Darket Diaries
Darket Diaries

98: Zero Day Brokers

Zero day brokers are people who make or sell malware that’s sold to people who will use that malware to exploit people. It’s a strange and mysterious world that not many people know a lot about. Nicole Perlroth, who is a cybersecurity reporter for the NY Times, dove in head first which resulted in h

Featured Speakers

Jack Rhysider HostNicole Perlroth Guest

Topics Discussed

Episode Summary

Executive Summary: This episode of Darknet Diaries explores the gray market for zero-day exploits, featuring Nicole Perlroth, a New York Times cybersecurity reporter. She reveals how vulnerabilities are discovered, sold secretly to governments or brokers, and used for espionage and warfare. The episode traces the history from Project Gunman, where the US discovered Soviet bugs in typewriters, to modern times where the NSA and other agencies purchase exploits. It highlights the ethical dilemma of governments stockpiling vulnerabilities, the shift of top talent from the NSA to private firms, and the risks when exploits leak, causing global damage.

Main Topics: The Gray Market for Zero-Day Exploits (Priority: 5/5): Explores the secretive, legal market where vulnerability researchers sell exploits to governments and brokers, often under NDAs. Nicole Perlroth's investigation in Argentina reveals a scene where young hackers sell to government representatives at conferences. Project Gunman: The Origin of US Cyber Espionage (Priority: 5/5): Details the 1984 operation where the US discovered Soviet bugs in embassy typewriters using magnetometers, sparking a US effort to exploit every new technology for intelligence. Government vs. Vendor Tensions (Priority: 4/5): Describes the conflict between software companies like Microsoft and governments that hoard exploits, undermining trust and leaving systems vulnerable. Examples include the Flame malware and Shadow Brokers leak. The Ethics and Asymmetry of Cyber Warfare (Priority: 4/5): Discusses the moral calculus of exploit developers, the imbalance between defenders and nation-state attackers, and the risks of tech-illiterate leaders making decisions about cyber operations. Journalist Targeting and Source Protection (Priority: 3/5): Nicole Perlroth shares personal experiences of being targeted by hackers, including a Chinese breach of the New York Times and a dark web bounty on her devices, highlighting the need for extreme security measures. From NSA to Private Sector: Talent Drain (Priority: 3/5): Examines how top NSA hackers left to form private vulnerability research labs, selling more reliable, 'click-and-shoot' tools to their former agency and others, while losing mission oversight.

Key Arguments: Zero-day exploits are a weapon—once disclosed, they lose value, which is why they are kept secret and sold at high prices. Governments, especially the US, have prioritized espionage over security, stockpiling exploits and even pushing weak encryption standards (e.g., RSA backdoor). The US government's actions set a precedent for other nations, leading to a global cyber arms race with minimal accountability. Software companies cannot compete with government pricing for bugs, creating a market where only nation-states can afford top exploits. Leaked exploits, such as those from the Shadow Brokers, can cause massive collateral damage, as seen with NotPetya. Journalists face significant risks when investigating cyber topics, requiring meticulous operational security practices.

Data Points: Zero-day exploit cost for iOS remote access: $2.5-3 million - Nicole Perlroth states this is the going rate, with Crowdfense offering $3 million for such capability. NSA black budget for exploit purchases: $25.1 million - Perlroth mentions this line item from Snowden documents for the year 2030. Duration of Chinese hack on New York Times: Four months - Nicole describes the attack lasting several months in 2012. Number of computers compromised in NYT hack: 53 - Attackers gained access to 53 employee computers. NotPetya damages - FedEx, Merck, Cadbury: $400 million / vaccine lines / production lines - Perlroth cites specific costs and impacts from the 2017 attack. Years Soviets had bugs in US embassy typewriters: Seven to eight years - Perlroth reports this from Project Gunman findings.

Pivotal Quotes: "The biggest thing that I needed to protect was my sources and my conversations with sources. So I have been very old school about using pen and paper, about bringing burner laptops and devices to these conferences." — Nicole Perlroth: Explaining her operational security methods after being targeted by hackers. "If you can't trust that the prompt you're getting that you need to update your software is coming from Microsoft and not the NSA or Unit 8200 in Israel or whoever, then that is a real problem for the company." — Nicole Perlroth: Discussing the trust erosion caused by Flame malware exploiting Microsoft's update mechanism. "Before that, we were just living in la-la land. After that, we realized that if we did not catch up to the Soviets in terms of our own exploitation... we would probably lose the Cold War." — Jim Gosler (via Nicole Perlroth): Describing the impact of Project Gunman on US cyber strategy.

Implications: This episode underscores the fragility of digital trust when governments hoard exploits. It warns that without transparency and international norms, a catastrophic leak or attack is likely. Listeners should understand that complete digital security against state actors is nearly impossible, and advocate for policies that prioritize patching over stockpiling.

🔓 Sign Up for Unlimited Episode Search

About Darket Diaries

Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.

View all episodes from Darket Diaries