serves as a powerful validation tool for technical intelligence. As demonstrated by the example of the fake access sale, information from forums needs verification. Defenders can use HUMINT to confirm the credibility of leaked data, assess the authenticity of claims made by threat actors, and avoid acting on false positives or exaggerated threats.

In essence, integrating HUMINT principles into defensive strategies empowers organizations to think like their adversaries, anticipate their moves, and build a more resilient and proactive defense posture.

Key Takeaways

  • HUMINT is Irreplaceable for Deep Insight: Automated tools and OSINT cannot build trust or penetrate closed cyber criminal communities, making human intelligence indispensable for understanding adversary intent and accessing high-value, pre-public information.
  • Tradecraft Outmatches Tooling: Success in deep cover operations relies on meticulous tradecraft—persona crafting, operational consistency, social engineering, and rigorous documentation—which consistently proves more effective than relying solely on technical tools.
  • Trust is the Primary Gateway: Gaining credibility and trust within criminal forums is the critical enabler for intelligence extraction, leading to access to private discussions, early data, and candid insights unavailable through other means.
  • Patience and Precision are Paramount: Building a believable persona and establishing trust is a time-intensive process that cannot be rushed. Every detail, from language to time zones, must be consistently maintained with precision to avoid detection.
  • Ethical and Legal Considerations are Crucial: Deep cover operations exist in legal and ethical gray zones. Organizations must establish clear policies, consult legal counsel, and analysts must be aware of the psychological toll and avoid actions that directly harm innocent parties.
  • Verification and Documentation are Non-Negotiable: All intelligence gathered must be rigorously verified against external sources, and every interaction meticulously documented to ensure its actionability, maintain a legal trail, and preserve evidence.

About the Speaker(s)

Sean Jones is a Senior Manager at Groupsense, bringing decades of experience as an accomplished senior information security professional. His career has involved extensively "breaking things, building things," and securing networks and applications through best practices and technology. He also describes stumbling upon "three-letter agency honeypots" while keeping people safe and collecting "cool stories," indicating a diverse background in both offensive and defensive security, potentially with government exposure. He is also noted as a "Defcon goon," highlighting his deep involvement and standing within the cybersecurity community.

Robert Rosio is a Threat Intelligence Analyst with Groupsense. His career began in US special operations, providing him with a strong foundation in intelligence collection and analysis. In his current role, he focuses on intel collection and analysis, particularly in areas like ransomware negotiations and human intelligence. He emphasizes his privilege to apply his skills to protect people, underscoring a mission-driven approach to his work in cyber threat intelligence.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent tradecraft walkthrough from practitioners who've clearly done this work, but the content sits firmly in 'solid methodology explainer' territory rather than anything that advances the field. The intel lifecycle they describe — persona building, trust cultivation, verification loops — is real and useful, but it's not new, and the talk leans heavily on structure and framework over the kind of specific operational detail that would make it genuinely memorable.

Heather Calloway (CISO) — SOLID

A competent walkthrough of cyber HUMINT tradecraft with genuine operational grounding, but it stays in practitioner mode and never makes the leap to institutional decision-making. Useful for analysts who do this work; limited for the leaders who have to authorize, govern, and absorb the liability of it.

→ Top-rated talks at Recon Village @ DEF CON 33

All talks from Recon Village @ DEF CON 33