BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//hack-lu-2026//speaker//PDBSJ9
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20251023T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T030000
RDATE:20261025T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:When Victims Become Infrastructure: Inside Ink Dragon’s Victim-B
 ased Relay Network - Israel Gubi\, Eli Smadja
DTSTART;TZID=Europe/Luxembourg:20261023T101500
DTEND;TZID=Europe/Luxembourg:20261023T104500
DTSTAMP:20261009T050417Z
UID:pretalx-hack-lu-2026-W8Y8XG@pretalx.com
DESCRIPTION:Some of the most effective malicious traffic is the traffic no
  one thinks to question. In the Ink Dragon campaign\, what appeared to be 
 routine cross-border government connectivity was in fact the first visible
  layer of a hidden relay network. \n\nIn this talk\, we present Ink Dragon
 \, a China-nexus espionage cluster that has targeted government and teleco
 mmunications entities in Southeast Asia and is now expanding into Europe. 
 Rather than deploying new infrastructure\, the actor turned its victims in
 to infrastructure - chaining compromised systems into a multi-hop relay ne
 twork that routed commands and exfiltrated data across organizational and 
 national boundaries while blending into trusted inter-government communica
 tion flows.\n\nWe detail how investigating a single compromised environmen
 t led us to uncover this relay network and map a campaign far larger than 
 any individual victim could see. By pivoting from a compromised endpoint t
 o the upstream relays feeding it and then tracing back downstream to other
  victims behind those same relays\, we correlated activity across environm
 ents that appeared entirely unrelated\, revealing dozens of previously unk
 nown compromised systems while the operation was still active.\n\nThis inv
 estigation required fusing incident response\, reverse engineering\, and t
 hreat intelligence to connect what initially looked like isolated intrusio
 ns into a single coordinated operation. We provide technical deep dives in
 to key components of the actor's arsenal\, and show how analysis of these 
 tools helped us link activity across victims and trace the relay network t
 o its full extent. Ink Dragon is a case study in how modern espionage camp
 aigns are designed to remain invisible at the single-organization level an
 d what it takes to break that design.
LOCATION:Europe
URL:https://pretalx.com/hack-lu-2026/talk/W8Y8XG/
END:VEVENT
END:VCALENDAR
