How to Become One of Them: Deep Cover Operations in Cybercriminal Communities
Recon Village @ DEF CON 33 • 8th, 9th and 10th August 2025
Abstract
HUMINT is one of the most powerful, yet least understood tools in cyber threat intelligence. This talk will walk through the full lifecycle of a deep cover HUMINT operation-from identifying high-value sources, to crafting believable personas, navigating forum dynamics, and extracting intelligence through direct engagement with threat actors. We’ll explore how these operations provide early warning of attacks, insights into actor motivations, and access to tools before they’re deployed. But going undercover isn’t without risk. We’ll cover the technical and psychological challenges, OPSEC fundamentals, and ethical dilemmas that define this high-stakes work. Attendees will learn how to map underground communities, build credibility, and collect actionable intelligence without blowing cover. With real-world examples and field-tested strategies, this session offers a rare look inside the human side of CTI-where trust, deception, and tradecraft matter more than tooling. For anyone serious about adversary engagement, this is where the automation ends-and infiltration begins.
Speakers
GroupSense, Threat Intelligence Research Manager
Kaloyan Ivanov began his journey in cybersecurity in 2020 and now leads as the Manager of Threat Intelligence Research at GroupSense.
View full speaker profile →GroupSense, Sr. Manager of Threat Intelligence
Sean Thomas Jones is an accomplished Senior Information Security Professional with decades of experience in successfully stopping hackers, securing networks and applications by using best practices, tools and technologies. He currently works as a Sr Manager with a Threat Intelligence Analyst team to protect the cyber and physical assets of governmental, corporate and high profile individuals.
View full speaker profile →