Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Liam Amarku

๐Ÿ‘ค Speaker
134 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
175: Bayrob

So Jabber is encrypted and there are different settings that you can use.

Darknet Diaries
175: Bayrob

And by default, the setting for attachments is not, it doesn't default to encryption.

Darknet Diaries
175: Bayrob

So your text, all the messages that you sent are encrypted, but attachments are not encrypted.

Darknet Diaries
175: Bayrob

And that was the mistake that they made.

Darknet Diaries
175: Bayrob

They were talking to each other and we couldn't see what it was that they were talking about.

Darknet Diaries
175: Bayrob

But if they sent an attachment,

Darknet Diaries
175: Bayrob

like an Excel spreadsheet with all of their accounting in it or a picture of their desktop.

Darknet Diaries
175: Bayrob

That was not encrypted and we could extract that from the network and we could see what it was.

Darknet Diaries
175: Bayrob

We got to see them transferring spreadsheets talking about all of the transactions, how much money they were making, who were the victims, what were the credit card numbers of the victims, what were the home addresses of the victims, what money mules they were using, the identity of all their money mules.

Darknet Diaries
175: Bayrob

picture of their desktop that they had transferred between each other, two members had transferred between each other, and they were trying to figure out why something wasn't working with their malicious campaign.

Darknet Diaries
175: Bayrob

So one of the Bayrob members had taken a screenshot and had transferred it to another one, but they had actually gone through my proxy machine at that time, so I could see this.

Darknet Diaries
175: Bayrob

They were using encrypted chat actually, so I couldn't see the chat, but because

Darknet Diaries
175: Bayrob

the pictures that they sent in the chat were not encrypted, I got this rare opportunity to see this image get transferred across, just like flash across my network.

Darknet Diaries
175: Bayrob

And when we decoded it, we saw that it was the attacker's desktop.

Darknet Diaries
175: Bayrob

And he was inside a VM machine.

Darknet Diaries
175: Bayrob

And then he had his control panel, his attacker's control panel on the desktop.

Darknet Diaries
175: Bayrob

And he had a Facebook campaign that they were using to try and find victims on the desktop.

Darknet Diaries
175: Bayrob

And he was running that campaign through a hacked account.