About
Nation-states are hijacking residential IoT devices — streaming boxes, smart home tech — to run surveillance and espionage campaigns against energy sector executives and critical infrastructure. This talk covers the TTPs behind campaigns like BADBOX, BADBOX 2, and KIMWOLF, based on original device teardown, firmware reverse engineering, and counterintelligence research conducted with authorities. You'll learn how these actors exploit consumer tech and network blind spots to build hard-to-detect, hard-to-remove distribution networks — and what actions to take in response. No advanced technical background required.