- Cyber Safety
- Posts
- Why Attackers Prefer Persistence Over Destruction
Why Attackers Prefer Persistence Over Destruction
Blu Dot surpasses 2,000% ROAS with self-serve CTV ads
Home furniture brand Blu Dot blew up on CTV with help from Roku Ads Manager. Here’s how:
After a test campaign reached 211,000 households and achieved 1,010% ROAS, the brand went all in to promote its annual sales event. It removed age and income constraints to expand reach and shifted budget to custom audiences and retargeting, where intent was strongest.
The results speak for themselves. As Blu Dot increased their investment by 10x, ROAS jumped to 2,308% and more page-view conversions surpassed 50,000.
“For CTV campaigns, Roku has been a top performer,” said Claire Folkestad, Paid Media Strategist, Blu Dot. “Comping to our other platforms, we have seen really strong ROAS… and highly efficient CPMs, lower than any other CTV partner we've worked with.”
Using Roku Ads Manager, the campaign moved from a pilot to a permanent performance engine for the brand.
Long-Term Access Is More Valuable Than Immediate Chaos
Sophisticated attackers often avoid triggering alarms early. Quiet persistence allows them to observe operations, collect credentials, and expand access gradually.
Persistence Mechanisms Are Designed to Survive Cleanup
Scheduled tasks, OAuth grants, hidden admin accounts, stolen session tokens, and modified startup processes help attackers maintain access even after passwords are reset.
Silent Access Increases Strategic Advantage
The longer attackers remain undetected, the more they learn about infrastructure, workflows, backup systems, and incident response procedures.
Two Minutes to Know What Slow Billing Is Costing You
Most SaaS finance teams know their billing process is slow.Most SaaS finance teams know their billing process is slow. Few know what it's costing them.
The Tabs Billing Lag Calculator puts a dollar figure on it in two minutes — benchmarked against top SaaS companies.
Detection Usually Happens Too Late
Many organizations only discover compromise during ransomware deployment, public data leaks, or operational disruption — long after persistence was established.
Traditional Security Focuses Too Much on Initial Entry
Blocking phishing and patching vulnerabilities matters, but post-compromise visibility and persistence detection are equally critical.
Cyber Resilience Depends on Continuous Validation
Monitor for abnormal privilege changes, review OAuth permissions regularly, audit dormant accounts, and validate persistence mechanisms continuously. In cybersecurity, attackers succeed when they remain invisible long enough.
Introducing The First Agentic CRM
Get revenue agents, workflows, and automations across every stage of your motion. Access customer data in real time through Attio's web app, MCP, API, and SDK.
Then Ask Attio anything about your business and get instant answers.
It's the CRM that runs the work behind every win.



