Hack.lu 2026

Hunting requires a bit of luck

Behind the facade of modern Content Delivery Networks (CDNs) like Cloudflare, malicious threat actors frequently hide their true infrastructure to evade network-level scanning, block automated detection, and hinder attribution. Yet, even the most calculated psychological operations are prone to human error, and sometimes, effective threat hunting just requires a bit of luck. This presentation walks through a high-stakes, real-world investigation into an aggressive disinformation and smear campaign targeting the international press freedom organization Reporters Without Borders (RSF).

We demonstrate how standard Cyber Threat Intelligence (CTI) workflows combined with targeted Open Source Intelligence (OSINT) and a stroke of operational serendipity can completely tear down a CDN-backed defense.

Through a collaborative effort, two threat analysts (one from RSF Nicolas DIAZ and the other one Felix Aimé) successfully unmasked the origin web server of a malicious cybersquatted domain used to denigrate the NGO. Bypassing Cloudflare’s proxy allowed the team to map out the adversary’s broader digital footprint, leading directly to the technical attribution of (at least) one French communication agency. Attendees will gain a deep technical understanding of infrastructure tracking methodologies and witness how contemporary domestic influence operations, such as those executed by Progressif Media, are increasingly borrowing leaf-by-leaf from the psychological warfare and TTP manuals of notorious actors like the Wagner Group.


Modern influence operations have evolved far beyond basic botnets; today, they leverage sophisticated corporate structures, search engine optimization (SEO) manipulation, and enterprise-grade network obfuscation. When an aggressive disinformation campaign targeted Reporters Without Borders (RSF) using a deceptive, cybersquatted domain ("reporterssansfrontieres.fr"), the attackers hid their origin server behind a Cloudflare CDN proxy. To the casual defender, the trail ended at Cloudflare's generic IP blocks. However, a joint investigation by two analysts sets out to crack this facade using an efficient mix of OSINT tools, CTI platforms, and a critical bit of hunter's luck.

The technical breakthrough did not happen overnight but was sparked by a classic operational security (OPSEC) failure on the adversary's part. While the attackers properly routed their primary web traffic through Cloudflare, the analysts hypothesized that backend configuration oversights could leak the true origin IP. The investigation followed a multi-stage threat-hunting workflow:
Passive DNS and Historic Tracking: Analysts scrutinized historical DNS records across multiple repositories, looking for the brief window of time before the domain was officially proxied behind Cloudflare's infrastructure.
The "Stroke of Luck" (The Leak): The turning point occurred during an infrastructure update by the threat actors. For a short window, the DNS of the origin web server’s IP was revealed. Just one internet scanner captured this exposure, mapping a unique SSL certificate serial number directly back to a bare-metal server hosted outside the CDN's IP range.

Once the real IP of the web server was revealed, the house of cards collapsed. Cross-referencing the netblock ownership, historical SSH keys, and co-hosted staging sites uncovered an interconnected cluster of infrastructure. This digital evidence led to the hard attribution of one communication agency pulling the strings behind the campaign.
Crucially, the detailed analysis of the campaign mechanics—later supported by internal documents from the agency obtained by RSF's investigation team —revealed that Progressif Media was deeply inspired by the Tactics, Techniques, and Procedures (TTPs) of the Wagner Group (specifically their infamous troll farms and influence apparatus). The agency didn’t just spin narratives; they utilized systematic cybersquatting, algorithmic boosting via paid Google ads, automated trolling, and coordinated narrative amplification to destroy reputations. This talk breaks down the exact OSINT queries, technical pivot strategies, and mindset required to bypass modern CDNs, proving that while threat hunting relies on rigorous methodology, a bit of luck can turn the tide against sophisticated adversaries.

Nicolas DIAZ

Nicolas Diaz is a cyber security enthusiast. He studied linguistics until 1995 before becoming passionate about the internet. Nicolas turned to webmastering, completely self-taught. In 1999, within the International Federation for Human Rights (FIDH), he was trained by a French Navy system and network engineer. He then worked for the FIDH NGO for more than 15 years, training human rights defenders and journalists from around the world to improve the security of their communications.

Nicolas Diaz is a fervent promoter of open source and free software as an ally of human rights defenders. He was a Community Manager for YesWeHack from 2016 to 2019, and from 2020 to December 2022 was in charge of cyber projects for R&D company DIATEAM in Brest. Since 2023 he is the Chief Information Security Officer at Reporters Without Borders.

Félix Aimé

Félix is a Threat Intelligence specialist with 15 years of experience. Having previously worked at ANSSI and Kaspersky, he is now a Principal Threat Intelligence Researcher at Sekoia. His main areas of expertise include hunting for emerging threats, developing user-friendly software tools, and sharing his knowledge to enhance his team’s ability to discover, track, and analyze new cyber threats.