Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Liam Amarku

๐Ÿ‘ค Speaker
134 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
175: Bayrob

And I understood that they were trying to defraud customers of eBay.

Darknet Diaries
175: Bayrob

So I decided to name it, I couldn't use eBay as a trade name, so I decided to call it BayRob because they were robbing customers of eBay.

Darknet Diaries
175: Bayrob

And what the malware was doing was it was sitting on your computer and when you tried to connect to the eBay website, it would intercept your connection and it would inject false information into your browsing session.

Darknet Diaries
175: Bayrob

And it made it look like the false information was actually coming from the eBay legitimate URL, so you wouldn't notice that anything was different.

Darknet Diaries
175: Bayrob

And then they were using that to sell you things that didn't exist on eBay.

Darknet Diaries
175: Bayrob

I kept searching to see if I could find that missing piece, and I just kept on looking through our telemetry and looking to see where I might find this.

Darknet Diaries
175: Bayrob

And I knew there was some places where this was probably going to be distributed, so I was looking in those places, like on Craigslist, for example, in email, looking to see if I could find any places where I could find a complete package that would help me to analyze it from beginning to end and understand exactly what the attackers were doing, how they were making money, where they were sending the money, the entire thing.

Darknet Diaries
175: Bayrob

I wanted to know it all.

Darknet Diaries
175: Bayrob

And it turns out that the reason I couldn't solve the entire problem was because the attackers were geofencing their fraud so that it could only happen in America and only happen in certain locations within America.

Darknet Diaries
175: Bayrob

And I was in Ireland at the time, I was based in Ireland.

Darknet Diaries
175: Bayrob

So when I tried to connect to these auctions, because they were posting these fraudulent auctions, because I wasn't in America, I wasn't authorized to see this fraudulent data.

Darknet Diaries
175: Bayrob

And I managed to discover who that victim was.

Darknet Diaries
175: Bayrob

I reached out to that victim and she had actually signed up for an auction after she had been defrauded the first time.

Darknet Diaries
175: Bayrob

She went, she found another auction that was very similar and she signed up for that and she had gotten the entire package, the entire malware package.

Darknet Diaries
175: Bayrob

And I spoke with her and she's prepared to share that with me.

Darknet Diaries
175: Bayrob

I recorded my entire session and I went online and I bought this car.

Darknet Diaries
175: Bayrob

And as part of the fraudulent information that they were injecting into the eBay website, they injected a chat window where you could chat about this fraudulent auction.

Darknet Diaries
175: Bayrob

And when you chatted, you thought you were talking to eBay support, but you're actually talking to these attackers.

Darknet Diaries
175: Bayrob

So I recorded this entire thing.