Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Ryan McFarlane

๐Ÿ‘ค Speaker
175 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
175: Bayrob

So they were running Linux with Lux on it, and then they had a couple of TrueCrypt containers on it.

Darknet Diaries
175: Bayrob

And then Nicolescu had written his own

Darknet Diaries
175: Bayrob

encryption software uh for because truecrypt was no no longer being updated so that's five layers of encryption just to unlock the laptop yeah four or five different layers and everybody in the group got the same package essentially and they also that was that was not the extent of it they also got some networking gear so each of them got a custom flash router

Darknet Diaries
175: Bayrob

And that custom flash router would allow them to proxy their traffic between their different houses.

Darknet Diaries
175: Bayrob

And their operational security was that their first hop from their house was using a directional Wi-Fi to the internet.

Darknet Diaries
175: Bayrob

And that individual, say, you know, Nicolescu was in Brazov, he would establish that on the router, the custom flashed router.

Darknet Diaries
175: Bayrob

And then he would communicate to the other group that his router was set up and everybody would tunnel their traffic for the group through that stolen Wi-Fi through the router at that location.

Darknet Diaries
175: Bayrob

And then they'd switch the router the next week to another individual's home.

Darknet Diaries
175: Bayrob

And that was why we were seeing the encrypted traffic

Darknet Diaries
175: Bayrob

between the two locations that we couldn't explain.

Darknet Diaries
175: Bayrob

It was their tunneled encrypted traffic that was then being sent over stolen Wi-Fi using the directional antennas, then to Tor or a proxy network, then to infected systems, then up into the command and control infrastructure.

Darknet Diaries
175: Bayrob

So again, they were doing a pretty good job of hiding their tracks.

Darknet Diaries
175: Bayrob

So Danette ends up pleading and we confronted him with the evidence during a proffer session.

Darknet Diaries
175: Bayrob

And during our investigation, one of the things we did with the evidence collection is we had really good visibility into when they were logging into and logging off of all of their criminal accounts.

Darknet Diaries
175: Bayrob

And we didn't know it at the time, but this information ended up being incredibly valuable because it established this pattern of life for all the different actors.

Darknet Diaries
175: Bayrob

We could see when they were online doing, you know, like in their criminal accounts and when there were large gaps.

Darknet Diaries
175: Bayrob

And when we were able to get Danette's personal computer and search that, he liked to travel.

Darknet Diaries
175: Bayrob

and he vacationed a lot, and he also took photos of everywhere he went.

Darknet Diaries
175: Bayrob

He was an avid photographer.

Darknet Diaries
175: Bayrob

So we could see through the photo metadata when he was in these certain locations, and then we overlaid it with all the criminal account data, and you could see that every time one of these accounts went dark,