Darket Diaries
Darket Diaries

44: Zain

Ransomware is ugly. It infects your machine and locks all the the data and to unlock you have to pay a fee. In this episode we dive into some of the people behind it. Sponsors This episode was sponsored by CMD. Securing Linux systems is hard, let CMD help you with that. Visit https://cmd.com/dark to

Featured Speakers

Jack Rhysider HostZane Kaiser Guest

Topics Discussed

Episode Summary

Executive Summary: The episode follows Zane Kaiser, a British teen who helped run a ransomware scheme by combining the Angler exploit kit, Reveton “police” ransomware, and malvertising on porn sites to trap everyday users. The story shows how social engineering, laundering via Liberty Reserve and prepaid cards, and criminal supply chains enabled a highly profitable operation before police investigations, arrests, and platform takedowns unraveled it.

Main Topics: Ransomware as loud, coercive malware (Priority: 5/5): The episode opens by contrasting ransomware with stealthy malware: it locks computers immediately and forces victims to pay to regain access, making it psychologically and financially coercive. Zane Kaiser’s criminal startup (Priority: 5/5): Seventeen-year-old Zane, a computer science student in East London, pitched Russian criminals on distributing their malware and monetizing infections through ad traffic and extortion. Angler exploit kit and Reveton ransomware (Priority: 5/5): Angler scanned visitors for outdated software and exploited vulnerabilities, while Reveton encrypted machines and displayed fake police/FBI warnings to pressure victims into paying. Malvertising and social engineering (Priority: 5/5): Zane bought ad space on porn sites and used fake identities to drive users to malicious pages, exploiting embarrassment, fear, and shame to increase payment rates. Money laundering and criminal infrastructure (Priority: 4/5): Ransom payments were collected via Green Dot MoneyPak cards, funneled through Raymond, and laundered using Liberty Reserve and other intermediaries to obscure the proceeds. Law-enforcement takedown and digital forensics (Priority: 5/5): International and national investigations eventually linked Zane to the scam through server records, chat logs, dashboards, and financial trails, leading to arrests and convictions. Broader rise of sextortion and ransomware (Priority: 4/5): The episode ends by connecting Zane’s tactics to the wider evolution of sextortion and ransomware, where scammers increasingly rely on fear and stolen data rather than full malware infections.

Key Arguments: Ransomware succeeds not just through technical compromise but through psychological pressure, embarrassment, and urgency. A single actor can orchestrate a sophisticated cybercrime enterprise by combining third-party malware, ad networks, and laundering services. Porn-site malvertising was a highly effective vector because it matched the fake police warning and made victims less likely to seek help. Outdated software and weak defenses made users easy targets for exploit kits like Angler. Criminal ecosystems are modular: exploit developers, ransomware authors, distributors, and money launderers each play a distinct role. Shutting down one component of the network, such as Liberty Reserve or the Reveton crew, disrupts but does not fully end the broader ransomware market. Digital forensics and cross-border coordination were essential in building the case against Zane. The scam was profitable enough that a teenager could live extravagantly despite having no legitimate income. The same tactics evolved into modern sextortion, showing the durability of fear-based extortion schemes.

Data Points: Age of Zane Kaiser: 17 - He was a teenager living with his parents in Barking, East London, in 2011. Year the scheme began: 2012 - Zane began working with the Russian malware group and launching the ransomware operation. Ransom demand: $200 - Victims were told they could unlock their computers and avoid alleged legal consequences by paying this fee. MoneyPack card deposit limit: up to $500 - Green Dot MoneyPack cards were used as an anonymous payment method for ransom. MoneyPack daily allowance: up to $1,000 in 24 hours - The transcript notes this as a typical transaction limit, prompting use of multiple accounts. Liberty Reserve alleged laundering volume: more than $6 billion - The U.S. government later shut down Liberty Reserve for suspected criminal laundering activity. Reveton-related cases in Spain: more than 1,200 reported cases - Spanish police recorded widespread ransomware complaints since May 2011. Gang revenue estimate: more than 1 million euros a year - Police believed the Spanish-linked ransomware group was collecting this amount annually. Angler peak share of exploit kit infections: 40% - By mid-2016, Angler was estimated to be behind a large share of exploit-kit infections. Angler annual revenue estimate: around $60 million a year - Cisco Talos estimated the kit generated this amount for hackers. Zane's share of ransom payments: about 70% - He reportedly received this cut from the operation. Zane's estimated monthly ransom intake example: $16,000 per month - The narrator estimates this from 800 infections with a 10% payment rate at $200 each. Zane's total moved through accounts: at least $5 million - NCA estimates across the five-year operation. Zane's personal profit estimate: almost $900,000 - Authorities estimated his personal profit by the time of arrest in 2017. Raymond's estimated laundering volume: about $93,000 - Prosecutors estimated his one-year involvement in laundering ransom proceeds. Raymond sentence: 18 months in jail plus 3 years supervised release - He was convicted in the U.S. for conspiracy to commit money laundering. Zane sentence: 6 years and 5 months - He was sentenced in Kingston County Court on April 9, 2019. DDoS damage estimate: at least £500,000 - Advertising agencies lost money from downtime and incident response costs after Zane retaliated. Cash-out method fee: about 5% - Liberty Reserve exchangers converted criminal cash into digital value for a fee.

Pivotal Quotes: "It's a story about individual users being hit with ransomware on their own computers, and the criminal behind it was a teenage boy in his bedroom." — Jack Rhysider: Framing the episode’s central twist: a youth-run cybercrime operation targeting ordinary people. "Really, it's better if we work together. We can make some serious money together. It's my way or no way. The king is back." — Zane Kaiser: A threat sent to an advertising company after they questioned his operations. "I'll first kill your server and then I'll send child porn spam abuses to you." — Zane Kaiser: Escalating intimidation used against advertising partners who resisted his scam.

Implications: The case shows how ransomware is powered by fear, trust abuse, and criminal infrastructure, not just code. It also foreshadows modern sextortion and the need for patching, vigilance, and rapid cross-border law-enforcement cooperation.

🔓 Sign Up for Unlimited Episode Search

About Darket Diaries

Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.

View all episodes from Darket Diaries