Attack Surface in Motion

Muslim Koser

Recon Village @ DEF CON 33 · Day 1 · Recon Village

Overview

In his compelling Recon Village keynote, "Attack Surface in Motion: Why Today's Threats Don't Knock First," Muslim Koser, a seasoned cybersecurity veteran with over 25 years of experience, presented a stark evolution of the cyber threat landscape. Koser, Vice President at Fortinet and co-founder of Volon (acquired by Fortinet), leveraged his extensive background in cyber threat intelligence and risk management to dissect how the digital battleground has transformed over the past two decades. The central thesis of his talk is that modern cyber adversaries no longer rely on overt, easily detectable reconnaissance or traditional exploitation techniques; instead, they often gain immediate, stealthy access to target networks through readily available stolen credentials, misconfigurations, and sophisticated supply chain compromises.

Watch on YouTube

Visual summary for Attack Surface in Motion by Muslim Koser
Visual summary for Attack Surface in Motion by Muslim Koser

Key moments

  1. 0:00 Welcome and speaker introduction to Recon Village
  2. 2:00 Speaker's background: honeypots (Detox, Shiva) and national CERTs
  3. 4:00 Talk agenda: revisiting attack evolution from 2005 to 2025
  4. 5:40 Starting the 'quiz mode' on past threat actors
  5. 6:00 Analyzing Anonymous: Early anti-establishment hacktivism (2009-2010)
  6. 6:50 Lizard Squad's impact, including the famous Sony hack
  7. 8:00 The brief but intense activity of Lulsec (50 days)

Attack Surface in Motion

Speakers: Muslim Koser, Vice President, Fortinet

Conference: Recon Village

YouTube: https://www.youtube.com/watch?v=N7w6FklAmVA

Overview

In his compelling Recon Village keynote, "Attack Surface in Motion: Why Today's Threats Don't Knock First," Muslim Koser, a seasoned cybersecurity veteran with over 25 years of experience, presented a stark evolution of the cyber threat landscape. Koser, Vice President at Fortinet and co-founder of Volon (acquired by Fortinet), leveraged his extensive background in cyber threat intelligence and risk management to dissect how the digital battleground has transformed over the past two decades. The central thesis of his talk is that modern cyber adversaries no longer rely on overt, easily detectable reconnaissance or traditional exploitation techniques; instead, they often gain immediate, stealthy access to target networks through readily available stolen credentials, misconfigurations, and sophisticated supply chain compromises.

Koser meticulously traced the journey from the early days of ideologically driven hacktivism and mass Distributed Denial of Service (DDoS) attacks to today's highly monetized, interconnected cybercrime ecosystem. He highlighted the profound impact of cloud computing, the proliferation of Internet of Things (IoT) devices, and the widespread adoption of remote work models, all of which have dramatically expanded and diversified the global attack surface. Crucially, Koser emphasized the emergence of Initial Access Brokers (IABs) and the dark web's role as a marketplace for stolen data, particularly infostealer logs, which provide attackers with a direct bypass to network perimeters, rendering traditional "knocking" unnecessary.

This talk is vital for cybersecurity professionals across all sectors because it redefines the fundamental assumptions about how breaches occur. By illustrating the shift from perimeter-focused defense to a model where identity, cloud security, and real-time threat intelligence are paramount, Koser provided a critical recalibration for defensive strategies. His insights underscore the urgency for organizations to adopt a more proactive and adaptive security posture, moving beyond reactive patching and toward comprehensive risk management that accounts for an increasingly dynamic and unpredictable threat environment where the initial compromise often happens without a visible "knock."

Background

▶ Watch: Welcome and speaker introduction to Recon Village (0:00)

To understand the current state of the attack surface, Koser first guided the audience through a historical retrospective, spanning roughly from 2005 to 2015. This period was characterized by different threat actor motivations and attack methodologies compared to today.

Initially, the landscape was dominated by activism-focused groups driven by ideology, often anti-establishment sentiments. Koser presented a "quiz" of old logos, recalling groups like Anonymous (active from 2009-2010, known for anti-establishment activities and splitting into various country- and sector-specific cells), Lizard Squad (known for the 2011 Sony hack), LulzSec (a notoriously active group for only 50 days before arrests, but leaving a significant mark), the Syrian Electronic Army (a pro-Assad group active during the Syrian war), RedHack (a pro-Turkey, anti-political establishment group), AntiSec, and Host Squad Hackers. Their primary tactic was DDoS attacks, often orchestrated through decentralized operations coordinated over IRC channels using tools like Loic. The goal was disruption and protest, not primarily financial gain.

As the decade progressed, a significant shift towards financial crime began to emerge. While activism still exists today, it's no longer the prevalent motivation. The mantra became: "Wherever there is money, I will go." This era (2010-2015) saw the rise of more targeted attacks. Phishing was common, but targeted phishing (or spear phishing) became more sophisticated. This period also saw the prevalence of script kiddies – individuals who would run pre-made tools without understanding their underlying mechanisms. While their numbers declined for a while, Koser noted a recent resurgence, ironically fueled by the accessibility of AI tools that can generate malicious scripts on demand.

Banking trojans like Zeus and Citadel were highly prevalent, utilizing web injects to compromise victim machines and steal financial data. The concept of Crime-as-a-Service (CaaS) began to surface, with actors setting up infrastructures to offer malicious services on the nascent dark web. Cryptocurrencies were not yet mainstream for illicit transactions; instead, a currency called Liberty Reserve (LR) was widely used until a crackdown forced a shift towards Bitcoin and Monero. Ransomware was also in its early stages, still figuring out its monetization model, and Man-in-the-Browser attacks were used, primarily by banking trojans, to manipulate transactions.

Finally, this period also saw the coining of the term Advanced Persistent Threats (APTs). While nation-state attacks like Stuxnet were known, the systematic naming and tracking of these groups by cyber intelligence firms became common practice, marking the formal recognition of state-sponsored cyber espionage and sabotage as a distinct and evolving threat.

Key Findings

▶ Watch: Talk agenda: revisiting attack evolution from 2005 to 2025 (4:00)

The core finding of Muslim Koser's talk is that the traditional "knocking first" paradigm of cyberattacks is largely obsolete. Modern threats prioritize immediate, stealthy access, often bypassing conventional perimeter defenses entirely. This fundamental shift is driven by the radical transformation of the global attack surface and the evolving motivations and capabilities of threat actors.

Koser identified several critical developments:

  1. Expanded and Diversified Attack Surface: The shift from localized, on-prem infrastructure to highly distributed, heterogeneous environments (cloud, IoT, remote work) has fragmented the traditional security perimeter. Organizations now contend with assets across Azure, Google Cloud, AWS, numerous APIs, buckets, and VMs, often managed under shared responsibility models, making comprehensive visibility and control exceptionally challenging.
  2. The Rise of Infostealers and Initial Access Brokers (IABs): This is perhaps the most significant finding. Instead of exploiting vulnerabilities, attackers now frequently purchase infostealer logs or VPN access from IABs on the dark web. These logs, which often contain SSO, mail, and GitHub credentials, provide immediate, authenticated access to corporate networks, effectively "not knocking." Koser highlighted that these credentials can be purchased for as little as $10.
  3. Ransomware's Evolved Ecosystem: Ransomware groups no longer need to conduct extensive reconnaissance or develop zero-day exploits. They form partnerships with IABs, purchasing validated initial access to target networks, escalating privileges, deploying ransomware, and exfiltrating data with unprecedented efficiency. This specialization makes ransomware operations more streamlined and effective. Koser noted a shift in ransomware targets, with an increasing focus on companies with less than $5 million in revenue, indicating a broader, less selective targeting strategy.
  4. AI as an Attack Multiplier: The rapid evolution of AI and Large Language Models (LLMs) has democratized exploit development and attack kit creation. Attackers can now use AI to generate sophisticated phishing kits, malicious scripts, and even chain exploits on the fly, significantly reducing the skill barrier and increasing the speed of attack vector generation. The emergence of "dark AI" models (WarGPT, AutoGPT, FraudGPT, PoisonGPT) without ethical filters further exacerbates this risk, enabling the creation of highly malicious content.
  5. Shift in Darknet Operations: The dark web ecosystem has changed from fostering long-term "personas" and trust among actors to a more transactional, "smash and grab" approach. Actors use disposable profiles to sell stolen data or access, making attribution and tracking far more difficult for intelligence analysts. Communication has also migrated from traditional IRC and Jabber to faster, easier platforms like Telegram and Discord.

In essence, Koser's key finding is that the modern attack surface is in constant motion, characterized by a fundamental shift from traditional, observable exploitation to stealthy, credential-based infiltration, driven by a highly organized cybercrime economy and amplified by emergent technologies like AI.

Technical Deep Dive

▶ Watch: Starting the 'quiz mode' on past threat actors (5:40)

The technical transformation of the attack surface, as detailed by Muslim Koser, is multifaceted, encompassing infrastructure, attack methodologies, and the underlying cybercrime economy.

Evolution of Infrastructure and Attack Surface:

Historically, organizations operated primarily with on-prem infrastructure. Security was localized, focusing on physical data centers and network perimeters. Vulnerability management largely involved patching known flaws and correcting misconfigurations within a defined, manageable scope.

Today, this has been supplanted by a highly distributed and heterogeneous environment. The proliferation of cloud computing means assets reside across multiple providers like Azure, Google Cloud, and AWS. This introduces shared responsibility models, where security duties are split between the cloud provider and the customer, often leading to confusion and misconfigurations. The attack surface now includes countless APIs, storage buckets, and VMs that can be spun up rapidly, sometimes without adequate security oversight. Koser emphasized that IT departments often lack full visibility into all cloud instances, creating blind spots.

The rise of IoT devices further compounds this complexity. From smart TVs and refrigerators to industrial control systems, every connected device represents a potential entry point. Koser cited an example of an attack originating from a vulnerable HVAC system, highlighting the expanded supply chain risk introduced by these devices. Similarly, the post-COVID surge in mobile computing and work from home models has extended the corporate network into employees' homes. Managing endpoint security across diverse, uncontrolled home networks presents significant challenges, as personal devices and family usage can inadvertently introduce vulnerabilities.

AI's Impact on Attack Vectors:

Koser detailed how AI has revolutionized attack techniques. Previously, attackers relied on manual methods, crafting specific scripts, basic fishing kits, templates, and rudimentary malware. Protection was relatively simpler, focusing on known signatures and attack patterns.

Now, AI-powered attacks enable rapid, on-the-fly exploit generation. Attackers can use Large Language Models (LLMs) to create sophisticated phishing kits and templates with minimal effort. By changing parameters or providing different prompts, an AI model can generate numerous variations of an exploit. Beyond mere generation, LLMs are being misused to develop malicious code, chain exploits, and even extract sensitive PII by carefully crafting questions.

A more ominous development is the emergence of "dark AI" models, such as WarGPT, AutoGPT, FraudGPT, and PoisonGPT, available on the dark web. Unlike legitimate LLMs like ChatGPT, these models lack ethical filters, allowing attackers to generate highly malicious content, including exploits, without any restrictions. This significantly lowers the barrier to entry for less skilled individuals, turning them into capable threat actors.

Transformation of the Darknet Ecosystem:

The darknet has also undergone a profound transformation. What was once a realm requiring significant effort to build a "persona" – a strong presence, good reputation, and trusted contacts over time – has become a transactional marketplace. Koser noted that today, actors often use "smash and grab" tactics with disposable, "burn and throw" profiles. They post a single screenshot of a breach, offer the data, and then disappear, making tracking and attribution a nightmare for threat intelligence analysts.

The commodities exchanged have also shifted. Earlier, actors would sell or share databases, vulnerabilities, or services like Crime-as-a-Service, DDoS-as-a-Service, or Ransomware-as-a-Service. Today, the focus is squarely on initial network access and VPN access, which are highly sought after.

This shift is largely due to the arrival of infostealers. These malicious programs hook onto a user's browser, capturing all credentials (passwords, session cookies, multi-factor authentication tokens) for every website visited, then exfiltrating them to a command and control (C2) server. Koser referred to this as the "new oil" of cybercrime. With a purchased VPN credential from an infostealer log, an attacker can bypass traditional authentication, especially if 2FA is not enforced, gaining immediate access to a corporate network without any exploitation. This data is then used for account takeover and reconnaissance.

The IAB-Ransomware Nexus:

A critical technical development is the symbiotic relationship between Initial Access Brokers (IABs) and ransomware affiliates. IABs operate a sophisticated cycle of collecting, parsing, validating, and selling infostealer logs and other forms of initial access. This validation often involves reconnaissance to ensure the access is still viable and valuable.

On the other side, ransomware affiliates no longer engage in extensive, "janky monkey" reconnaissance or exploit development (like searching for SQL injection vulnerabilities). Instead, they directly purchase validated access from IABs. Once inside, they focus on privilege escalation, deploying their ransomware, and exfiltrating data for double extortion. This division of labor creates a highly efficient and effective cybercrime pipeline.

Communication Channel Shift:

Finally, the preferred communication channels for threat actors have also evolved. While IRC and Jabber were once common, they have been largely abandoned. Today, platforms like Telegram and Discord are dominant. These instant messaging platforms are fast, easy to use, and facilitate the distribution of malware kits, coordination of DDoS and activist campaigns, trading of credential data (stealer logs), and execution of social engineering and brand impersonation schemes. This necessitates a shift in threat intelligence monitoring tactics from traditional channels to these modern, encrypted platforms.

Demo / Proof of Concept

▶ Watch: Lizard Squad's impact, including the famous Sony hack (6:50)

While Muslim Koser's talk did not feature a live technical demonstration or a traditional proof of concept, he visually reinforced his points with several screenshots. These screenshots were primarily sourced from dark web forums and marketplaces, illustrating the active trade in "dark AI" models (such as WarGPT, AutoGPT, FraudGPT, PoisonGPT) and the sale of infostealer logs. These visual aids served to confirm the real-world availability and accessibility of the malicious tools and services he discussed, demonstrating how readily attackers can acquire the means to bypass traditional defenses without "knocking." The screenshots showed recent posts on these illicit platforms, underscoring the current and active nature of these cybercriminal operations.

Defensive Implications

▶ Watch: The brief but intense activity of Lulsec (50 days) (8:00)

The paradigm shift articulated by Muslim Koser demands a fundamental re-evaluation of defensive strategies. If today's threats don't knock first, then traditional perimeter-focused security, while still necessary, is no longer sufficient.

  1. Prioritize Identity and Access Management (IAM): Given the prevalence of infostealers and credential theft, robust IAM is paramount. Organizations must enforce Multi-Factor Authentication (MFA) across all critical systems, especially for SSO, mail, and code repositories like GitHub. This is crucial, as Koser explicitly mentioned that a lack of 2FA makes stolen VPN credentials immediately exploitable. Implementing Zero Trust Network Access (ZTNA) principles, where every access request is verified regardless of its origin, becomes indispensable.
  2. Comprehensive Cloud Security Posture Management (CSPM): With assets distributed across Azure, Google Cloud, AWS, and other services, continuous monitoring for misconfigured cloud buckets, APIs, and VMs is vital. Organizations must deeply understand and meticulously adhere to the shared responsibility models of their cloud providers, ensuring their portion of security is rigorously maintained. Automated tools for identifying and remediating cloud misconfigurations are no longer optional.
  3. Enhanced Endpoint Detection and Response (EDR): The expanded attack surface encompassing IoT devices and remote work environments necessitates advanced EDR solutions. These tools are crucial for detecting anomalous behavior, lateral movement, and the presence of infostealers on endpoints, even if the initial access was through legitimate-looking credentials. For remote workers, ensuring corporate devices are securely configured and monitored, irrespective of the home network, is critical.
  4. Proactive Threat Intelligence and Darknet Monitoring: Defenders must actively monitor cybercrime forums, Telegram channels, and Discord servers where infostealer logs and other compromised data are traded. This intelligence can provide early warnings if an organization's credentials are being sold, allowing for proactive password resets or account lockouts before a breach escalates. Understanding the tactics of Initial Access Brokers (IABs) and ransomware affiliates is key to anticipating attacks.
  5. Supply Chain Security: The example of the HVAC system compromise underscores the need for rigorous supply chain security. Organizations must vet the security posture of all third-party vendors and IoT devices connected to their networks, understanding that any vulnerability in these components can serve as a backdoor.
  6. AI Security Awareness and Mitigation: Defenders must be aware of the capabilities of Dark AI models and their potential to generate sophisticated exploits and social engineering campaigns. This requires staying updated on AI-driven attack trends and potentially employing AI-based defensive tools to detect and counter these evolving threats.
  7. Focus on "Bonus" Vulnerabilities: While the "first knock" may be gone, exposed services and vulnerable software still represent "bonus" targets for attackers once they gain initial access. Therefore, diligent patch management and vulnerability assessment remain important for reducing the attack surface after initial infiltration.
  8. Embrace a "Stay Paranoid" Mindset: As Koser concluded, a heightened state of paranoia, coupled with a proactive and adaptive security strategy, is the most effective defense against an adversary that no longer bothers to knock. Assume compromise and build defenses accordingly.

Key Takeaways

  • The traditional cyberattack paradigm of reconnaissance and exploitation ("knocking first") is largely obsolete; modern threats often bypass perimeter defenses directly via stolen credentials and misconfigurations.
  • The attack surface has expanded dramatically due to cloud computing, the proliferation of IoT devices, and widespread remote work, creating a highly distributed and complex environment for defenders.
  • Infostealers are a primary driver of initial access, providing attackers with legitimate credentials (SSO, mail, GitHub) that can be purchased for as little as $10 on dark web marketplaces.
  • Initial Access Brokers (IABs) and Ransomware-as-a-Service (RaaS) groups form a symbiotic ecosystem, enabling efficient and monetized breaches without the need for extensive exploit development by ransomware operators.
  • AI and "dark AI" models significantly lower the barrier to entry for attackers, allowing for rapid generation of sophisticated phishing kits, malicious code, and chain exploits, accelerating the pace of attacks.
  • Defenders must shift their focus from perimeter-centric security to robust Identity and Access Management (IAM) with MFA, comprehensive Cloud Security Posture Management (CSPM), advanced Endpoint Detection and Response (EDR), and proactive threat intelligence including darknet monitoring.

About the Speaker(s)

Muslim Koser is a highly experienced and insightful cybersecurity professional with over 25 years in the field of information security. His expertise spans cyber threat intelligence, cyber risk management, and cybersecurity consulting. Koser currently serves as a Vice President at Fortinet, focusing specifically on attack surface and threat intelligence areas. Prior to this role, he was a co-founder of Volon, a company that was later acquired by Fortinet. His extensive career also includes significant tenures at renowned security firms such as FireEye and I-Partners.

Koser's contributions to the cybersecurity community are notable. He played a crucial role as a core member in establishing national-level CERTs (Computer Emergency Response Teams) in at least two or three different countries, as well as setting up organizational-level CERTs. He was also actively involved in India's honeynet project, where he contributed to the development of early honeypot technologies, including Detox (the first Linux-based honeypot, developed around 15 years prior to the talk) and Shiva (a honeypot specifically designed for spam intelligence collection). His deep and varied experience provides him with a unique perspective on the evolution of cyber threats and the attack surface.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

A Fortinet VP delivers a well-organized but fundamentally thin retrospective on threat evolution that reads more like a vendor awareness deck than security research. The content is accurate and coherently presented, but there's nothing here that a competent threat intel practitioner didn't already know — and the Fortinet affiliation casts a shadow over the whole thing.

Heather Calloway (CISO) — WEAK

Koser knows the terrain and the historical narrative is credible, but this talk stays in briefing mode — it describes the problem landscape without producing decisions. The defensive recommendations are a generic laundry list that any security professional already owns, and there's no governance signal, no accountability frame, and no institutional diagnosis for why organizations remain exposed.

→ Top-rated talks at Recon Village @ DEF CON 33

All talks from Recon Village @ DEF CON 33