In this session, we’ll dive into a multi-stage attack campaign that resulted in a major financial fraud in Brazil, where a threat group escalated from rudimentary network intrusions - leveraging compromised home and small business routers - to a highly effective social engineering operation targeting contact center operators. Drawing from firsthand forensic investigations, we’ll walk through the group’s initial tactics, including physical implants and unauthorized access in remote branches, and how these evolved into a sophisticated social engineering vector that ultimately enabled a $15M (USD) fraud. You’ll see how the attackers adapted over time, exploited both technical and human vulnerabilities, and maintained persistence in the environment. This talk will present timeline reconstruction, threat actor behavior, missed detection opportunities, and key lessons learned - offering actionable insights for defenders, red teamers, and incident responders alike.
Presented at Ekoparty Miami 2026