You Get a C2! And YOU Get a C2!: The democratisation of sophisticated Command & Control
Sophisticated espionage focused Command and Control (C2) frameworks and offensive cyber tooling has been historically restricted to use by large powers and developed economies due to the high cost or lack of turn key solutions offered by open source. At the end of the day these platforms are just software suites built to strict and specialised requirements.
LLMs through shifts in software development methodologies have become commonplace in enterprise software development life cycles and have lowered the barriers of the cost, maintainability and flexibility issues plaguing legacy offensive tooling.
In this talk we will explore several frameworks that have been captured from the front lines to see first hand how actual APTs are building and breaking sophisticated C2 frameworks to prompt their way to success.
We will explore the spec driven approaches that produce robust and battle ready tooling without guess work, review examples of development artifacts, documentation and prompts from a mistakenly exposed VoidLinkC2 development server and pass these lessons on to any budding red teamers wanting to replicate this success.
Defenders and researchers need not worry - we will also discuss our lessons learned through researching AI built frameworks and what this means for the way we track and react to these threats in the future.