Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Ryan McFarlane

๐Ÿ‘ค Speaker
175 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
175: Bayrob

Yeah, so my name's Ryan McFarlane.

Darknet Diaries
175: Bayrob

I'm the IR practice lead at Trusted Tech, but at the time I was a cyber agent.

Darknet Diaries
175: Bayrob

I was coming from DC where I spent two years at our National Cyber Investigative Joint Task Force working whole of government counter operations against China and was transferring back to Cleveland and got to Cleveland and the first thing

Darknet Diaries
175: Bayrob

I ended up getting asked to do was to work with Stacey on this case.

Darknet Diaries
175: Bayrob

You know, I land in Cleveland and start working this case with Stacey.

Darknet Diaries
175: Bayrob

And I spent the first, you know, six months to a year just going after all the infrastructure that these actors were using and working with

Darknet Diaries
175: Bayrob

Attorney's Office in Cleveland and CSIPS to get legal process and a ton of technical coverage on the Bay Route group.

Darknet Diaries
175: Bayrob

And the Romanian National Police were great.

Darknet Diaries
175: Bayrob

And they would go and they'd come back and they'd say, you know, we just talked to a really nice school teacher.

Darknet Diaries
175: Bayrob

And we were sending the Romanian National Police all over Romania.

Darknet Diaries
175: Bayrob

And they were just, you know, the more doors they knocked on, the more we realized something was going on that we just didn't understand.

Darknet Diaries
175: Bayrob

Right around this time, we're in pursuit mode, right?

Darknet Diaries
175: Bayrob

So we're trying to get as much visibility into their infrastructure.

Darknet Diaries
175: Bayrob

And around this time, we get a data intercept on their systems that are controlling all their malware.

Darknet Diaries
175: Bayrob

So they had a multi-layer command and control infrastructure.

Darknet Diaries
175: Bayrob

where all the malware was reporting up to the first layer, and then that layer was forwarding on to a couple of servers that were hosted in different places.

Darknet Diaries
175: Bayrob

And we were able to, as a team, figure out where those servers were located.

Darknet Diaries
175: Bayrob

So we went with legal process.

Darknet Diaries
175: Bayrob

We got a data intercept on a couple of these top-level command and control servers, and we were able to see the communications for all the botnet, which meant that we got to see when they updated their malware,

โ† Previous Page 1 of 9 Next โ†’