Félix Aimé
Félix is a Threat Intelligence specialist with 15 years of experience. Having previously worked at ANSSI and Kaspersky, he is now a Principal Threat Intelligence Researcher at Sekoia. His main areas of expertise include hunting for emerging threats, developing user-friendly software tools, and sharing his knowledge to enhance his team’s ability to discover, track, and analyze new cyber threats.
Session
Behind the facade of modern Content Delivery Networks (CDNs) like Cloudflare, malicious threat actors frequently hide their true infrastructure to evade network-level scanning, block automated detection, and hinder attribution. Yet, even the most calculated psychological operations are prone to human error, and sometimes, effective threat hunting just requires a bit of luck. This presentation walks through a high-stakes, real-world investigation into an aggressive disinformation and smear campaign targeting the international press freedom organization Reporters Without Borders (RSF).
We demonstrate how standard Cyber Threat Intelligence (CTI) workflows combined with targeted Open Source Intelligence (OSINT) and a stroke of operational serendipity can completely tear down a CDN-backed defense.
Through a collaborative effort, two threat analysts (one from RSF Nicolas DIAZ and the other one Felix Aimé) successfully unmasked the origin web server of a malicious cybersquatted domain used to denigrate the NGO. Bypassing Cloudflare’s proxy allowed the team to map out the adversary’s broader digital footprint, leading directly to the technical attribution of (at least) one French communication agency. Attendees will gain a deep technical understanding of infrastructure tracking methodologies and witness how contemporary domestic influence operations, such as those executed by Progressif Media, are increasingly borrowing leaf-by-leaf from the psychological warfare and TTP manuals of notorious actors like the Wagner Group.