Episode Summary
Executive Summary: This episode of Darknet Diaries features Chris Davis, a cybersecurity expert who shares his experiences tracking and taking down cybercriminals. He recounts catching the hacker 'Curidor' in the early 2000s, dismantling the massive Mariposa botnet, and investigating a botnet targeting French critical infrastructure. The episode highlights the challenges of international cybercrime investigations and the persistence of threats.
Main Topics: Catching Curidor (Priority: 5/5): Chris Davis tracks down an arrogant hacker who bragged about stealing credit cards from e-commerce sites. Using logs and collaboration with the FBI, he helps arrest the 18-year-old in Wales. The Mariposa Botnet (Priority: 5/5): Chris discovers a massive botnet infecting millions of computers, takes down its command-and-control servers, and faces retaliation from the botmasters who later audaciously apply for jobs at the security company that stopped them. French Critical Infrastructure Botnet (Priority: 4/5): Chris identifies a botnet infecting France's power grid, rail system, hospitals, and banks. Despite reporting to French authorities via the FBI, the systems remain compromised years later. Challenges in International Cybercrime Enforcement (Priority: 4/5): The episode illustrates difficulties in cross-border investigations, including language barriers, lack of expertise, and slow response from authorities, as seen in the French case. The Role of Infrastructure Providers in Cybersecurity (Priority: 3/5): Chris leverages relationships with DNS and hosting providers to track and disrupt cybercriminal activities, emphasizing the importance of collaboration.
Key Arguments: Cybercriminals often make mistakes, such as bragging or reusing infrastructure, which can be exploited by investigators. International cooperation is crucial but often hampered by bureaucratic and jurisdictional issues. Critical infrastructure remains vulnerable due to inadequate security and slow response to threats. Malware creators can be held accountable if intent to facilitate crime is proven, as in the case of the butterfly bot creator. Proactive monitoring of DNS traffic can reveal emerging botnets before they cause widespread damage.
Data Points: Bitcoin value at arrest: $600 per coin - Story of a criminal arrested in 2016 with Bitcoin worth $600. Bitcoin value later: Over $30,000 per coin - Same criminal's Bitcoin wallet now worth nearly $1 million. Bitcoins in wallet: 18 Bitcoins - Criminal's wallet contained 18 Bitcoins. Unique IPs in Mariposa sinkhole: 14 million - First 24 hours after taking down Mariposa botnet. Stolen Bitcoin from NiceHash: 4,700 Bitcoin ($60 million) - NiceHash mining pool hacked in 2017.
Pivotal Quotes: "I think that there's intent. And, you know, one of the things that cyber criminals, a lot of them make the same mistake over and over again, which is I'm going to build this thing and I'm going to say, hey, you're only allowed to use this to test your own stuff, whatever. But the intent of the code is to be stealthy, to hide, to do this, to do that. It's to commit cybercrime." β Chris Davis: Discussing the culpability of malware creators like the butterfly bot author. "I get a message from Pedro Busamante, who ran the research lab at Panda Antivirus. And he goes, you're never going to effing believe this. And I said, what? He's like, these guys showed up this morning looking for jobs, both of them." β Chris Davis: Recounting the audacity of the Mariposa botmasters after their arrest. "I went back and looked at some traffic earlier today for those same command and control domains. There still is French infrastructure that is repeatedly looking up the command and control domain every three minutes, 24 hours a day." β Chris Davis: Revealing that French critical infrastructure remains compromised years after reporting.
Implications: The episode underscores the persistent vulnerability of critical infrastructure and the need for faster international cooperation. It also highlights how cybercriminals can evolve, even after conviction, and the importance of proactive threat hunting.
About Darket Diaries
Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.