mnemonic security podcast

Magic Cat (Part 1)

mnemonic

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 1:01:54

Magic Cat (part 1) with security researchers Erlend Leiknes and Harrison Sand 

Darcula is a phishing-as-a-service operation targeting victims globally. Over the past 1.5 years, mnemonic researchers and an international investigative reporting team have been looking into the technology, operations and individuals connected to this crime group.

In this episode, Robby speaks with mnemonic's Erlend Leiknes and Harrison Sand about the findings from their technical investigation, offering a rare look behind the scenes of this global phishing-as-a-service operation utilising the phishing kit Magic Cat.

The research unveils hundreds of thousands of victims spanning the globe, unique technical insight into the software enabling hundreds of criminal subscribers, and a glimpse into the flashy lifestyle of the operators.

This podcast was recorded in April, but on May 4th, Norwegian media agency NRK, together with French Le Monde and German BR released the first of their multi-part global investigation into the prominent people behind the phishing operation. The investigation brings them to Thailand, where they attempt to confront Darcula, and learn more about the inner workings of the scam central.

Listen to Part 2 to hear how this story progresses as Robby interviews investigative journalist Martin Gundersen from NRK.

- mnemonic's technical blog about Magic Cat: https://www.mnemonic.io/resources/blog/exposing-darcula-a-rare-look-behind-the-scenes-of-a-global-phishing-as-a-service-operation/

- Inside the Scam Network at NRK: https://www.nrk.no/dokumentar/xl/inside-the-scam-network-1.17399135

- The Hunt for Darcula at NRK: https://www.nrk.no/dokumentar/xl/the-hunt-for-darcula-1.17399157 



Send us Fan Mail

Speaker

From our headquarters in Oslo, Norway, and on behalf of our host, Robby Peralta, welcome to the mnemonic security podcast.

Robby Peralta

There's a floor mnemonic HQ I refer to as Meerkat Manor. It's where our network detection team sits, and they're pretty into Suricata, which explains all the Meerkat figurines. A few floors up, you'll find what I like to call demonic. It's our hacker team, officially known as Technical Risk Services. They're more into lockpicking the Meercats, but they do have a tendency to adventure into rabbit holes. And this episode is all about a rabbit hole. And somewhere along the way down, they stumbled upon a cat. Popularly known now as Magic Cat. One that fishes and impersonates hundreds of brands in all kinds of languages, and one that's been used to steal millions of credit cards all over the world. And if you're lost right now and wondering what I'm rambling on about, boy, do we have a treat for you. A rare look behind the scenes of a global fishing as a service operation, or just a pen testing story from my colleagues Harrison Sand and Erlend Leiknes. Either way, it goes a bit like this.

Erlend Leiknes

So we were sitting and having a brainstorm session trying to find out if there was anything that we would like to look into. And I remember at the time it was in the news that we received a lot of text messages ourselves about uh undelivered packages and that we needed to click a link, and all the thing we knew about it was the news saying that uh we should absolutely not click the link. And being penetration testers, we kind of felt that we needed to click the link. Click the link, click the link. So we clicked the link to see uh what was behind the scenes. So that was the start.

Harrison Sand

Yeah. I guess we looked at a few. I mean, we had all been getting a ton of different messages, and you could kind of tell they were formatted differently, probably from different people, different groups. So we poked around at a few different ones initially. And uh so basically just clicking on the link, setting up a man in the middle proxy so you could kind of see the traffic going from your web browser back to the server, kind of watching everything. We didn't even know really what the scam was. Like, what did they want from us? Like, was it uh credit card or was it like banking credentials? So yeah, we poked at a few different, I guess you call them like platforms or phishing kits. And uh we found one that seemed pretty professional. That like you looked at the code and you could actually tell that like somebody had put some time and some thought into this. So we we I guess eventually we kind of just narrowed in and decided like okay, we're really gonna spend time on this one. Like, this is the one we wanna. They seemed like the a big player, I guess, if that makes sense.

Robby Peralta

So you guys uh everybody listening to this has gotten a SMS that says, hey, you need to do something that you're not supposed to do. It's trying to trick you into it. Yeah. And it was usually from in Norway, um, it's probably from Polsten or it's from a brand that you all we all know and love.

Harrison Sand

Yep.

Robby Peralta

Uh and switch you guys saw that and you knew that, okay, this is a scam. And then you said you made a man-in-the-middle browser. How do you go about doing that?

Harrison Sand

You install a piece of software. Um

Robby Peralta

on your phone?

Harrison Sand

Uh you can do it on your phone, but just for simplicity's sake, just say it's on your computer, right? And then you have Chrome or Firefox or whatever, and then you have this man-in-the-middle software. Uh, and you point, instead of your browser connecting directly to the server, you point your browser to connect to your man-in-the-middle software, and then your man-in-the-middle software connects to the server. So it's kind of just like a proxy or like a man in the middle, and you kind of you just you watch everything that goes through so you can kind of see what the website is actually doing.

Robby Peralta

By the way, this is this is called smishing when they're sending out these SMSs with phishing or with like links attached, right? Is that the term?

Harrison Sand

Yeah.

Erlend Leiknes

But the platform doesn't actually you don't need to click the link from SMS message. You could get it on an email. Yeah. You could change the context instead of a package on SMS, you get an email saying that you need to uh update a password. Then they could just change the uh like phishing package and ask for something completely different because they are trying to trick you with a context. Oh, you have uh undelivered package, you need to pay some extra postage stamp. Of course, you need to give away the credit card.

Robby Peralta

Yeah.

Erlend Leiknes

So the SMS is just the entry point to the entry point, yeah.

Robby Peralta

So that at the say at the end of the day, it's a link that they're trying to get you to visit and do something.

Harrison Sand

Yeah. Cool. So yeah, basically, we got a we got a link. Uh they put some effort into making the process of kind of understanding how the application worked difficult. I guess they knew that people were gonna look at their software. Imagine you were like you get this link, it's phishing, and you report it as suspicious. Somebody at some point will do like a domain takedown, somebody's gonna report it as suspicious, and then maybe your browser will like no longer like that domain will be bad, and then your browser's gonna block people from visiting that. So uh it looks like what they were trying to do is put some steps in between so that like just clicking on the link on a computer. So for example, you had to visit it from a mobile device on your phone. If you just took that link and like copied and pasted it into a into a laptop, you couldn't get access.

Robby Peralta

Interesting.

Erlend Leiknes

Um didn't they check if it was uh uh geo uh like the IP came from as well?

Harrison Sand

I I think so, actually. I think they were also checking the that the IP came from a mobile network. So that uh imagine you report a suspicious SMS that you get, and then there's some guy in a sock somewhere whose job it is to kind of validate like, is this real? Is this fake? Should I actually block this domain? But then you're sitting on a desktop computer, you click on the link, and nothing shows up. So how do you validate that it's actually a phishing page or not? And you can't unless you spend, you know, a few hours of time. And in most cases, the guy who has a bunch of tickets to go through is not gonna be. Something else. Yeah, they're gonna go do something else, and they can't validate it. So I'm my guess, there's probably a few different reasons they do it, but my guess is like it slows down that process, and then it takes longer for your domain to get blocked. Interesting. But also a side effect of that it was made our jobs harder.

Robby Peralta

Yeah.

Harrison Sand

So we had to there are a few different protections I had in place. We eventually were able to get around them and then kind of like see the actual so basically we were able to eventually load it up on a desktop computer with our software running, and you could see the traffic going back and forth. Even that traffic was kind of I guess they they used some levels of obfuscation and encryption.

Erlend Leiknes

Yeah, yeah, yeah. Yeah, the first hurdle we had was that the communication between the phishing page and the server collecting stolen credit cards and so on was encrypted by a custom implementation. When we tested it, we sat on the client, so we had the keys to do the encryption. So with some extra steps and debugging, we would find the hard-coded key and we were able to remove this layer of obfuscation.

Robby Peralta

And by the way, they were trying to hide this stuff so to make it harder to see what they were trying to steal, or what was the point of them encrypting this stuff?

Harrison Sand

That'd be a good question for a guy.

Robby Peralta

For them, yeah.

Erlend Leiknes

No, I it was it's uh obfuscation that you have to peel off, and once you have peeled it off once, you can you you you don't need to bother with that again. Yeah, it's just making it a bit harder.

Harrison Sand

It's like if you kind of think about like the lock on the front door of your apartment, right? Like it keeps most honest people out, but if somebody really wants to get in, they're just gonna drill. They'll get in, right? So it's it's kind of just like adding an extra layer to make they're probably gonna turn away a bunch of people who don't want to spend the time kind of digging down deep into it.

Robby Peralta

But you two.

Erlend Leiknes

Yeah, but for the uninitiated, this could be uh like a harder barrier to get across.

Robby Peralta

So well, I'll never crack crack any encryption, so I guess uh I would have gone home uh a while ago. But you guys didn't, so what happened next?

Harrison Sand

All right. So then we then at this point we could kind of uh we could actually see what was going on. So we had our software set up and you could actually see the data that was going back and forth. Basically, the scam was quite simple. You have a package at the post office, uh, you have to pay some nominal fee. I think it was like two crowns or like it was nothing. It was basically like, and then uh to pay the fee, you would type in your credit card. Um, but we could actually see because you could see that traffic, they were actually sending character by character, like as you were typing, like live, it was getting sent to the server. So at this time we didn't really know exactly what that you know back end page looked like, but you could kind of imagine they have like a live stream of everything you were typing. And you could even, you know, if you pressed backspace, they were even like sending the backspace characters. So we at this point we were kind of thinking, like, oh man, that would be a really cool thing to look at. Just like seeing like how does this look? How does the attacker or the operator they're just like they just have this like massive control panel, just like watching everybody like typing live. We thought that was kind of cool.

Robby Peralta

You guys noticed there was like a key, what do they call it, key logger there?

Harrison Sand

Basically, that's actually kind of interesting. So, like you would think um, you know, you're on this phishing page and uh you're like filling out your information and then halfway through you're like, ah, this is kind of sketchy. I'll just exit the page. But even if you didn't click the next or submit button, you had already given away whatever you typed into the page.

Robby Peralta

For example. Yeah, or the whole thing.

Harrison Sand

Yeah, so depending on how far you got, you actually still sent it even. So that yeah, so that was kind of interesting. Kind of made us uh a bit more intrigued to kind of keep digging to actually see what's going on.

Robby Peralta

But they were just asking for your pay payment card and they were asking for address info or what?

Harrison Sand

Yeah, so they would ask for your it was like name, address, credit card.

Erlend Leiknes

Um they could choose to ask for a PIN. Yeah. And that's on uh the discretion of the operator. If he wants to or needs the pin, he would be able to ask the user to enter a PIN code uh he or she would receive on the phone. Yeah.

Harrison Sand

At this point we didn't really fully understand how that worked, but uh it makes more sense like later on after we kind of like fully understood how everything came together. Um we see the traffic going back and forth, but then we were trying to like understand how does this application like how has it logically been put together? And kind of poking around at a bunch of different stuff, and eventually we came across I'm gonna simplify it a bit, but basically we came across what was kind of like a chat room. And when I say chat room, it's not humans talking, it was like it's a chat room for different computer systems to talk together. And the reason I'm gonna use chat room is it's kind of like the terminology the developer used, so it makes it just a bit easier to put everything together. But basically what it looked like was that the phishing victims would have their web browser open and this data that you know, the the phishing data, the credit card data, their names that they were typing, that was getting live streamed to a chat room. And then you would also have the admin backend page that was subscribing to the chat room, and they would just see the messages together, and then that would allow the system to build that page or like the the live. We would assume at this point. Like basically we were kind of assuming, but basically what it looked like it was those two chat rooms were come together, and that was like how the phishing data would come in, and then how the operator of the site would see it. And when you first connected to the phishing page, there was a command where you joined the chat room. So there was a command and it said join room, and then you could specify what room you wanted to join. And by default, you joined like an empty default room. But then we were looking through the code, and there were more rooms than that. And there was a room called admin. So we were like, what if we just like replace this default room with the admin room?

Erlend Leiknes

Yeah, because the reason we saw it admin room was because we the phishing victim would be sitting in the default room and not receive any messages. But as the victim would type all the details in, yeah, it would send the details into the admin chatroom. Yeah. So it was like a one-way communication. You didn't get anything back, you just gave a way data.

Harrison Sand

Yeah. In essence, we could see that there were different rooms. You were in one room and you were sending data to another room, and we were like, what if we just joined that other room that we're sending data to? So we did, made a small computer program to kind of join that room uh manually. And uh I think at that point we kind of just sat there and we were like, holy shit, because it worked, and we essentially got a live stream, an identical copy of what the phishing operator would have seen. It wasn't like you didn't have the you didn't have the pretty web browser showing everything nice and organized, but you got like a live stream of all the phishing data that the operator was seeing.

Robby Peralta

I could just I'm just imagining like a matrix like following uh credit card numbers here.

Harrison Sand

It was like a in our terminal, we just had this like super rushed together scripts, and it was just like it was the data was flying by our screens faster than we could read it.

Robby Peralta

That was people typing in their credit card.

Harrison Sand

That was that was like live stream. You could type, you could see like character by character people getting fished all around the world. Like because they would type in their address and their name and you would see where that like where the active fishing campaigns are. Uh it was a bit like

Robby Peralta

were you guys in the same room at this point?

Erlend Leiknes

No, I think you put it uh yourself.

Harrison Sand

Yeah, one evening I went down the rabbit hole and I was uh you were looking at another fishing website.

Erlend Leiknes

We hadn't decided which uh phishing kit to look at yet, so we kind of looked at all of them.

Harrison Sand

Yep. And then uh and then uh I was working late one night looking at this one and uh found what I found, and I was just like, holy shit, Arlen, I think this is the one we need to focus on.

Erlend Leiknes

Yeah, you kind of agreed quickly that we should uh dig deeper into this one.

Harrison Sand

Now you have the basically the fishing data, you could see the scale of the operation, and it was it was so many people.

Erlend Leiknes

Yeah, and I remember the discussions we had, like, should we start telling the banks?

Harrison Sand

Yeah, exactly. Because I mean, imagine, yeah, because you have all this data and or you have access to all this data, and you're like, do we call the police? Do we call the bank? You could save people money if you had these credit cards cancelled. We sat for a while kind of thinking like the ethical uh dilemma that we had, and it was tough, but I think we eventually landed on okay, so we could sit here and we could collect, we could see this stream of data and basically copy what the thieves are stealing. But it's probably only going to be for a limited amount of time, you know, if they change the code, if somebody else finds this vulnerability.

Erlend Leiknes

Yeah, and at this point, this was only one of many phishing servers, and we would only have access to ones that we had links to.

Harrison Sand

Exactly. Uh it's basically a software package that you install on your own server. So every phishing operator runs their own server. So we had access to like a few servers if we happened to get a link to them or if we were able to find them somewhere. But there were probably you know, hundreds or thousands of other servers doing the exact same thing that we didn't have access to. So we basically had very limited insight into one or two servers, and we kind of knew that yeah, maybe we could do this for a few months, but at some point we would lose our access. And we were also a bit worried too, because like if we collected that data and gave it to the banks and they started canceling credit cards, does that you know, is there a police investigation against these people? Like, here's an opportunity to maybe make a difference. Because you see, you know, yeah, like Arlen mentioned, like you see in the news everyone's getting these pages or these these uh SMS messages, everyone's saying don't click the link. But I hadn't seen too much like who are these people? Like, is anybody doing anything? Are they getting in trouble? Like, what's happening? So we kind of thought, like, here's maybe an opportunity to make a difference and actually solve this problem as a society instead of just a super, super small subset of victims in a limited time frame. So we kind of like we we decided to take a step back, try and focus on the bigger picture. So we kind of just ignored that data for the time being and kind of kept going to see if we could find out more about how the software worked.

Robby Peralta

Like a good cop would do in uh when they have the the bad guy. Yeah. You can get the lower level, but you gotta go for the higher. Yeah.

Harrison Sand

Yeah, that's basically what we tried to do for admin chat room, and we realized that most of the data was phishing victim information. But every now and then there was some other data streaming through there as well. So just imagine you're an operator and you have this page open and and you're getting live updates of all the victims. But you also can get, you know, pop-up messages or alerts, you know, and maybe there's an update for the software and you want to like click on the update button, or if you want to uh running some software and you get a pop-up window. So you get like uh logs or alerts. And and that was kind of in that chat room as well. And eventually we came across some logs from the system where it was creating it was something related to a database. It said like a database has been created or deleted or or something, or there was a problem with the database, but whatever it was, there was an error message and it said the name of the database. And the name of the database was Darcula. And I just sat to myself and I was like, this feels like a username. I I I didn't really have much to go on, but it wasn't like Darcula. Yeah. So like you wouldn't uh because like normally you name a database, it'd be like customer or like I don't know, victim, or like passwords. Yeah, passwords, or I don't know, like whatever. Like I would and but they called it Darcula. So what do you do? You Google it. And it's the name of a theme. Like it's a color scheme that a lot of different programs can use. Okay. So when you Google it, even if you go to page like 20, it's just full of like download this color theme for this software. And it's so basically nothing. It's just like even if there was information about this hidden somewhere, it was just buried in all of this, like download this theme package here. And then kind of thought, okay, so you have some criminals, like, how do you find criminals? And this was around the same time when there were a lot of articles, the New York Times had a front page piece on basically how Telegram was the hotspot for criminals. So I just gave it a shot and I typed in Darcula on Telegram, and pretty much immediately found a group called Darcula and a user called Darcula, and you just go into that group, and it was just like photos of credit cards and SIM cards and people spending tons of money at bars and driving fancy cars, and I was like, okay, this an open group. At the time, it took a bit of sleuthing around. There were a few open groups, there were a few closed groups. Sometimes they would share invite links to the closed groups in the open groups. Up sex. Yes. Yeah. Uh I was able to get enough information by poking around to say, like, okay, like at least here's the right group. And then I kind of just like clicked on a bunch of stuff, tried to join a bunch of groups, see what's going on. And eventually we got access to this. It was it was closed, but not impossible to get into. Should have been closed, but for you guys. Yeah, basically. We were like, okay, so seems like we're kind of on the right track here. And uh eventually, you know, was going through all the messages, and they shared some documentation on how to download and install the software that we were looking at. So we were looking at it running, you know, out in the wild, but now you have an install script or like some documentation like here's here's you can download it yourself. So we got a got a laptop and uh ran that script.

Robby Peralta

So at this point, you are looking at the program that the bad guys were using to collect all this uh credit card information and from the SMSs.

Harrison Sand

Yeah, so we hadn't so like we we were fairly certain we were on the right track and that it was like the same software, but we had to kind of install it and double check it was, ended up being the case. Um so so yeah, we basically uh we download the software, install it on a on a dedicated laptop, and uh they obfuscated or encrypted all of the data that was getting sent from the victim's web browser to the server, and then they did the same or similar thing with the code. So if you download the software, they ran it through like an obfuscation tool, which basically takes the code, jumbles it all up so that you can't really see what's going on. Yeah, and then we actually got kind of lucky because somebody it gets a bit technical, but I guess that the code still needs to run on the computer, so the computer still needs to understand how the code works, but it makes it harder for a human to understand. So you run it through this, they ran it through this open source obfuscation tool, and then another, there's another project that's also open source to basically reverse the first tool. So the developer obfuscated everything through this one tool, and then we just run it through the other tool to kind of go back, and then and then we had access to to kind of see okay, how does this work? How does the activation process work?

Erlend Leiknes

Yeah, that saved us a lot of time. Yeah. But with access to actually reading the code, we noticed that there was checks if this instance we were running were a license server or if it was a phishing server. So it was the same software had two purposes.

Harrison Sand

Yeah. Because you needed to buy a license, right? So then you have um, you know, the operators of this uh phishing software, they have a Server out on the internet, and if you pay for a license, you know, they're gonna log into this licensing server, they're gonna make an activation key for you. You get you know, you pay some crypto, and then you you uh you know share the activation key.

Robby Peralta

Those guys are corporate, yeah?

Erlend Leiknes

Yeah, but so basically we were able to set up our own license server, and then we could install new instances of this phishing kit and generate licenses and license it and uh get a green b uh green check mark saying that uh we have paid for it. Yep, yeah. And then we could really start digging into how it was working on the admin side of the yeah.

Harrison Sand

So now we basically set up like a offline copy of like the entire infrastructure. So we had basically a copy of this central licensing server running. We had a copy of the phishing software, and we could just you know, go ham. We could like just hack as much as we wanted. We didn't worry about people seeing what we were doing because everything was kind of on our own systems. I'm just seeing like, you know, just curious, like, are there vulnerabilities here? Are there backdoors here? Like, what are they like how does this work?

Robby Peralta

And so just uh just a quick question. So you two at this moment in time could have put in my phone number there, sent me, sent me a phishing link, and if I would have gone in there and added it, it would have gone to your server and you would have had my everything I think.

Harrison Sand

Or even even better, we could have up we could have opened up a second telegram group with like half off price for the phishing software, right? Because now we had our own like activation server. So I think if we really wanted to make money, we could just like just make like a second group.

Robby Peralta

Yeah, because at that point you had the keys to sell or give away that software.

Harrison Sand

Basically.

Robby Peralta

Which is you and the the owners of the the software that was they didn't they didn't know that you were doing this. No, they didn't. They don't to this day know that you're doing this, or did they?

Speaker 1

No, not yep, no, no.

Robby Peralta

Was it in English?

Harrison Sand

Uh no. Everything was Chinese. Uh so we even got some hints along the way that it was probably a Chinese language group uh when we started looking into the software. Some of the um even before we got access to the Telegram group, uh there's some like Chinese notes and debug and log hints. Okay. Then when we got access to the Telegram group, it was like completely Chinese.

Erlend Leiknes

Yeah, and that was that was really surprising to us because there was no hints uh before we started looking into it. There was no mentioning in the news who were behind it. And uh what we saw, it was as far as we could tell at this point, only uh Chinese speaking uh people.

Robby Peralta

Yeah. Interesting.

Harrison Sand

Yeah, Google Translate was a good uh surprisingly worked surprisingly well.

Robby Peralta

Yeah, so so this was uh I guess ChatGPT was not out yet, or

Harrison Sand

I guess it was. Yeah, it was, yeah.

Erlend Leiknes

Yeah, yeah, but Google Translate is uh does the job. But it was uh hard to understand the context.

Harrison Sand

Uh well the the software was okay-ish, but the reading the messages in the telegram group are really tricky. Like slang and yeah, imagine, imagine like even if it was in English or whatever, like you log in, like if you just join some random group, you know, they have their own slang, they have their own way of talking.

Robby Peralta

Inside jokes too.

Harrison Sand

Exactly.

Erlend Leiknes

A big culture barrier for us to understand.

Harrison Sand

And they have like their uh this was new to me, but there's like an entirely different like culture of memes in uh in China. So you have uh cats. Yeah, yeah, or like tons of just like completely, it was like a whole nother universe that I like didn't understand. So even like so basically what I'm getting at is like you may not understand the content of the messages, but then like you see like a meme and you're like, okay, at least maybe I can get memes, but it's like no, like I don't even know what this meme is like at all. Did you feel old? Old and lost, and I felt like I was in a parallel universe. It was uh yeah.

Robby Peralta

Well so I'm just imagining you guys taking this like at this point, you're like in this portal highlighting the buttons and trying to get the text, or is that just to see what the button means? Or was they have like an English tab? So you can like

Harrison Sand

Nope

Erlend Leiknes

the the good thing with programming languages is that it's logical in terms of like we can add numbers and concatenate strings and uh so the software was like yeah, so when we looked at the code, that's basically English.

Harrison Sand

Yeah. Um, but then like the front end page that the phishing operator would see, that was all Chinese. Yeah. But then yeah, we were basically just like putting it to Google Translate and Yeah, interesting.

Robby Peralta

Yeah, okay, cool. Okay. Now uh now what happens?

Harrison Sand

Yeah, so now we um

Erlend Leiknes

you mentioned backdoors.

Harrison Sand

Yeah. Uh you can go through that one.

Erlend Leiknes

Yeah, because that was funny because uh looking at that with uh like the eyes from the security industry, we uh had access to read the source code for the APIs, and then we come over some strange um conditions. And I remember the first thing we said when we looked at it was this looks like a backdoor. Yeah. And it turned out it was. And it was a bit strange because it we couldn't actually see uh why it was there, but we could guess, but it was not in use. So it was like a plausible deniability backdoor at uh best, I guess.

Harrison Sand

Yeah, so basically it works. So when the phishing operator, when they want to go use the software, uh you have the URL that the victim would go to, it's like post dot whatever dot whatever. Um but then you go to like a secret URL, and then you get to a login page. And and uh when you set up the server, you know, it tells you what the secret URL is. And then you have a username and a password and you log in. Uh so what you're supposed to be able to do, or like like any piece of computer software basically, you're supposed to authenticate first before you're able to get the data. Um, and then you kind of get an authentication token in exchange for your username and password. And we basically found out that under a very strange set of conditions, you didn't need to send that authentication token. And it was we we we were only really able to figure this out because we were looking at this uh deobfuscated code. It was it was quite unique in the way that it worked. You would basically say that you were coming from another component in the application that didn't exist, plus some other stuff, and then you could just basically ask the server for any data without a username and password, and it would give it back to you. And yeah, and and Arlen kind of mentioned so it was basically it looked like a backdoor, and it and it could have been a backdoor, it could be a backdoor, could be a mistake, but it also could be, yeah, like Arlen said, it could be a backdoor built to have a good plausible deniability. Uh so basically saying, like, you know, if if somebody called him out on it, be like, oh sorry, I just made a bug.

Erlend Leiknes

Or thank you, I'll fix it.

Harrison Sand

Oh yeah, exactly. Yeah, so don't really know why it was there. Fun. If you put your black hat on, you could think, you know, maybe if I'm the writer of the software, if I skimmed a few credit cards off the top, it's some extra income. Don't really have any proof of that, but interesting thought, maybe. Don't know. How did you guys find that?

Erlend Leiknes

Oh, we had access to the source code and we were able to de-obfuscate it. So while looking at it, it's it's our job to find issues like this. Yeah, like that.

Harrison Sand

So you have the code in front of you, and you would basically have a section that handles authentication, right? So like normally you have like before, let's say you want to get victim data, right? And there's some request to the server to get victim data, and you can kind of see how that flow goes. So you start at the top, and then it basically says uh first thing is do you have the right credentials? You know, do you have this authentication token? And then normally you would say like true, false, yes, no, and then it would give you back data. That's what you would normally expect to see in most applications. But here there was some extra code there. Maybe statements. Yeah, it was basic, yeah, basically kind of saying that like first check if you have your authentication token, but if you don't, also check this other weird stuff, and uh then if this other weird stuff is in place, then you could also return the data without the authentication token. So kind of just going down that rabbit hole a bit and be like, what you guys just looked at that and like hmm, backdoor or this is a little bit. Yeah, it's like why like why would you have functionality to return sensitive data without providing authentication? It's just it's weird. Yeah. Like, why why does that logic exist?

Robby Peralta

Interesting.

Harrison Sand

I mean, we already had through that, you know, we kind of already through this the chat room functionality, you know, we could already see a lot of the like victim data that was flying by and some of this debug information about how the software worked. But now uh that we have this backdoor, we basically could do any function in the application that an admin or like a phishing operator could do. So we could change settings, we could look at logs, we could see like the history of this chat room kind of to uh simplify the new users. Add new users, see who's logged in.

Robby Peralta

I'm the captain now.

Erlend Leiknes

Yeah, basically. Yeah, like we could log in and uh get that well, we already had access to the um the phished uh credit cards, but now we would see it in a nice web portal at the uh in the same way that the phishers would.

Harrison Sand

Yeah, so now we could basically log into any phishing server. If we knew the phishing server, we could log into the phishing server. And now it's a bit interesting too, because if you go back, remember the phishing server is also the same software package as this licensing server, this activation server. So we also had a backdoor to the activation server. And then uh we also knew, because we set up our own activation server, that there's a list of activations on the activation server, right? So uh if we were able to use this backdoor on this activation server or this licensing server, you would have you would be able to see, get really good insight into the scale of the operation, how many people have bought the software. And there was also guessing at this point, but it seemed likely, there was a comment field, right? So you if somebody buys a license, you're gonna say, who bought the license, when, you know, uh, how long is it active for, how many activations is it valid for. So we thought, yeah, maybe there's the name of whoever bought it, and maybe like so we really wanted to get this like central database of who bought the software. So that was a process.

Erlend Leiknes

They were using Cloudflare to hide themselves on the internet. So we know flare. Yeah, so so uh it was in their instructions on how to install the software, so everyone did it the same way. They would use Cloudflare because that was the documentation stated that they should do it. So when they installed their own server with the phishing kit, and instead of uh giving the links directly to their own server, they would put Cloudflare in front of it, and I'm guessing for two parts to hide the identity of the real server, but also to get uh HTTPS very simply installed on the web server.

Harrison Sand

And and basically the I guess why this is kind of important is Cloudflare or our backdoor for some technical reasons, our backdoor basically only worked if you could connect directly to the activation server. So Cloudflare normally would sit in between. So you have your server, you have Cloudflare, and then you have your victim or whatever, your web browser. Uh basically Cloudflare would kind of strip out the content of our backdoor, so it wouldn't work. So we had to kind of find a way to go around Cloudflare. But we didn't, but that IP was hidden because Cloudflare hides it. So we didn't know. So basically, we kind of had to search the entire internet to find a needle in a haystack to find like where is this activation server? What is the IP address of this activation server?

Erlend Leiknes

But luckily we didn't have to scan the entire internet. We could make a very accurate fingerprint. So I think we had 5,000 candidates when we searched on Showdown. And then we wrote a manual test. We just connected to the same chat room with the software you made to listen to the messages sent to the admin channel. And then we I think we got about around 1,000 servers uh online at the same time.

Harrison Sand

Yep. We narrowed down, we found a way, because Shodan, basically the search engine for servers, uh kind of uh yeah, we found we found a query that allowed us to narrow down basically to find copies of this software running on the internet. So Shodan did a lot of the heavy lifting there. And then we kind of made a small script to poke each instance to see is this the server we're interested in. Is this you? Is this you? Is this you? Basically, yeah. Yeah. And then eventually we got lucky and we we found the right one.

Erlend Leiknes

Yeah, and the license server.

Harrison Sand

Yep. Very happy to see. Basically, I think at the time, these aren't exact numbers, but basically there were there were several thousand activations. And each activation can be used multiple times. So you do have a lot of people buying multiple activations because it's only active for a few weeks at a time or however long you want to pay for.

Erlend Leiknes

Do you remember how much it costs? We just found out, I guess.

Harrison Sand

I think it depends on the plan you pay for. I don't know, around around $100 a week, maybe, or something around those along those lines. So yeah.

Robby Peralta

So if I want to be a bad guy into the submission stuff, I pay somebody a hundred a couple hundred dollars a week, and then I'm I get access to this platform.

Harrison Sand

Yeah. Uh but so yeah, so uh in this database, you got the activation key, and you got the as part of their like bookkeeping, they uh kindly uh put in the telegram username of every person who bought the software. So we have a database of every telegram user who bought the software, when the license was issued, how long it's active for, and also it keeps a log of the IP address that was used to perform the activation. So now you have an IP address of every single phishing server that's out on the internet. And not and and also the one that's uh not through Cloudflare, right? So this is uh so basically the server, when it when the server wants to request an activation key, it talks directly to the licensing server. And now we have a copy of a log of each time that happened and the IP address. So now we had basically thousands of names, of usernames, and thousands of IP addresses. And yeah, this was uh

Robby Peralta

So at this point you know who a lot of a lot of bad uh guys are.

Harrison Sand

Or at least who their online identities are, yeah. Yeah. And we could we had a really good view of the scale of the operation. Um and uh thousands of smishers. Yes. And I think at this point we kind of like consolidated everything we found, all of uh like the scale, the numbers, you know, our estimated, how many victims there were, uh, how many credit cards have been potentially stolen. And uh we made a report and we were like, okay, this is the time to contact law enforcement. We knew the IP address of the central server. We're pretty sure it was located, or maybe still is located in a hosting company in Los Angeles. So we're like, uh, okay, so like if the police want to get involved here, they could go out and tap the server, you know.

Erlend Leiknes

Yeah, and at this point it was also we had the link between who had bought the software, uh, where the server is, but also uh every victim that this uh criminal have fished. Yeah, like every victim, uh it was like a chain from uh telegram user, server, and victim.

Robby Peralta

So each uh each one of these platforms that had bought a license, they probably had what thousands, tens of thousands of victims per

Erlend Leiknes

a hundred thousands in total then.

Speaker 2

Yes.

Robby Peralta

Each one of these users that had bought the platform, maybe one was in Brazil, maybe one was in, I don't know, Norway. Yeah. Like this. So they each one would buy it, customize it based on the brands or in the country, and then make up their own method to get people to click on it, right?

Harrison Sand

Basically. So yeah, I think it's like timeline speaking, I think we're spring of 2024-ish. And at that time, I think there was like 230, 240 brands that you could impersonate. So like fishing kits, so like you have Poston or USPS or DHL or and there were just basically 240 of those. So you can kind of imagine the scale. Like basically every country has a few different ones. And we're kind of like roughly estimating that there had been potentially around a million stolen credit cards and in total. We don't have uh insight into exactly how much they charged on those cards or if all of them were, you know, maybe some got blocked in time or whatever. But you you can do the math and imagine that you know there's a lot of money moving around here.

Erlend Leiknes

There was uh one Swedish news article said that uh uh this type of loss usually yielded five thousand. But then again, we don't know if they charge dollars or Swedish corners. Swedish. But we don't know if every credit card that we had had been abused.

Harrison Sand

Yeah. But basically, we had a lot of it was big. I think there was no question that it was big, uh, and we had a lot of information. So yeah, but we basically we brought it all to the police, shared it with a few different police agencies. We we were really worried that we didn't want to step on the toes. Like if if we continued and there was an active investigation and we kind of scared every we messed up and we scared everybody away. So we wanted to avoid that. Um so basically we did that and and uh they were happy to receive the information. I'll say that.

Erlend Leiknes

We kind of got a confirmation that we were not stepping on any toes.

Harrison Sand

Yeah. Nobody told us to stop. Yeah. So which is a good sign. Yeah. So we kept going. Yeah. Yeah. So basically we had the identity or the the online identities, like the usernames of all these telegram users. Some were more public than others, people sharing, showing off their money, driving fancy cars, going out to bars. Some were like the uh Darcula, the developer, very quiet. Like he would basically almost never talk to say, like, hey, there's an update uh for the software, go click on this or go do that. It was uh so he he was uh he was an interesting target. Wanted to kind of like He must be smart. Yeah, uh this was interesting because the the software I mean minus the back door maybe, but like it actually like it was easy to install, worked pretty well. Modern?

Erlend Leiknes

Modern new frameworks, it was uh logical and uh nice uh setup.

Harrison Sand

It was it was a very good piece of software if it was made by one guy or a small team. Uh at the same time, you know, this Darkyal identity was quite quiet, so we we were like, okay, who's this person? So as part of the licensing server has logs, like most servers do. And in those logs were entries that basically said this person logged in at this time from this IP address. I'm simplifying it, but basically we could see the IP address for the admin of the licensing server.

Erlend Leiknes

Yeah, and only guy logging on into a licensing server is someone that manages the license.

Harrison Sand

So even if it even if it's not Dark Hello, like this is an interesting IP address. This is where like the inner circle, basically. Yeah, basically like this this is somebody's uh internet connection. Somebody who somebody like deep in the group, this is their internet connection, or like where they're accessing the server from. So we poke around a bit, and the IP address was located in Alibaba cloud. So it looked like a virtual machine in Hong Kong. And most the time you're not sitting with a laptop in Alibaba data centers, so we figured this is probably a VPN. And it is quite common for developers and tech-minded people uh in China to use VPNs, because if you want to access Western resources like YouTube or whatever, you have to use a VPN. So it it felt at we didn't know at this point if this is like uh you know just a server that they set up to use as their own VPN, or if this was like a shared VPN service where you have a lot of different people using. But yeah, I kept wanting to see like, okay, what is this IP address? Who's who's been using this IP address? Um we looked. There's something called passive DNS. Mnemonic actually has a passive DNS service helped up quite a bit.

Erlend Leiknes

Yeah, so we used the passive DNS service to look up the history of this IP address.

Harrison Sand

So yeah, so basically like uh a DNS record kind of points your server's IP address to a domain name. So when you type in Google, that translates to an IP address, and then you know your computer knows how to get to Google. And this is basically a historical log of looking back in time to say three years ago. Like we could look today and see if it was like registered to anything, but like this is going back in time to say like this domain name pointed to this IP address at this point in time. And so we kind of looked through that database. And it was a it was a loose connection, it was a bit strange, but basically this IP address pointed to a GitHub account. So normally you would point to like a website or domain name, but basically it was like a redirection. There was a domain in between, it's kind of complicated, but basically we saw hints that this IP address used to be registered to a domain name, and if you went to this domain name, it would forward you to some guy's GitHub account. Basically, this me at this point it really didn't mean much. You know, IP addresses move around all the time. You know, it could make a virtual machine in Alibaba Cloud, and I would get a random IP address that somebody else used before. So we thought, you know, it could have just been random. Was using it and then they deleted their server and somebody else got the IP, didn't really know. But we thought it was interesting that this GitHub account was the developer was developing software using the same types of languages or like software stacks as the phishing software. So we're like, okay, so a few years apart, this IP address was used as a VPN to log into the phishing infrastructure. And then there's also this developer who at also a few years ago was using this IP address for their website. And then they're using the same technologies. It's popular technologies, it's not the strongest link. But we're looking through their GitHub page, we're looking at their code, and like whenever you put code in GitHub, you can uh put your email address kind of like as like this this email, put this code here. Kind of. We saw an email address for a Gmail account. So we sat there for a while, we did some open source intelligence work, and we found out that there's some services out there where you can type in an email address. And you know, like when you forget your password for Google or something, you type in the email and it's like, oh, we sent uh to recover your password, we sent a text message to this phone number, but they don't give you the full phone number, they give you like the last two digits, right? So we found out that this email address, the last two digits associated with one of these accounts that it was used for, uh also was the last two digits of a phone number that DARKula had on their Telegram account. So we had seen this phone number before, and it looked, we're not completely sure, but we think it's like a burner Google Voice phone number. But then kind of thinking, okay, so we know Darcula, the Darcula identity on Telegram uses this burner phone number potentially. And here's this email address, who's loosely linked with that VPN server and the Gmail account. But then that Gmail account has a phone number ending in the last two digits. So like, okay, so like it's still kind of fuzzy, but you know, some pieces are coming together. So we we we kind of like sat there and we couldn't really we weren't we didn't know what to do.

Erlend Leiknes

Yeah, we kind of just kept on digging and digging and adding in data points on this profile of uh like this developer. And and we could see that there was very much data that could fit. Yeah.

Harrison Sand

And uh but there was no like smoking gun. We it was like it's it's plausible. Yeah, it seems like if I had to bet money on it, I would say probably. But like you can't we didn't yeah, we didn't we basically didn't know for sure.

Erlend Leiknes

And also like the confirmation bias, like we would keep on looking and just like we didn't reject ideas like oh maybe have a second phone number. But we kind of had a good hope that this could be the guy, but uh for very long we didn't have any strong links to if uh if he were actually Darcula .

Harrison Sand

Yeah, yeah. So at this point, our kind of are working like if we had to play devil's advocate against our like working theory, you know, it could have just been an innocent developer who had reused the IP address. So we so we knew that this IP address was used by a developer a few years ago, but we didn't know if it was still used by the same developer. So uh without more leads to go on, I was uh sitting one afternoon and I thought, you know what? I'm just gonna send this guy an email. An email to the Gmail account for the public identity of this developer. And in the email, I kind of on purpose made it look like spam. So like if you got it, you wouldn't be too suspicious, you could kind of just ignore it. But I it was like asking a question about like, hey, hey, how does this code work on one of your projects? Like, I'm confused or like whatever. And there was a link, I put a link in the email to say, uh, hey, here's some more information if you want to click on this. But when you clicked on the link, you could see the IP address that visited that page. So like he basically clicked on the link, and then we could see that uh it was the same IP address from that Gmail account. So the guy using that Gmail account had the same IP today that was also logging into a licensing server for the whole like Dark Eli infrastructure. So we'd like, okay, so like basically pretty strong link that you know it still theoretically could have been a shared IP, but you know, pretty good link here. Like, okay, so this guy is uh probably the right guy.

Erlend Leiknes

Yeah, we found the like the when we looked up the IP address on passive DNS, we got a couple of host names of uh old web pages that didn't exist anymore. So when we looked at the internet archive, which is an archive of uh Wayback Machine or Wayback Machine, yeah. Like old web pages, how they looked before, and if they were deleted, you can still have a look at how it was before they disappeared. So we found some um uh old web pages, but we also found uh documents and in like Word documents, and uh in the Word documents it's uh usually uh author field like the

Harrison Sand

metadata of the document. Like if you right-click and click on properties, you can see the username of who made that file.

Erlend Leiknes

Or like you most of the time the like the name that you would fill out, like the real name. Yeah. So that was the first time we actually found a name for uh that could be the name of the Darcula , like the real identity. Yep. And the name of the Word document was

Harrison Sand

Yeah, basically, basically in in uh it was in Chinese characters, but if you put it in the Google Translate, you could see like the name was if you translated that name in the Word document, it was sh. So we got like we got two people with as a name. Yeah, and then yes, you said we found the third document, then it was also a Word document with some uh like support material for the software. And if you looked at the metadata at so this was a Word document shared by the Darcula user in Telegram. And if you looked at the metadata of that word file, it also said Yeah, it's like proper OPSEC failure. Yeah, so we have like we have a bunch of different documents that all say. We have the email address that says we know the IP address was reused. So we're like, okay, I think we know the name, name of this guy. So we we went through the the way back machine, we had a few different email addresses that were associated with some websites. Um we also we had like the phone hints, hints that like when you have an email, right? Like I was talking about, you can you can kind of get all the different uh partial phone numbers. And on some of those accounts, there was a Chinese phone number. And you know, in a lot of countries, they're kind of cracking down on burner phones, so you need to provide an identity.

Erlend Leiknes

Yeah, we like the same in Norway. Yeah.

Harrison Sand

So yeah, basically, like you need to give a passport or an identity document or like something to get a SIM card. So if you find we knew that the US number was probably a burner number for Google, that's probably not gonna go anywhere. But we knew if we found this Chinese phone number, there was a really good chance that we could use that as a pivot point to find like an actual identity. So we did a lot of OSINT uh it's kind of funny. Um there doesn't seem to be a standard for what digits of a phone number get disclosed as part of that password reset function. So imagine like Google might give you the last two digits, but PayPal might give you the first two and one of the last digits. So if you do this for a bunch of accounts, you can kind of overlap them together and narrow in on what the actual phone number is. So I think we used this OSENT as far as we could, and we we narrowed down on uh there were three missing digits, so we had like a thousand a thousand possibilities for this number, and then uh you you helped crack the last three.

Erlend Leiknes

Yeah, we found some service on the internet, which is basically uh search database for leaked data, and it allowed us to enter phone numbers, and uh I spent an evening and scripting and just inserting uh 1000 phone numbers to get leaks that had also leaked the phone number, and it was quite a shot in the dark because we didn't know if there was any leaks that actually had the phone number of DARCA. So after one uh good evening, uh we think we sat with 15 candidates, and then we got what we got from the phone numbers is uh leaks, not like password or usernames, but it's like this phone number is associated with this email address. It was a QQ uh like a Chinese email provider. And then with these 15 email addresses, we went back to the open source intelligence tools and then entered data and then looked for like connecting points. Is this uh new data that we find? Can we tie it back to what we already have?

Harrison Sand

So eventually, so one of those candidates, we took that phone number and we found that it was associated with an account that had the same avatar, it was pretty unique, like avatar image of like one was associated with phone number, and we had seen that one before because it was associated with uh it was Instagram, but basically that that we had seen that before and it was associated with one of the other accounts that we had found. And we're like, okay, this is like pretty good chance like this is the guy's phone number. Um we basically to kind of take to take a step back, you know, we're we're tech guys, right? We can do we can do this like uh technical investigation, but we really wanted to be able to make a bigger difference because we had seen some other research into not exactly this group, but other phishing campaigns. And it seemed like the research kind of always stopped on the technical level. Like it would, it would kind of circulate in the tech groups, like so I would see it, but it's not something the average person who gets these messages would really understand. And it was mainly like, how does the software work on a technical level? And we were thinking, okay, so we can we can provide that context, but if we bring it to uh somebody who does like proper investigative journalism, you know, maybe they can find out who these people are. They can kind of take it to the next level and actually tell like the human part of the story, not just the not just the bits and bytes, the tech part. So yeah, we had been uh talking with uh a reporter at NRK. They have some sources and they have some contacts, so we kind of handed over, you know, we had the phone number with email address, and we kind of we basically gave them everything we just talked about now. We kind of briefed them on. And uh they worked their magic with their connections, and uh, they were able to come back with the proper identity of of our guy. They found him. So yeah, that was uh that was a cool day.

Erlend Leiknes

Yeah, and I think like our job ended at the technical part because here is people who have lost real money, and uh there is ethical conundrums that is better sold by journalists than by IT people.

Harrison Sand

Yeah. And it's and it's of course, like I think it's an interesting, like the tech stuff is definitely interesting, right? So there, I mean, there's for people like us, it is interesting to see, you know, how does the software work? What kind of protections do they put in place to make our job harder? That's interesting. But I think you know, everybody all around the world in every country is getting these text messages. And it's super interesting in my mind for the average person to understand, like, okay, who are these people? How are they operating without getting caught seemingly? How are what are the systems in place? Like, how what do we do about it as a society? And I think those are the kind of questions we felt that would be best answered by, and of course, like the you know, the investigative journalist and journalists, they have connections with banks, they can talk to people who maybe would have more insight into the financial side of things or you know, working with the cell phone companies for like how did these messages get sent in the first place. So we kind of wanted to give the story away a bit to help build it into something bigger than just the tech.

Erlend Leiknes

Yeah, and in the beginning when we started, the only thing we saw in the news was that we shouldn't click the link. Yeah. So kind of added, you gave some heat to the bone for uh the uh what was that going on? Yeah, definitely.

Robby Peralta

So maybe I'll have to have NRK on as a as a part two to this, but before I let you guys go, uh I mean so this process you worked on it for a year and a half now or what?

Harrison Sand

Yeah, almost a year and a half.

Erlend Leiknes

Not full time, thankfully,

Robby Peralta

but uh have you noticed any change in the industry itself? Like uh on their side?

Harrison Sand

The uh the phishing groups.

Robby Peralta

Yeah.

Harrison Sand

A bit. The software's gone through a few different iterations. It's been it's in pretty active development.

Robby Peralta

Uh, this is still happening as we speak.

Harrison Sand

Yeah, there's people uh there's people getting text messages from these guys today. I I think uh they made the rounds in Norway like two weeks ago.

Erlend Leiknes

Yeah, remember I got some uh messages not too long ago. Yeah.

Robby Peralta

So is nobody more happier than you to uh oh look, yeah. I wonder if it's uh Yeah, yeah, yeah.

Erlend Leiknes

And sometimes we actually see it just

Harrison Sand

Yeah, because we we know the because I mean remember we started, right? We got that initial message, so we know the format that they use.

Robby Peralta

Oh template.

Harrison Sand

Yeah, yeah, yeah, basically. So like you it says template, and then uh you know, you it's it's not uh you know, you people could reuse templates, but you know, you see the you see the link and you click on the software and it's like yep, same guys, here they are. Sending links out to everybody again. And they uh yeah, they did it, I think they did it around the like Christmas shopping season uh before getting a lot of links.

Robby Peralta

So you showed a picture of some phones that were kind of like being used.

Harrison Sand

Yeah. In these telegram groups, they just they're basically advertising, right? They want to look cool, they want to show that they have access to trying to sell their platform. Yeah, exactly. They're trying to sell their platform. So you see walls of phones, hundreds of phones, just like all connected together on a rack, running automated software, and they have videos of these phones, and it's mind-boggling. It's just like uh running some software, and it's just they're in the messaging app, and it's like boom, boom, boom, boom, boom, boom, boom. You see it sending out text messages to like yeah, like the whole world basically. It was crazy.

Robby Peralta

I just thought it would be more smarter than that, than having like a wall of phones. Like I thought that it'd be a computer, like you know, but it's actually like real phones. What the fuck?

Harrison Sand

Yeah, yeah. I mean, uh, but I mean uh that's what they were showing, but I guess you know, this software is just uh, you know, you could you could send it however you want, right?

Erlend Leiknes

But for phones, I guess you actually need a phone to do iMessage.

Harrison Sand

That's true. Yeah, so there's yeah, there's some uh so like some of the messages were text messages, some of them were iMessages.

Erlend Leiknes

On some of the photos, there was actually uh a wreck of servers, so we speculate that that is used for either crypto mining or they emulate Android devices.

Harrison Sand

Yeah, potentially.

Robby Peralta

If an iMessage is ever asking you to fill in something, don't don't believe that shit. Yeah. Basically. Unless it's from me. Yeah. Do you have any like lessons learned that you want to share with people? Uh I guess besides don't click anything, don't trust anything on your phone.

Harrison Sand

Or maybe sometimes sometimes if you're careful, it may it's worthwhile to click the link.

Robby Peralta

Yeah. Just to install some software first and see where the traffic is going.

Harrison Sand

No. That's true. That's true. To look at the big picture, I think it's something that I think there's it seemed like a this is a kind of a problem in society that didn't really directly fall on one industry or one group. It was kind of like the victims were maybe the banks, but then also the phone companies are involved. And uh, you know, some victims, you know, obviously like if people don't get their money back from the bank or they have to deal with the banks, and then like it's uh and then the police, it's you basically like it's hard to pinpoint exactly whose fault it is, and then the amounts that they're stealing aren't high enough to really warrant huge investigations. So it just seems like this not victimless but almost victimless crime that you kind of get away with because it like slips through the cracks. So I think it's it's uh I don't know. It's definitely been interesting to kind of like help tie the picture together to like really see what's going on. Like, what does this world look like?

Robby Peralta

I mean, even if the bank takes, okay, let's say I put my credit card in there, I get tricked, and then they take, let's say, 5,000 kroners, which was the average of the Swedes, right? So 5,000 kroners, I still have to call somebody in the bank and wait in line and convince them that this happened. And I have to feel like not very smart, obviously, if I got tricked by that. I guess it teaches me a lesson, but or worst case, I do lose all that money. But it's not a victimless crime in the fact that I still wasted my time having to deal with this.

Harrison Sand

But actually, it's it's uh, I mean, NRK did some work on this, but basically it it uh it seems like a lot of the victims are, you know, the elderly, which is kind of what most people would maybe think of, but also uh teenagers because they've never, you know, maybe they just got their first credit card, their first bank card. They've never had to pay for toll at the post office, so they don't really know what that flow looks like. And maybe they don't notice the charge on the card, maybe uh maybe there's a delay, maybe they wait a month before the transaction, maybe they don't want to get in trouble with their parents, so they kind of like don't say anything. It's like there's a lot of uh like even if you are like on top of your credit card bill, you can get the money back potentially, but there's a lot of cases where you know people don't see it or they don't.

Robby Peralta

Yeah. Yeah. Well, gentlemen, uh thank you for the rabbit hole. The rabbit holes that you continue to go on in the name of uh justice. Yes. Thank you. Thank you for your service. And uh good luck moving forward. Yes. Thank you, thank you. Well, that's all for today, folks. Thank you for tuning in to the mnemonic security podcast. If you have any concepts or ideas that you'd like us to discuss on future episodes, please feel free to hit me up on LinkedIn or to send us a mail to podcast at mnemonic.no. Thank you for listening, and we'll see you next time.