Zero, Dark and Dirty – Zero Trust like you’ve never seen it before
Download resourcesAbout this session
Aamir Lakhani, a global threat research architect at Fortinet presenting in a personal capacity, delivers a demo-heavy tour of how attacks really work and why Zero Trust alone cannot stop them. He restates Zero Trust principles (authenticate, grant least access, isolate and segment breached assets) and where it fits: identity and access control, device discovery, IoT and OT devices, and simplifying VPN or cloud access. He then shows why detection is hard: a trivial backdoored Adobe Reader on VirusTotal evades many engines, and cheap stolen data funds a financially motivated crime economy. Live demos walk through the BlackEye and Social Engineering Toolkit phishing kits with Let's Encrypt certificates, a leaked ransomware negotiation chat, a 'build your own botnet' framework, Shodan scans for exposed VNC and RDP, and the typical phish-to-botnet-to-ransomware timeline. He covers evolving vectors such as smart-speaker skill squatting and IoT targeting of remote workers, then his own researcher workflow using Cuckoo Sandbox, an IOC database and Maltego for attribution. He closes with a survivorship-bias war story to argue that awareness, education and layered defence matter more than any single product.
This is not your father’s Zero Trust presentation. This talk will look at offensive playbooks used by threat actors to attack organizations like yours and how a Zero Trust Architecture forces you to think about how you enforce internal and
external policies. But what are those policies really capable of protecting, and how can they be broken? All roads lead nowhere. Trust No One.
Key takeaways
- Zero Trust helps by isolating and segmenting breached assets, but it does not stop attacks on its own; treat it as one part of a layered ecosystem.
- Do not read VirusTotal as a vendor scoreboard: a brand-new backdoored file evades many engines there yet may still be caught in a real deployment.
- Phishing kits like BlackEye and the Social Engineering Toolkit make convincing credential-harvesting sites, complete with valid TLS certificates, in under a minute.
- Modern botnets are content-delivery frameworks for attacks; ransomware is usually the last step after persistence, lateral movement and data exfiltration.
- Put remote desktop behind a VPN and watch IoT and OT devices, since attackers now scan Shodan for exposed RDP and VNC and target home and gaming users to reach corporate networks.
Speakers

Aamir Lakhani is a leading global threat research architect at FortiGuard Labs. He provides IT security solutions and cybersecurity strategies to major enterprises and government organizations. Mr. Lakhani creates technical security strategies and… Read moreRead less
Aamir Lakhani is a leading global threat research architect at FortiGuard Labs. He provides IT security solutions and cybersecurity strategies to major enterprises and government organizations. Mr. Lakhani creates technical security strategies and leads security implementation projects for Fortune 500 companies. Industries of focus include healthcare providers, educational institutions, financial institutions, and government organizations. Aamir has designed offensive counter-defense measures for the Department of Defense and national intelligence agencies. He has also assisted organizations with safeguarding IT and physical environments from attacks perpetrated by underground cybercriminal groups. Mr. Lakhani is considered an industry leader for creating detailed security architectures within complex computing environments. His areas of expertise include cyber defense, mobile application threats, malware management, Advanced Persistent Threat (APT) research, and investigations relating to the Internet’s dark security movement. He is the author or contributor of several books, and has appeared on FOX Business News, National Public Radio, and other media outlets as an expert on cybersecurity.
