Bad Bears, Careless Kittens: State-Sponsored Espionage Exposed
Nation-state operators are often treated as disciplined, sophisticated, and untouchable. But sometimes, their own infrastructure tells a different story.
In this talk, we examine two active espionage campaigns linked to Russia’s GRU and Iran’s MOIS where exposed command-and-control infrastructure revealed source code, operator logs, tooling, and evidence of live operations. By turning the adversaries’ own mistakes against them, we show how defenders can move beyond indicators and gain rare insight into how state-backed campaigns actually function.
This is a story about C2, OPSEC failures, and what happens when the hackers accidentally expose themselves.
Command-and-control infrastructure is meant to give adversaries control. In March 2026, it gave Ctrl-Alt-Intel visibility instead.
This talk presents a comparative analysis of two exposed nation-state operations: one linked to Russia’s GRU, the other to Iran’s MOIS. Both campaigns independently made the same fundamental mistake: leaving operational infrastructure exposed to the public internet. What followed was a rare look inside active espionage activity, including custom malware frameworks, live C2 components, operator artefacts, and campaign data tied to government, military, healthcare, aviation, and critical infrastructure targets.
The session will compare the two campaigns across targeting, tooling, persistence, infrastructure choices, and OPSEC failures. It will also challenge a common assumption in threat intelligence: that “advanced” actors are always operationally secure. In reality, even top-tier adversaries make basic mistakes when speed, scale, and institutional inertia override discipline.
Attendees will leave with practical lessons for hunting exposed adversary infrastructure, extracting defensive intelligence from attacker mistakes, and safely translating C2 exposure into detection, disruption, and victim notification.
Ben Folland is a volunteer researcher at Ctrl-Alt-Intel, where they investigate cybercrime and
espionage operations, track threat actor infrastructure, analyze TTPs, and expose threat actors.
His professional work has included stopping Akira affiliates, responding to Qilin, and Space Bear
ransomware incidents, investigating Storm-2603 activity linked to Warlock ransomware, tracking
Chinese adversaries targeting IIS servers for SEO fraud, and hunting DPRK malware used in
supply-chain attacks.
They are passionate about DFIR, threat hunting, CTI, malware analysis, and OSINT, and
regularly write about security research at Ctrl-Alt-Intel. They have previously spoken on the main
stage at DEF CON, as well as hack.lu, Malware Village, DC441905, and multiple BSides events.