RomHack Camp 2026

Moataz Moustafa

Moataz is a cybersecurity expert with over a decade of extensive experience specialising in offensive security. Presently working as a Senior Consultant at Google APT66 advanced offensive security services. Moataz focus lies within the realms of red teaming and intelligence analysis.


Session

10-02
12:00
40min
Command and Collusion: Flipping the C2 Model for No-Egress Environments
Hatem Mohamed, Moataz Moustafa

Modern red team operations rarely play out in friendly territory. The days of wide-open egress are fading, replaced by environments where defenders tighten every screw. Outbound traffic is inspected, filtered, and often blocked entirely. A shell on a public-facing server might feel like a win, but in many cases, it comes with no DNS, no HTTP, and no callbacks at all. In these conditions, the familiar C2 playbook runs out of pages, and operators are forced to adapt or stall.

In this session, we will flip the C2 model on its head. You will see how to turn "dead-end" footholds into fully functional command channels without a single outbound packet, blending covert tasking into legitimate inbound web traffic. We will break down the design choices, the stealth advantages, and the pitfalls you will want to avoid, then share tooling to make it work with your own implants and frameworks.
If you have ever been stuck behind a wall of egress controls, you will walk away with a new blueprint and a few tricks to make the unreachable reachable.

Why This Matters

This is original, never-before-published research that redefines how C2s can function under extreme network restrictions.
The technique has been tested in real red teams, proving both its stealth and reliability in complex environments.
We’re genuinely enthusiastic about sharing this research with the community. Not just as a technical talk and tooling, but as a fresh perspective on adversary resilience in a post-egress world.

Cybersecurity and Hacking
STAGE 2 (Ghost in the Shellcode)