Menu
Sign In Search Podcasts Charts People & Topics Add Podcast API Pricing

Jack Rhysider

👤 Person
248 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
135: The D.R. Incident

Bandook. Okay, if I Google Bandook malware, I immediately get an article saying that this malware gives remote access to a computer, and it was written by someone named Prince Ali who's from Lebanon in the Middle East. More specifically, the Bandook malware has been known to be used by a group called Dark Caracol. Well, that's what the EFF named them, at least.

Darknet Diaries
135: The D.R. Incident

Bandook. Okay, if I Google Bandook malware, I immediately get an article saying that this malware gives remote access to a computer, and it was written by someone named Prince Ali who's from Lebanon in the Middle East. More specifically, the Bandook malware has been known to be used by a group called Dark Caracol. Well, that's what the EFF named them, at least.

Darknet Diaries
135: The D.R. Incident

And while we aren't sure exactly who they are, there are quite a bit of clues that lead us to believe that the Lebanese government is somehow behind this dark Caracol group. Now, I want to paint a clear picture for you.

Darknet Diaries
135: The D.R. Incident

And while we aren't sure exactly who they are, there are quite a bit of clues that lead us to believe that the Lebanese government is somehow behind this dark Caracol group. Now, I want to paint a clear picture for you.

Darknet Diaries
135: The D.R. Incident

Hundreds of phishing emails are flooding into different government agencies in the Dominican Republic, all of which are trying to get the recipient to open an attachment or click a link, which will infect them with this Banduk malware, which typically seems to be the work of this threat actor group called Dark Caracal. As Omar looked at these emails coming in, he noticed something even more scary.

Darknet Diaries
135: The D.R. Incident

Hundreds of phishing emails are flooding into different government agencies in the Dominican Republic, all of which are trying to get the recipient to open an attachment or click a link, which will infect them with this Banduk malware, which typically seems to be the work of this threat actor group called Dark Caracal. As Omar looked at these emails coming in, he noticed something even more scary.

Darknet Diaries
135: The D.R. Incident

So what happened here is that the attackers knew that the Dominican Republic was doing business with a certain company, and they infiltrated that company just to pose as people from there in order to trick the victims in the Dominican Republic government to open attachments.

Darknet Diaries
135: The D.R. Incident

So what happened here is that the attackers knew that the Dominican Republic was doing business with a certain company, and they infiltrated that company just to pose as people from there in order to trick the victims in the Dominican Republic government to open attachments.

Darknet Diaries
135: The D.R. Incident

I mean, this seems to be the start of a horror story where it feels like you're home alone at night and someone is throwing rocks at your window, at all your windows, at once, constantly pinging them. And you just know at any moment one of those windows is going to break. But there's just no way to secure everything at once.

Darknet Diaries
135: The D.R. Incident

I mean, this seems to be the start of a horror story where it feels like you're home alone at night and someone is throwing rocks at your window, at all your windows, at once, constantly pinging them. And you just know at any moment one of those windows is going to break. But there's just no way to secure everything at once.

Darknet Diaries
135: The D.R. Incident

It just takes one user in an agency to get infected, and then the attacker can jump off their machine to infect the whole agency. And for dozens of agencies to be attacked at the same time is horrifying. On top of that, the attackers are scanning web servers, looking for vulnerabilities, trying to find an exploit to get into the network that way.

Darknet Diaries
135: The D.R. Incident

It just takes one user in an agency to get infected, and then the attacker can jump off their machine to infect the whole agency. And for dozens of agencies to be attacked at the same time is horrifying. On top of that, the attackers are scanning web servers, looking for vulnerabilities, trying to find an exploit to get into the network that way.

Darknet Diaries
135: The D.R. Incident

So it's like endless banging on the doors and you know they're not going to hold. Where do you even put your attention in a situation like this? The bull is trying to get in your house and there's nothing you can do to stop it.

Darknet Diaries
135: The D.R. Incident

So it's like endless banging on the doors and you know they're not going to hold. Where do you even put your attention in a situation like this? The bull is trying to get in your house and there's nothing you can do to stop it.

Darknet Diaries
135: The D.R. Incident

The hacker group Dark Caracal had successfully made their way into 30 different government agencies. And each came in through a different entry point too. And to see that this was coming, to know the bull was headed towards you, but to have no ability to stop it, has got to be one of the most terrifying feelings. The feeling of helplessness, despair, vulnerability.

Darknet Diaries
135: The D.R. Incident

The hacker group Dark Caracal had successfully made their way into 30 different government agencies. And each came in through a different entry point too. And to see that this was coming, to know the bull was headed towards you, but to have no ability to stop it, has got to be one of the most terrifying feelings. The feeling of helplessness, despair, vulnerability.

Darknet Diaries
135: The D.R. Incident

Suddenly, a huge portion of the Dominican Republic government's network is now in the control of someone else? Someone you have no idea who they are, but maybe related to the Lebanese government?

Darknet Diaries
135: The D.R. Incident

Suddenly, a huge portion of the Dominican Republic government's network is now in the control of someone else? Someone you have no idea who they are, but maybe related to the Lebanese government?

Darknet Diaries
135: The D.R. Incident

Holy flip, critical infrastructures, things like power plants, water treatment facilities, dams. Disrupting or destroying these systems would absolutely bring this country to its knees.

Darknet Diaries
135: The D.R. Incident

Holy flip, critical infrastructures, things like power plants, water treatment facilities, dams. Disrupting or destroying these systems would absolutely bring this country to its knees.