Keynote: Cyber Threats in the Age of AI
Black Hat Asia 2025 · Day 1 · Briefings
Overview
This keynote address, delivered by Edward Chen, Deputy Chief Executive of National Cyber Resilience for the Cyber Security Agency (CSA) of Singapore, delves into the evolving landscape of cyber threats, particularly in an era marked by geopolitical instability and the rapid ascent of Artificial Intelligence (AI). Introduced by Black Hat host Jeff, the talk sets a strategic tone, moving beyond the traditional pursuit of zero-day vulnerabilities to highlight critical, yet often overlooked, foundational security challenges. Chen argues that while AI is reshaping the battlefront, the fundamental weapons of choice for adversaries remain rooted in basic security oversights.

Key moments
- 0:00 Welcome to Black Hat and its core purpose
- 1:20 How Black Hat talks inspire new businesses
- 2:19 Black Hat's global reach and scholarship program
- 3:40 The current chaotic global landscape and great power competition
- 4:20 Business strategies: diversify for predictability, concentrate for returns
- 6:20 Geopolitical pressure creating fragmented tech stacks
- 8:00 Forced choices: aligning with tech stacks and values
Keynote: Cyber Threats in the Age of AI
Speakers: Edward Chen, Deputy Chief Executive, National Cyber Resilience, CSA (Cyber Security Agency of Singapore); Jeff (Black Hat Host)
Conference: Black Hat Asia
YouTube: https://www.youtube.com/watch?v=7HVUgbuX-ZU
Overview
This keynote address, delivered by Edward Chen, Deputy Chief Executive of National Cyber Resilience for the Cyber Security Agency (CSA) of Singapore, delves into the evolving landscape of cyber threats, particularly in an era marked by geopolitical instability and the rapid ascent of Artificial Intelligence (AI). Introduced by Black Hat host Jeff, the talk sets a strategic tone, moving beyond the traditional pursuit of zero-day vulnerabilities to highlight critical, yet often overlooked, foundational security challenges. Chen argues that while AI is reshaping the battlefront, the fundamental weapons of choice for adversaries remain rooted in basic security oversights.
The presentation focuses on what Chen terms "RSA" – Ransomware, Scams, and Advanced Persistent Threats (APTs) – dissecting how these known threats are adapting, becoming more sophisticated, and exploiting the current chaotic global environment. It underscores the urgent need for a multi-pronged, "whole-of-nation" approach to cyber resilience, emphasizing strong legal mandates, deep technical expertise, and robust international partnerships. The talk serves as a call to action for defenders to prioritize foundational cyber hygiene, cultivate agility, and proactively leverage AI to anticipate and counter emerging threats.
The significance of this keynote lies in its pragmatic assessment of the current cyber threat landscape. It challenges the industry to look beyond the allure of cutting-edge exploits and instead address the pervasive, fundamental weaknesses that adversaries consistently exploit. By presenting real-world case studies and operational insights from Singapore's experience, Chen provides a clear, actionable framework for governments, businesses, and individuals to enhance their cyber security posture amidst increasing complexity and interconnectedness. It highlights that in this "infinite game" of cyber security, success hinges not just on technological prowess but on mindset, discipline, and collaborative action.
Background
▶ Watch: Welcome to Black Hat and its core purpose (0:00)
The talk opens with Jeff, a Black Hat host, setting the stage by describing the current geopolitical climate as "chaotic" and "unpredictable," characterized by "great power competition." He references global events like the Ukrainian-Russian war, tensions with China and Taiwan, and US sanctions, which collectively contribute to an environment of uncertainty. This chaos, he suggests, is leading to a fragmentation of the global technology landscape, with regions like Europe and China contemplating their own distinct tech stacks, potentially forcing companies and nations to make difficult, often conflicted, choices based on regulation and geopolitical alignment. This shift from a unified, lean, and centralized model towards diversified, potentially less efficient, and more resilient systems is a key contextual element.
Within this turbulent backdrop, the rapid emergence of AI introduces new dynamics. Jeff raises concerns about an "AI gap" between competing powers, although Edward Chen later posits that AI will likely lead to multiple winners tailored to specific national and economic objectives (e.g., manufacturing-focused AI in China vs. feature-rich AI in the West). The central problem highlighted is that in the race to innovate and adapt to these new technologies and geopolitical pressures, fundamental security often takes a back seat. Chen illustrates this with examples of early vulnerabilities in leading AI systems like ChatGPT and DeepMind. In both instances, the critical flaws were not AI-specific exploits but rather basic security oversights: a web cache vulnerability in ChatGPT and unsecured open ports in DeepMind's database. These incidents underscore a recurring theme: while AI is transforming how information is consumed and created, the "weapons of choice" for adversaries remain rooted in unpatched systems, weak credentials, and human errors. The talk thus positions itself as a critical reminder that foundational cyber security is not just important but the "bedrock of cyber resilience" in an increasingly complex world.
Key Findings
▶ Watch: Black Hat's global reach and scholarship program (2:19)
Edward Chen's keynote delivers several critical findings, emphasizing that while the cyber landscape is evolving with AI, many core vulnerabilities persist and are actively exploited. The central theme revolves around the "RSA" threats – Ransomware, Scams, and APTs – which are not only persistent but are also adapting in sophisticated ways that challenge traditional security paradigms.
First, a foundational finding is that basic security oversights remain the primary entry points for adversaries, even in cutting-edge AI environments. The vulnerabilities discovered in ChatGPT (a web cache vulnerability) and DeepMind (unsecured open ports) were not complex AI exploits but rather fundamental errors. This highlights that the "race to innovate" often leads to the neglect of essential cyber hygiene, making unpatched systems, weak credentials, and human errors the persistent weak links.
Second, ransomware activity has surged globally and locally, with Singapore experiencing a 20% increase in reported cases last year, mirroring global trends. Over 40 new ransomware groups emerged globally in 2024, acting like a "hydra" where new groups quickly replace dismantled ones. Key trends identified include:
- Victimology Shift: Professional services (e.g., small-to-medium law firms, business consultants) have become the second most impacted sector in Singapore, targeted for their disproportionately large amounts of sensitive client data.
- Asset Targeting: A shift from locking up email systems to directly targeting network-attached storage (NAS) systems, leading to data exfiltration and wiping without deploying encryption payloads, relying solely on the threat of data loss or leaks.
- Multi-Party Extortion: Ransom demands are now issued not only to the directly affected vendor but concurrently to their financial services clients and even end-customers whose data was stolen, maximizing coercion.
Third, scams have reached record highs in Singapore, with a 10% increase in cases and total losses exceeding a billion dollars in 2024 due to a 70% surge. An investigation into a transnational job scam syndicate revealed:
- Extreme Automation and Speed: Scammers designed their operations with end-to-end automation, using Telegram bots for full remote administration, capable of registering new domains and spinning up web hosting infrastructure for new campaigns in mere minutes.
- Significant Agility: The syndicate operated across multiple jurisdictions, hosting infrastructure in one region while targeting victims in another, effectively evading law enforcement.
- Robust Resiliency: They employed Docker containerization for easy redeployment and used automated bash scripts to routinely back up databases via Telegram every two hours, enabling rapid recovery within minutes or hours of infrastructure takedowns.
Finally, Advanced Persistent Threats (APTs) are becoming increasingly sophisticated and pervasive. While typically covert, Chen shared details of an international operation that disrupted a global botnet, believed to be used by an APT actor, which infected hundreds of thousands of devices, including 2,700 in Singapore. Technical observations included:
- Advanced Architecture: A special variant of Mirai malware operating on a sophisticated three-tier architecture (C2, payload, exploitation servers), suggesting extensive groundwork for sustained campaigns.
- Broad Compatibility: Support for diverse processor architectures, including less common ones like Power PC and SH4, indicating an ambition to compromise embedded systems, routers, industrial equipment, and even baby cameras.
- Novel Orchestration: The cross-platform malware orchestration framework was so advanced that its developer even sought a patent for it, highlighting a new level of sophistication and professionalization in APT operations.
These findings collectively paint a picture of an adversary that is highly adaptable, technically proficient, and leveraging both basic vulnerabilities and cutting-edge operational frameworks to achieve their objectives in a fragmented and chaotic world.
Technical Deep Dive
▶ Watch: The current chaotic global landscape and great power competition (3:40)
The keynote provides compelling technical insights into the evolving tactics of ransomware groups, scam syndicates, and APT actors, grounded in real-world investigations by the CSA.
Ransomware Evolution: Beyond Encryption
Chen highlights a significant shift in ransomware operations, moving beyond mere data encryption to more aggressive and efficient extortion methods.
- Targeted Victimology: Professional services, such as small and medium-sized law firms and business consultants, are increasingly targeted. The rationale is their management of disproportionately large amounts of sensitive client data, making them perceived as more susceptible to coercion. This contrasts with previous trends that often focused on larger enterprises or specific industries.
- Asset Focus: Attackers are moving away from solely compromising email systems. The new trend involves directly targeting network-attached storage (NAS) systems. These systems often hold critical operational data, backups, and intellectual property, making their compromise highly impactful.
- Encryption-less Extortion: A particularly notable departure is the observed tactic of skipping the encryption phase entirely. Upon gaining access to NAS systems, threat actors would exfiltrate data and wipe the remaining files, leaving behind only ransom demands for data recovery. This prioritizes simplicity and speed, as it eliminates the computational overhead and time required for encryption. The coercion relies solely on the threat of data loss or data leaks, leveraging the victim's fear of regulatory penalties, reputational damage, and operational disruption.
- Multi-Party Pressure: The extortion model has expanded. In a case involving a local IT vendor serving the financial services industry, the threat actor not only demanded ransom from the affected vendor but concurrently extorted the financial services firm and even their end-customers whose data had been stolen. This tactic reflects a sophisticated understanding of supply chain interdependencies and the application of pressure across the entire trust chain to maximize the chances of payment.
Scam Syndicates: Engineering for Automation and Resilience
The investigation into a transnational job scam syndicate revealed a level of operational sophistication that resembles a well-run tech company.
- End-to-End Automation via Telegram Bots: The syndicate designed its operations with full remote administration capabilities, leveraging Telegram bots. This allowed them to automate core processes like registering new domains and spinning up new web hosting infrastructure for new campaigns in a matter of minutes. This rapid deployment capability enabled them to launch over 110 different scam campaigns, targeting more than 3,000 victims over two years. The use of a popular, encrypted messaging platform like Telegram for command and control also adds a layer of obfuscation and ease of use for the operators.
- Cross-Border Agility: The syndicate demonstrated significant agility by deploying infrastructure across multiple jurisdictions. Investigators used IP geolocation and contextual clues (e.g., colloquial language in scam messages) to assess the likely origin of operators, which was often different from the victim's country. This cross-border operation model, hosting infrastructure in one region while targeting victims in another, is a deliberate strategy to evade law enforcement by complicating jurisdiction and attribution.
- Containerized Resilience: The syndicate leveraged Docker containerization for their infrastructure, which made redeployment exceptionally easy and fast. This meant that even after successful infrastructure takedowns by law enforcement, the syndicate could bounce back quickly. Furthermore, automated bash scripts were used to routinely back up their databases via Telegram every two hours. This combination of containerization and automated, off-site backups ensured minimal effort or data loss and allowed operations to resume within minutes or hours of a disruption, showcasing a robust business continuity plan that many legitimate enterprises would envy. Chen quipped that these scammers could have been "competent CIOs in their past lives."
Advanced Persistent Threats (APTs): Sophisticated Botnet Operations
Chen detailed insights from an international operation against a global botnet, believed to be operated by an APT actor, highlighting its advanced technical characteristics.
- Three-Tier Mirai Variant Architecture: Unlike traditional botnets with a single layer of Command and Control (C2) servers, this variant utilized a sophisticated three-tier architecture. This included dedicated payload and exploitation servers in addition to C2 servers. This multi-layered design suggests the actor was not merely operating the botnet for immediate use but was actively laying the groundwork for a more extensive and sustained campaign, indicating long-term strategic objectives. The mention of it being a "special variant of the Mirai malware" points to customization and adaptation of existing, well-known botnet frameworks.
- Extensive Cross-Platform Compatibility: The botnet demonstrated support for an unusually diverse range of processor architectures, including Power PC and SH4, which are less commonly targeted in conventional malware campaigns. This broad compatibility suggests an ambition for scale, aiming to compromise not only standard IT devices but also embedded systems, routers, industrial equipment, and even consumer devices like baby cameras. Such a wide targeting approach reflects a well-resourced adversary seeking to maximize the botnet's reach and persistence across varied digital infrastructure.
- Patented Malware Orchestration Framework: Perhaps one of the most striking revelations was that the cross-platform malware orchestration framework used was so advanced and novel that its developer "even felt a patent application for it." While potentially a rhetorical flourish, it underscores the significant research and development investment by the APT actor, suggesting a level of professionalization that rivals legitimate software development. The idea of a patent office inadvertently documenting threat intelligence highlights the blurring lines between legitimate and illicit innovation.
- Detection Strategy: Despite the sophistication, the botnet was detectable. Notable indicators included unique ports used for C2 callback and naming patterns in TLS certificates. Adopting such detection strategies enabled preemptive identification and disruption of malicious infrastructure before it could be fully leveraged by threat actors.
These technical deep dives illustrate how adversaries are innovating not just with new exploits but by optimizing their operational workflows, leveraging existing technologies in novel ways, and demonstrating exceptional resilience and adaptability.
Demo / Proof of Concept
▶ Watch: Geopolitical pressure creating fragmented tech stacks (6:20)
As a keynote address focused on strategic insights and threat landscape analysis, this talk did not include a live technical demonstration or proof of concept. Edward Chen explicitly stated at the outset, "If you are here expecting a deep dive into cutting edge AIdriven cyber attacks, I have news for you. I'm not revealing any zeroday CVE." Instead, the speaker presented detailed case studies and technical observations from real-world incidents investigated by CSA, illustrating the operational mechanics and sophisticated tactics of ransomware, scam syndicates, and APT botnets.
Defensive Implications
▶ Watch: Forced choices: aligning with tech stacks and values (8:00)
The insights shared by Edward Chen carry significant defensive implications for organizations, governments, and individuals navigating the complex cyber landscape in the age of AI and geopolitical chaos.
Prioritize Foundational Cyber Security: The most critical implication is the unwavering emphasis on foundational cyber security. Despite the allure of advanced threats and AI-driven attacks, the speaker repeatedly highlights that basic security oversights—unpatched systems, weak credentials, and human errors—remain the primary vectors for compromise. Defenders must redouble efforts in:
- Patch Management: Implement rigorous and timely patching policies for all systems, including less common architectures and embedded devices.
- Strong Authentication: Enforce strong, unique passwords and multi-factor authentication (MFA) across all accounts, especially for administrative access and sensitive systems.
- Security Awareness Training: Continuously educate employees on common attack vectors (e.g., phishing, social engineering) and secure practices to mitigate human error.
Adapt to Evolving Threat Tactics:
- Ransomware: Defenders must recognize the shift towards data exfiltration and wiping without encryption, and the rise of multi-party extortion. This necessitates:
- Robust Data Backup and Recovery: Implement immutable backups, regularly test recovery plans, and ensure backups are isolated from network access.
- Data Loss Prevention (DLP): Deploy DLP solutions to monitor and prevent unauthorized exfiltration of sensitive data.
- Supply Chain Security: Enhance due diligence and security requirements for third-party vendors, recognizing that compromise of a vendor can directly impact clients.
- Scams: The high automation and resilience of scam syndicates demand:
- Rapid Takedown Capabilities: Organizations and national agencies need agile processes to identify and take down fraudulent domains, websites, and accounts swiftly.
- Enhanced Fraud Protection: Leverage technological partnerships (e.g., Google Play Protect's enhanced fraud protection) to block malicious applications and prevent mobile malware-enabled scams.
- Proactive Threat Intelligence: Share intelligence on scam infrastructure and operational patterns to enable faster detection and disruption.
- APTs: The sophistication of APT botnets (three-tier architecture, broad compatibility, novel orchestration) requires:
- Advanced Threat Detection: Implement network monitoring solutions capable of detecting anomalous C2 traffic, unique port usage, and suspicious TLS certificate patterns.
- Supply Chain Visibility: Understand the security posture of all components in your infrastructure, including embedded systems and IoT devices, as these are increasingly targeted.
- Collaborative Intelligence Sharing: Actively participate in national and international threat intelligence sharing initiatives to gain visibility into sophisticated campaigns.
Embrace a "Whole-of-Nation" and International Approach:
- Strong Legal Frameworks: Governments must establish and continually update legal mandates (like Singapore's Cyber Security Act) to safeguard critical information infrastructure, including evolving dependencies like cloud service providers and operational technology (OT).
- International Cooperation: Active participation in global coalitions like the Counter Ransomware Initiative is vital for exchanging intelligence, coordinating operations, and proactively neutralizing cross-border threats.
- Empowering All Stakeholders: Implement programs that empower businesses (e.g., SG Cyber Safe, CISO-as-a-Service for SMEs) and individuals to improve their cyber resilience, making expertise accessible and fostering a collective defense.
Leverage AI as a Defensive Tool:
- AI for Detection and Disruption: Harness AI to enhance security operations, such as the Scam Analytics and Tactical Intervention System (SATIS), which uses proprietary AI models for rapid scam website detection and takedown with over 90% accuracy.
- Secure AI Systems: As AI becomes deeply embedded, organizations must prioritize securing AI systems throughout their lifecycle (development to deployment) by following guidelines such as those released by CSA, ensuring AI-driven technologies remain resilient against emerging threats.
Cultivate the Right Mindset: Beyond tools and technologies, the speaker stresses the importance of mindset:
- Discipline: Maintain strong cyber hygiene consistently.
- Creativity: Outthink adversaries by anticipating their moves and adapting defensive strategies.
- Agility: Act decisively and quickly in response to threats.
Ultimately, the defensive implications call for a holistic, proactive, and collaborative strategy that blends foundational security with advanced threat intelligence, legal frameworks, and the intelligent application of AI, all underpinned by a resilient and adaptable mindset.
Key Takeaways
- Foundational Security is Paramount: Despite the rise of AI, basic security oversights like unpatched systems, weak credentials, and human errors remain the primary entry points for adversaries. Prioritizing robust cyber hygiene is non-negotiable.
- Ransomware, Scams, and APTs are Rapidly Evolving: These "RSA" threats are becoming more automated, agile, resilient, and sophisticated, employing tactics like encryption-less data extortion, multi-party pressure, and advanced three-tier botnet architectures.
- Geopolitical Chaos Fragments Tech and Complicates Choices: The current era of "great power competition" is leading to fragmented tech stacks and forcing organizations and nations to make difficult, often conflicted, choices that impact cyber resilience.
- A "Whole-of-Nation" Approach is Essential: Effective defense requires strong legal mandates, deep operational technical expertise, robust international partnerships, and empowering all stakeholders from governments to individuals.
- AI is a Double-Edged Sword: AI can be exploited by adversaries, but it is also a powerful tool for defenders, enhancing threat detection (e.g., SATIS) and disruption efforts, provided AI systems themselves are secured throughout their lifecycle.
- Mindset, Discipline, and Agility are Crucial: Beyond technology, success in the "infinite game" of cyber security hinges on a proactive mindset, the discipline to maintain strong cyber hygiene, and the agility to outthink and decisively act against evolving threats.
About the Speaker(s)
Edward Chen serves as the Deputy Chief Executive of National Cyber Resilience for the Cyber Security Agency (CSA) of Singapore. With a distinguished career spanning 25 years in the military, he was commissioned as a signal officer in 2000. His extensive experience includes commanding the Cyber Defense Group and subsequently the C4 Command Cyber Security Task Force. Most recently, he held the position of Defense Cyber Chief as a Brigadier General in the Digital and Intelligence Services. Transitioning from a national security and military perspective, his current role at the CSA focuses on operations and intelligence at a national civilian level, bringing a wealth of strategic and operational expertise to Singapore's cyber defense efforts.
Jeff is identified as the Black Hat host for this keynote session. He provided the opening remarks for Black Hat Asia, setting the context for the conference and introducing Edward Chen. His role involves welcoming attendees, discussing the conference's philosophy of providing insights into current and future cyber threats, and facilitating the keynote presentation.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
This keynote by Edward Chen from CSA Singapore delivers a highly credible and substantive overview of the evolving cyber threat landscape, particularly in the context of geopolitical fragmentation and AI. While not a technical deep dive into zero-days, it provides remarkable operational detail on ransomware, scams, and APTs, far surpassing typical executive keynotes. The focus on foundational security, coupled with actionable insights derived from real-world investigations, makes this a valuable strategic briefing for anyone managing cyber risk.
Heather Calloway (CISO) — STRONG ACCEPT
Edward Chen's keynote from Black Hat Asia delivers a clear, unsentimental assessment of the current cyber threat landscape, effectively cutting through the noise to focus on what truly matters for national and enterprise cyber resilience. He convincingly argues that while AI and geopolitical chaos reshape the battleground, foundational security failures remain the primary attack vector. The talk provides actionable insights for CISOs and policymakers, detailing the evolving tactics of ransomware, sophisticated scam operations, and advanced persistent threats, all framed within a critical 'whole-of-nation' approach to defense.