Darket Diaries
Darket Diaries

151: Chris Rock

Chris Rock is known for being a security researcher. But he’s also a black hat incident responder. He tells us about a job he did in the middle east. https://x.com/chrisrockhacker Sponsors Support for this show comes from Varonis. Do you wonder what your company’s ransomware blast radius is? Varonis

Featured Speakers

Jack Rhysider HostChris Rock Guest

Topics Discussed

Episode Summary

Executive Summary: The episode follows hacker/security researcher Chris Rock as he describes years of offensive and defensive work, including a Middle East engagement where he infiltrated an investment firm, traced theft of about $2.5M and IP, and later helped recover funds by compromising a bank. It also spotlights his DEF CON talk on exploiting online birth/death registration systems to create or kill identities.

Main Topics: Chris Rock’s hacker background and dual offensive/defensive career (Priority: 5/5): Chris explains he has hacked since childhood, worked in banks, later ran pentests globally, and built SIEMonster after seeing how logging exposes attackers. Middle East mercenary-style engagement (Priority: 5/5): He was hired through intermediaries in Turkey to investigate theft and IP misappropriation between wealthy Middle Eastern business interests and an investment firm. Target profiling and layered compromise (Priority: 5/5): The operation started with reconnaissance on multiple targets, then moving through levels of contacts (inner circle, associates, affiliates) to gather trusted communication patterns before hitting the main target. Physical intrusion and Wi‑Fi exploitation (Priority: 4/5): When email-based delivery failed, Chris planted a device in a co-working office, cracked weak WEP Wi‑Fi with AirCrackNG, and gained internal network visibility. Bank compromise and fund recovery (Priority: 5/5): After proving misappropriation, the client wanted the stolen money back immediately, so Chris compromised the bank, captured logins and 2FA, and moved roughly $2.5M back. Operational security, laundering, and evasive routing (Priority: 4/5): Chris describes using compromised systems and international hops through hostile jurisdictions to hide attribution, plus anti-forensics and planted evidence to mislead investigators. DEF CON research on online death/birth systems (Priority: 4/5): He explains how moving vital records online created flaws that could let someone fabricate deaths or births by abusing doctor/funeral-director workflows and public license data.

Key Arguments: Chris frames much of his work as a practical job rather than a moral debate: offensive and defensive hacking are both just parts of the same ecosystem. Successful intrusion depends less on “advanced” exploits than on understanding people, their relationships, and their communication habits. Layered compromise of contacts around a target is more effective than direct phishing because it makes malicious emails look normal and trustworthy. A small office with weak Wi‑Fi security and poor physical controls can be turned into a beachhead for full network access. Banks can be surprisingly weak internally; capturing employee credentials and web-session data can enable large-scale transfers. In this case the objective shifted from evidence collection to immediate asset recovery, showing how black-hat skills can be repurposed for client-directed outcomes. Online vital-record systems can be abused because public licensing data and separate approval steps make it possible to fake authority and create or cancel identities.

Data Points: Chris Rock’s age: 51 - He states his age when describing his career timeline. Years in banks: 10 years - He worked in Australian banks before moving fully into security/penetration testing. Years in pen testing: 10 years - He ran his own pen testing company after banking. Engagement duration: 9+ months - The Middle East investigation continued for nearly a year. Targets: 8 targets - The operation began with eight named people connected to the suspected theft. Stolen amount: $2.5 million USD - Chris says this was the amount recovered/returned from Bob’s account, though the original theft was slightly higher. Original amount referenced: $2.75 million USD - He notes the original money taken was around 2.75 million dollars. Adoption of the death-system research: 9 years old talk reference - He says his DEF CON talk on killing identities was given nine years earlier and the flaw still existed. Ransomware prevalence: 85% - The SpyCloud sponsor copy claims ransomware affected 85% of organizations in the past year. Corporate user exposure: Nearly half - SpyCloud sponsor copy says nearly half of corporate users have been infected by infostealer malware at some point. Identity records circulating: 63.8 billion - SpyCloud sponsor copy cites the scale of identity records on the dark web. Organizations detecting historical exposures: 38% - SpyCloud sponsor copy says only 38% can detect historical identity exposures.

Pivotal Quotes: "You have to be stupid to get caught." — Chris Rock: Explaining why experienced hackers avoid arrest and how anti-forensics becomes routine. "The first plan never works." — Chris Rock: Describing the need for multiple backup plans during the physical intrusion and Wi‑Fi attack. "It’s all full of shit." — Chris Rock: On public claims that hacking is not a crime and on the gap between public hacker narratives and real-world behavior.

Implications: The episode underscores how real-world breaches often hinge on social engineering, weak internal controls, and poor identity systems. It also shows how offensive tradecraft can overlap with defense, fraud recovery, and even systemic abuse of civil-record infrastructure.

🔓 Sign Up for Unlimited Episode Search

About Darket Diaries

Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.

View all episodes from Darket Diaries