BSides Atlanta 2025

KMcGrath

Kasey McGrath is an IT security intern at Wellstar Health System and a cybersecurity student at Columbus State University. She enjoys digging into problems, finding patterns, and understanding how things work.


Session

11-15
14:00
50min
The CEO is Calling: A Hacker's Guide to Building and Weaponizing a BEC Demo Environment
Brett Jenson, KMcGrath

The barrier to entry for creating sophisticated, custom phishing infrastructure has officially collapsed. Gone are the days of clunky templates and easily detectable campaigns. In this talk, we'll demonstrate how attackers can now leverage Large Language Models (LLMs) to rapidly clone and deploy pixel-perfect, convincing replicas of any target website and login page in minutes, not hours.

We will bypass the false sense of security offered by traditional MFA portals, showing exactly how modern adversary-in-the-middle (AitM) techniques render them ineffective. We'll provide a minimalist's guide to the backend, covering the bare-minimum PHP requirements for implementing convincing routing and live credential capture. This session moves beyond theory, culminating in a live Business Email Compromise (BEC) demo built from scratch specifically for the BSides Atlanta audience. We'll explore why this hyper-accessible threat is more dangerous than ever and what it means for the future of our defensive strategies. Attendees will leave with a sobering understanding of how quickly bespoke offensive tooling can be created and deployed in the real world.

Shared Knowledge, Shared Defense
Room 300