mnemonic security podcast
Hosted by Robby Peralta from mnemonic, one of Europe’s leading cybersecurity companies, the show features conversations with researchers, founders, operators, and security leaders working across the cybersecurity landscape.
Each episode explores a specific topic within cybersecurity: from incident response, threat intelligence, AI, and geopolitics, to leadership, resilience, and the changing role of security leaders.
The podcast is tailored to cybersecurity practitioners and decision-makers who want grounded conversations about where cybersecurity is going, what organisations should prepare for, and what experienced people are seeing.
mnemonic security podcast
Dark Web Roast
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Start your week with a laugh. And yes, it’s work-relevant.
Today’s guests, John Fokker, Head of Threat Intelligence, and Jambul Tologonov, Security Researcher at Trellix, have spent years monitoring the dark web and have quite a few stories to tell.
They are joining Robby to talk about their concept "Dark Web Roast", a satirical look at cyber criminals and their world of crime, aiming to show that at the end of the day, these threat actors are just human beings, messing up just like anyone else.
In the episode, they take us behind the scenes of the dark web: exposing failures among cybercriminals, uncovering ransomware-group drama, and revealing the vanity and rivalries fueling it all.
From our headquarters in Oslo, Norway, and on behalf of our host, Robby Peralta, welcome to the mnemonic security podcast.
Robby PeraltaHidden between layers of encryption and anonymity lies one of the most active engines of the cybercrime world. HackerForms. Analysts estimate that there are between 25 and 40 of them operating across the dark web, fueling everything from ransomware and data extortion to money laundering and the trade of hacking tools. But these aren't just marketplaces for stolen data and stealer logs. They're communities, complete with rivalries, drama, rebrands, and power shifts. And as we'll soon hear, farms vanish, reappear under new names, or collapse under their own chaos, only to be replaced by a new one. This bar never closes. And today's guests are here to roast some of the action that they've seen going on lately. Jambul Tologonov, and John Fokker. Welcome to the podcast.
Jambul TologonovThanks for having us.
John FokkerHey Robby, good to be here. Long time no see.
Robby PeraltaLast time I saw you, John, you were uh on the big stage at RSA. Ah, yeah, yeah, yeah. That was a little frightening, but uh we did it. I liked your joke. You said something about like it's your first time wearing a suit or something.
John FokkerOh, yeah. I was obviously the odd person out, like they were all CEO, C level executives. I know the guy from Cisco wasn't uh before me, and somebody from Microsoft after me, and that was just me, John. So it was about like changing the uniform to uh a blazer.
Robby PeraltaYeah, nice. And uh whose idea was it to do this dark web roast?
Jambul TologonovWell, it all started because you know, we are monitoring dark web, and sometimes you come across funny things, and usually we would share it internally. And at a certain point, I think it's you, John, who mentioned wouldn't it be awesome, you know, if we would would publicly share it with the cybersecurity community.
John FokkerYeah.
Jambul TologonovUm so we decided why not to try? And uh there was the uh June edition of Dark Web Bros.
John FokkerAwesome. This was just after the British, the NCA took down Lockbit and they kind of trolled the whole group. And we were seeing a lot of like cracks in the armor of cyber criminals, kind of like there's disputes and the trust is gone. And at the same time, if I look at the industry, we mentioned RSA, right? There are so many companies out there, or our industry mythologizes threat actors to a certain level because it it's good for business, apparently, and it's marketing and it's interesting. And we're like, but we're looking like Jumble monitors these threats every day, we're chatting about that, and we just see them mess up, and we're like, no, these are just human beings. So we should not go down the path of mythologizing, making them bigger than they are. Show the mistakes, make fun of it. Because if you start laughing about it and you see the humor of things, it takes away the fear of like customers and other people that they're not like these mythical cyber criminals. No, no, they're just trying to do things and they make mistakes just like us. And the other benefit is, and that's what we hope that we ultimately will reach, is that we'll reach that community and then they're like, oh shoot, Trellix makes fun of us. Oh, and then they'll their reputation will get damaged, and then they will not be taken so seriously, and that ultimately will have an effect on the the business climate where cyber criminals do business. Because if you if you have a bad reputation or people don't trust you or they make fun of you, why would they do business with you? Because you're not trustworthy, and that would limit their innovation as well. So that's kind of a thought process behind it.
Robby PeraltaBut just remember, they're just jokes, guys. Oh love how you guys had it at the end. Good touch.
John FokkerIt is the the Ricky Gervai s thing is like we're just gonna roast you, it's just jokes, so you gotta take it. So that's a recurring theme.
Robby PeraltaSo let's hop into it. You've done four, I believe, so far September, August, July, June. Let's just hop into uh September. So it started off with Luma Stealer's spectacular exit scam. So the Loomus Stealer operation decided in September that it was a perfect time to ghost their entire customer base, who'd invested in the malware as a service platform, watched hopelessly as their criminal business model evaporated overnight, proving once again there's no honor amongst thieves. And just a quick reminder for everyone Luma Stealer or Luma C2, uh, as it's also been called, is of course an info stealer, made primarily to steal information from Windows machines. And it tries to go after a bunch of stuff, for example, credentials, browser cookies, crypto wallet stuff. And it was offered as a sort of malware as a service, meaning their affiliates or partner bad guys would pay them a monthly fee, or they'd pay them a fee at least, uh, where they'd get access to the Luma C2 admin panel to manage their infections and see stolen data and stuff. Uh along with, of course, updates and support, just like every other enterprise software that we know. And LumasTeler, they were huge, right? Like, do we know what kind of money they were we were talking about here?
Jambul TologonovOh no, but indeed they were one of the major infastealers in the market. And they built already a strong reputation that they are reliable. There was also a uh law enforcement operation trying to take down Luma Steeler infrastructure, but somehow they've managed to survive that. So they were also then, you know, in the underground forums who would brag about it and say, okay, they tried to kill us, uh, look at us, we survived. And now we're going to go private and we're going to operate in a private mode. And then eventually, after a few weeks or months, they decided uh to exit Scam. At a certain point, the infrastructure just goes down, and they're not able to communicate anymore with that. And that's essentially uh a big loss for the affiliates of uh Luma Steeler. And they would, of course, then start complaining, raising so-called blacks on forums where then administrators would need to decide how to resolve it. And uh what we've seen is Luma at the moment is being uh banned from major Russian uh cybercrime forums. And we thought it was uh funny thing to include actually in the September edition of the dark web roast.
John FokkerYeah, uh for for us it was extra interesting because we're a security vendor as well, right? So we can see we see the conversations happening in the underground, and at the same time, we have teams that are hunting through our telemetry, and we see Luma infections. So when Endgame happened, and it was a good push by the FBI and Microsoft, and uh we provided some information as well. I've said it before, it's like if you do not either arrest people, so put silver bracelets on folks, if you just try to take down their infrastructure, they'll try to come back. It's like a badge of honor against cyber criminals to reinstate your infra to show that you're still there and that you cannot be beaten down. That's like the recurring theme that we see. And that's what we saw as well, because at the back end, we we were still seeing infections with Luma Steeler happening. And uh, I have to check the latest styles if it's now died down after the um the exit scam. It's definitely a lot less, but uh it's interesting to see. Maybe law enforcement is doing something that we don't know, but who knows?
Robby PeraltaA loss for them, a win for us, I guess. Let's move on to uh Lockbit's political campaign. Make XSS great again. So this notorious Lockbit SUP. Frequently described in reporting as the former head of Lockbit, a major ransomware as a service operation responsible for high-profile attacks all over the world, until they got shut down by the police, who exposed the group's internal chats, released their decryptors, and yeah, essentially doxxed their leader by letting the world see who he really was. So he, after all that, was banned from the XSS forum. But recently launched a full-blown political campaign to get unbanned, complete with a voting thread. Lockbit promised four members, if you vote for me, I will make XSS great again. Literally positioning himself as the Trump of the cybercrime forums. By the way, I love your uh LLM that it wrote this. The tone of voice is just on point. Uh, I wouldn't say he's thriving, but he's uh he's still living and still has computer access, apparently.
John FokkerYes, I think there's a fine line between um A) there's no silver bracelets, right? So there's he's out it, but he still has his money. And it does feel like there's an element of uh prestige or vanity or narcissism, you want to say. Because like honestly, I would like I we've been talking about this as well. If it's true that he made that much money, why don't you just shut down and do your own thing? But apparently there's something drawing him back to the community and and just like wanting to be on top and wanting to spread his voice, and maybe he can explain why. Because I don't know, any sound person would be like, if you have that much money and all the things that you have claimed in all the interviews, why don't you just live your life and find a new hobby? But yeah, it does make for good content.
Robby PeraltaSo did he get did he get granted access?
Jambul TologonovNo, I I don't think so. So what happened is he he was banned last year on XSS. And we know that after the arrest of Toha, admin of XSS, they managed to recover. So alternately now they have a new administration, new admin, new moderators. So he reached out to the new admin asking, well, why don't you unlock me, unban me from XSS, my previous account, LockBits Up. And admin decided, okay, I don't know all the details of the dispute before. Why don't we just like uh vote? Like everyone with the reputation on on the forum can vote and democratically decide whether we should unban him or not. But I think at the end of the day, there were so threat was huge. So many people actually voted uh yes or no, yes or no, but eventually they decided, I guess, against uh unbanning him. So yeah. Log beats up, remains banned on XSS.
Robby PeraltaThere's like a five-part ransomware diary series about going into that. So we could just leave that be. But I highly recommend it uh for those that have not read into that, do that because it was very, very entertaining. So this next one, Scattered Lapsus Hunters. The ultimate tryhard move. Imagine starting a rock band and calling yourselves the Rolling Queen Beatles, whilst expected to be taken seriously. So here the irony is, of course, the name, which references other household names of the dark net. These are the guys that are behind the Salesforce stuff recently, correct? Yep. Yeah, yeah.
John FokkerThey're a different animal when you compare them to like the more hardened Russian underground cyber criminals, right? There's a lot of ego, there's a lot of demonstration of skill, a lot of like, okay, look at what we did, and they're proud of themselves. The NCA recently arrested uh two individuals for some major um uh crimes they committed, and then you could see that the rest of the group, they're like, oh no, we're gonna shut down, we've proven our point, we've had enough or whatever. So it's to me, that's also a tactic of like, well, maybe it's there's a little bit of heat on you, so you wanna lay low, and then yeah, um, we'll have we'll have to see. But uh most of these attacks, as elaborate as they are, and and yes, they are exploiting a weakness that you can see, like the social element when it comes to a lot of these organizations, and then moving using that social element almost like a Kevin Mitnick style, and then mixing that with some pretty competent, like on target type of exploitation. Um, yeah, they're exposing a weakness in the industry. So that's that's that that is 100% true. It's just uh the way how it's done, it just tells you that they're in more for the bragging rights than they are for uh real business in a way. So that that that's what stands out to me.
Robby PeraltaI'm I'm just trying to imagine the ransomware negotiator looking at his playbook like scattered lap. How do how do I treat these? Who are these people? So moving on to the pandas copy paste empire. So a threat actor known as Panda has built what can only be described as a criminal inception scenario, copying other people's stolen data and redistributing it as if it was its own original content. The operation demonstrates a business model based entirely on repackaging other criminals' work, essentially running a secondhand shop for stolen information without bothering with actually stealing the data themselves. It's remarkably efficient and in a completely shameless way, recognizing that in the underground economy, most people can't tell the difference between fresh breaches and recycled data. So why bother with the risky work of actually hacking when you can just copy and paste your way to profit? My question to you, uh gentlemen, is is it illegal at this point? If you're not stealing the data, you're just copying some stuff you found on the internet.
John FokkerSo is fencing a bike illegal? So let's say you didn't steal the bike, but then you well, you have the bike and then you just like repurpose it, like and then you could argue if data is a good or it's anything else. In this case, yeah, they're they're dealing in PII, right? They're dealing in stolen data. And yes, it's combined and it's old and whatever. To me, this is something that is happening so frequently, and and even with us, with our look at our customers that that take our Intel services where we look at credential access and all these other things, and there's a new file. Companies nowadays are more they're spending a lot of times at like tracing down if the alert for stolen credentials is actually legitimate, or it was just a rehash of like the copy paste stuff, just like what Panda does, and they spend so much time on this, is this is a problem. And this is a perfect example why we list this here because yeah, what can you do? You can't really stop somebody from doing this. The thing that he has going is his reputation. So if you highlight the reputation and he's actually selling recopied stuff of old credentials, then yeah, he has no business. So that's that's kind of our way we're highlighting this individual here as well.
Jambul TologonovAlso, to add um on that, and on the ground, we are seeing lots of uh scammers as well, right? Who essentially just credit posts and say, okay, I'm selling this access, I'm selling data obtained from this organization. And at the end, uh people are just uh indeed reaching out to them without the forum escrow, and people are just scamming them. And then we see a lot of complaints being raised saying, okay, this person is you shouldn't trust him, he's just a scammer. I uh sent him the money, but I I just didn't get the service, so I didn't get the data. So that's quite common. And uh yeah, there are lots of scammers, and you have to be careful indeed. And not everyone can navigate the dark web. There's no trust pilot on the dark web, huh?
Speaker 3Yeah.
John FokkerWho would have thought that you cannot trust a criminal? Oh my gosh.
Robby PeraltaLots of honor amongst thieves, as they say. Yeah, yeah, yeah. So the Aura Corp? Aura Corp. Aura Corp. One of those two. Fin Center service introduced the concept of an insurance deposit, speaking of trusting thieves, for their crypto cleaner mixer services. So this is a service that cleans crypto, or at least kind of hides the origin of cryptocurrency by blending many users' funds together and redistributing them. It's meant to make it difficult to trace transactions on the blockchain, at least, according to my understanding. Why why'd you guys add this one?
Jambul TologonovYeah, sure. So um what's funny is here, they're trying to differentiate themselves from other uh crypto mixing services, right? And in here, they came up with a concept of insurance deposit, saying that if at the end we didn't do our job properly, didn't do the proper mixing or money laundering, then there's always a hundred percent refund guarantee. You'll always see, you know, here's your deposit, it stays there. If the final result is not delivered, you'll get it. So it just shows that there are lots of actors, thread actors offering similar services, mixing the cryptocurrency that is coming from the illicit activities to like run somewhere potentially. And they are trying to find a way to actually make a difference to the customers. And uh that's why we thought this might be an uh interesting entry to ads.
Robby PeraltaSo yeah, wow. Is this legit or is it just another scam disguised as uh as an innovation?
John FokkerOh, totally. Uh and we haven't tested it, let's be honest, so we'll have to see. But it's an interesting concept, right? Because you're putting a lot of trust in somebody to launder all your illicit gains. So if there's a way that you could, and that's that's basically, hey Robbie, I trust you because I know your reputation and everybody else is writing, and you have a good brand, but ultimately you don't want to have that situation, you want to have transparency because like you don't want to know as much from me, you want to be able to do your business, I want to be able to do my business, and this is just um uh an interesting innovation in a way that it adds to the transparency to be like, okay, yeah, I don't need to know you, but I do not necessarily trust you because of your reputation, but I trust the process that you're offering because of the addition that you do. So it could be a new new yeah innovation or a new step for to get more people to use their service.
Robby PeraltaYeah. In blockchain, we trust. It actually got me thinking, is there ever been like a like a brand or a on the dark web that actually didn't like end up exit scamming or getting taken down? Is there one that's been there from the beginning? What's like the oldest threat or like forum or you know, sort of service that survived? Ooh, wow.
John FokkerUh yeah, everybody like they they kind of remodel now and then, right? They always like I think some of the bulletproof hosts probably they have been some of them have been around quite a bit and they're they're used to having their name, and that's just more of a hosting business. So you'll see that. And they're harder to take down as well. So you'll always see them off being offered. I think some of the VPN providers have been around for a very long time, up until there was a law enforcement intervention. And it's it's a two-way thing, right? It's it could either be the chains or the exit scam or whatever intervention could be from internally, either there's an exit scam, or you're just trying to create a new business or whatever, or externally, there could be pressure externally from law enforcement forcing you to change and creating that that difference. That we're dealing with a lot of similar people and that they rebranded. That's one thing that's 100% for sure. There's a lot of uh familiar folks. Yeah, and whenever there's a new leak out and you can see new chats and a new uh because very often in like the jabber chats, they'll reference something else, or or there's a new service, and they mention a moniker that they had before, and then it's like, ah, okay, yeah, you that new moniker, you are you, and you are you, okay, and we can tie everything together, and it's like, okay, all the pieces on the chaff board have moved, but we now know who the players are once more again.
Robby PeraltaYeah, so brand brand name dies. People don't we have cyber hasn't been long enough for the people to die, I guess, yet.
John FokkerYeah, that that's a good point. There was a time with ransomware where they rebranded constantly, and then in the new brand name, there was some kind of recognition to the previous brand name, and then but they said always said they were different, and then you we had to do code comparison, and then it was like, oh yeah, no, they are the same because their code overlaps, and then yeah, it it it's an interesting dynamic.
Robby PeraltaIt's fun for you guys to look at and and follow and take it apart and see who's who, I'm sure. Uh moving on here. NYU professors accidentally create better ransomware than actual cyber criminals. So, New York University researchers developed something called Prompt Lock, the first AI-powered ransomware that uses large language models to autonomously conduct attacks and underground forums on ramp and exploit erupted in confused fascination. The academic proof of concept costs around 70 cents per run using GPT-5 and generates unique code each time, making antivirus detection difficult. So when university professors are building better ransomware than actual cyber criminals for around 70 cents per tax scenario, the underground economy has a serious innovation problem. Is this a good thing or a bad thing? I'm sort of confused.
John FokkerYeah, yeah, I have my opinion. There's a plenty of if we look at the things that we're detecting, there's plenty of tools. That started off as a research project or as uh a proof of concept and that has been adopted and built by somebody that was a legitimate researcher and then quickly was adopted by others. Uh probably the cyber criminals are not the best at innovation, but they're really good at adaptation and using things that are out there for their criminal gains. So and yeah, we expect this to happen, right? This is everybody's focusing on AI, everybody's trying to play around with Chet GPT and LLMs. Some build elaborate dark wet roasts, some build AI powered ransomware. So but it does show that criminals are looking at it and they're interested. For us, it would be also interesting to see it's like, okay, how if they can't innovate it themselves, because they are relying on somebody else, okay, how quickly can they actually adapt to it? How quickly do we see this in the wild that they're actually leveraging this?
Jambul TologonovYeah, but it was interesting at the beginning when AI generated ransomware prompt lock came out, people started like hunting for it. And they thought that probably it was created by malicious threat actors. There were, I think, a few blogs related to prompt lock. Yeah. But then later, professors from the new New York University confirmed that actually it was their proof of concept. They were trying to just check the new model, GPT-5, and see whether it can assist in generating the ransomware. And now we're more and more seeing malware where AI prompts are being embedded into the malware itself, or you know, sophisticated ransomware which are poorly generated by AI. So that is the trend, and it will only increase. And I think in DartPed, we'll see only more and more of those sort of uh malicious tools being developed.
John Fokker100%. I agree. I just wanted this is just a funny example, and it fits within the topic of the dark web. So we're monitoring our email uh telemetry, and one of the team members, he's like, Hey John, you have to take a look at this. So we all know like if if people use this an email client that is there's a lot of AI in the LLMs. So like if you use uh the Google Suite, it could actually do certain things for you. It reads the email and then it gives you uh a desired response or whatever. The threat actor was injecting a prompt into the email in a way, or they were trying to craft an email with an LLM, but part of that prompt ended up in the body that went sent out to the victim. So it was literally like, okay, we're having this offer, you can't have reviews or whatever, blah, blah, blah. Insert here a whole elaborate blah blah blah about a scam or something that is enticing to this customer, whatever. And I was just like within quotes, the actual prompt. Apparently, there's also cyber criminals that are AI slobs that just uh put it in and regurgitate it.
Robby PeraltaLuckily, if you see those sort of attacks, they're they're pretty loud, right?
John FokkerIt goes both ways, right? Because if you look at emails, in the beginning, everybody's like, oh yeah, but that's an AI written email. That's AI written content, so it stands out. So we want to detect the AI written. But when the adaptation of the masses will occur, then everybody will leverage those tools. So the emails that are written without AI would become less and less. It's tricky, right? How can you spot the emails that are AI written that have a malicious intent? Um, very often, if it's the classics, then that then there's still a malicious attachment. It's always either it's it's forcing you to download something, to click on there's an action involved. So those are things that we still see. Uh, or they divert to a different medium. Things that we're also seeing is like the the DPRK IT worker stuff, uh, where they do use LLMs to generate like very convincing job interview type of questions and content as well. But these are just uh yeah, those are just North Korean operatives behind the computer trying to get a job and then steal off all the salary pay, aside from that, back to uh to uh North Korea as well as uh all your intellectual property.
Robby PeraltaMoving to August here, anti-chat, their Oscar-worthy performance. Tell us about their um what do they call it, their fake access game.
Jambul TologonovYeah, I think it was around when administrator of XSS was arrested, and people saw that XSS now is actually a honeypot, so you shouldn't register. And they've actually built a uh alternative forum called Damage Leap. And lots of moderators moved to that forum because they couldn't validate whether the new administrator is actually the successor of Doha. And around the same time, Antichat decided, okay, why don't we just also pretend as if we've been also seized? So essentially they committed uh, well, it was more or less an exit scam when they and they decided to, and it's not a novel thing. I think uh Black Cat all did exactly the same thing. Whenever there were like some law enforcement intervention going on, they would copy the page uh as if the infrastructure is being under the control of the law enforcement now, and modify it uh and then pretend as if they've been also hit by FBI or NCA. So uh anti-chat, uh uh it's one of the oldest uh Russian-speaking forums, also attempted to do so. But uh lots of uh researchers and other actors that are suspecting that uh something is not right here because uh you know law enforcement is not reporting that uh so potentially it's an exit scamp.
Robby PeraltaAnd they never changed their hosting servers, right? That was the thing.
John FokkerYeah, yeah, that that's a clear sign. Usually, if you do take down, it's like our things get diverted to a different site that is on the control of law enforcement, right? For this one, I did reach out to some folks and I was like, yeah, what's going on about this? And they're like, Well, we're not doing anything, so I don't know, but it's interesting. So I don't know what the we'll have to probably ask the guys behind NTJet the reason why, and that's if and talking about the reason why or just having more contact, that's a thing that we've been playing with as well. Ultimately, we want the dark web roast to reach a certain audience, and that's the audience, as in everybody in the cybersecurity industry, because everybody can use a laugh because we're members work to the bone, there's always a new threat and there's a new thing. So, like, okay, let's have some fun. But it would also be good if some of the threat actors start reading this and they're like cracking up. I hope they have a sense of humor. Um, and then maybe even reach out. So if we have like a dedicated jabber account or some way to reach out and say, like, oh, well, actually, this is what's happening right now. Um, this would be interesting for this month's edition. So it's like that would be golden because that it would be for me and for jumbo and myself a sign that we've reached the right audience and they're actually participating in yeah, suggesting people to be roasted. So that's that's our goal eventually. But for now, I think it's it serves this purpose quite well, as in well, you Robbie, as well. It it creates a laugh. It's like there's so much fun stuff happening, and uh I never thought that our AI could assist us with writing it, and it's that salty and that funny. The rose is pretty good.
Robby PeraltaCan I ask which AI did you use? Did you use uh XAI for that one? Just the tone, or what it's not Chat GPT's tone. I know all these had different tones.
John FokkerThis is literally our own. This is our own internal own prompt, yeah.
Robby PeraltaYeah, okay, it's your own prompt.
John FokkerSo we we have no, we have internally we have all our data sources, including our underground sources, our ransomware leaks, all our telemetry, our EDR, anything that we do is unlocked, and we have like an agentic AI on it, so we can we can ask it questions, and it basically works as a researcher. And I think um we were playing around with this, and then when we said, Okay, yeah, let's do a roast, jumbo just took it and it and it kind of prompted the machine into become this like I don't know if Jumbo has like a dog humorous side to him because he's always like very modest, but it came out in the AI, it prompted, it over-delivered. Sometimes we were like, Okay, let's let's temper this a little bit, but no, it's it's it's funny, and I'm possibly really positively surprised of how it delivers.
Robby PeraltaWell, now I'm gonna start reading it with your voice, uh Jamble, knowing that it was you. Well, I hope you guys yeah, I hope you get that Jabbery channel set up so you guys have uh unlimited content here in the future. Let me keep going here. Yeah. Uh the racist social and engineering recruiter. Uh some criminal mastermind on a telegram channel is recruiting Gmail callers with the requirement that callers must be whites or sound whites. And they were offering $100 to $250 per successful scam. Which is interesting because that means that they were willing to pay $100 to $250 for a Gmail account, if I understood correctly. Is that what their aim was, do you think? Um, yeah.
Jambul TologonovIt might be, for instance, uh specific uh Gmail account in interest. That's why they would pay 100 to 250 uh per successful scam. But uh what we saw interesting was and uh fits into the dark webs theme is uh yeah, that they're posting race uh racist. Yeah, exactly. And um and we found also very nice uh related meme to it. It's also uh not easy sometimes to find nice uh related memes. So it was like, okay, well, we're going to include this.
Robby PeraltaYeah, nice. Let's see here. So the professional money launderers master class. Uh this one must have been a troll because uh user from the Dread Forum laid out their foolproof money laundering plan, which was to receive Bitcoin to Electrum wallet, send to Mixer, swap for Monero, so far so good, and then to a KYC exchange and finally into a bank account. Explain that one for me.
John FokkerWell, I find it fascinating that somebody is posting their whole scheme online and say, like, hey, uh, yeah, um, is it can we validate this? It's like you don't talk about this stuff. That's a secret sauce. Yeah. Like, yeah, there's multiple ways of doing things, but it's like you don't post that publicly. That you can do that in a one-on-one or whatever with somebody that you trust, but it it it just shows that like either you're completely ignorant or you're yeah, you you're trolling folks. It's like you're you're just making or you're trying to provoke some kind of response that somebody or a discussion that everybody's going to talk about their money laundering tradecraft all of a sudden. But yeah, this was just it stood out. Wasn't it jumble with um Conti, where they had like they just like had corrupted exchanges and they just paid them extra money and then they just exchanged large amounts of Monero and Bitcoin somewhere in Russia. No way. People are just walking out with like shopping bags full of cash.
Jambul TologonovBut I mean, uh not every exchange is doing proper KYC, right? There's a lot of exchanges where they potentially might be working with scammers like this, money launderers, and um, they get potentially their share from these money launderers. And when it comes to KYC, they just stick the boxes, but essentially they they don't do a proper KYC. And they allow uh mixing and exchange to happen.
Robby PeraltaThey have a reverse incentive, right? They have no financial incentive to actually do that. First, it costs them money and they earn less money, so it's like exactly a recipe for failure. Um, so your July edition started with some uh drama with uh Kulin? Kulin, ransomware gang. Tell us about that one, John.
John FokkerWell, uh for me it's uh it's fascinating. This is one of the emerging larger groups now. They're really prominent, they'd make a lot of victims. I think there's uh they're responsible for uh a large Japanese brewery to be encrypted by them. And oh yeah, yeah, yeah. Yeah, if you like Japanese beer. I love that beer, damn it. Yeah, shoot. Ah but they still fight out their disputes with like probably irrelevant, yeah. In the granar scheme of things, affiliates that don't really make it it wouldn't really matter, but they do fight that out on a public forum, and it just makes them look less serious, less professional. It's like, okay, why do you what why are you including everyone on this like this this your your your dispute and why are you posting all these these text messages and everything else? It's like, yeah, why why that just you just look like in the meme, like a little kid, like just not getting their way and getting that and getting a tantrum.
Jambul TologonovLook at John. John is already arresting them here.
Robby PeraltaJohn has feelings, but just so the story is said so the Q-in is ransomware gang. They have affiliates that sort of do tasks for them, use the ransomware. And they had a dispute with one of these affiliates. Uh, and the Q-in decides to go out in a public forum and start, you know, publicly outing their affiliate, which makes them seem like a very unprofessional organization. A very bad public, uh, they don't have a PR department, apparently. Maybe that's what they need. It's one of the functions they don't have, apparently.
John FokkerYeah, you can see legal departments nowadays, and there's insurance, but a good HR department and that actually solves these things. Yeah, that's still missing. We don't want to give them too many ideas, Robby. Go on.
Robby PeraltaNo, sorry, sorry, sorry. I I can uh cut that part out. So let me, I got a good one here. So the educational purposes only stealer. So a user on Demon Forums proudly shared echelon stealer v5 with its creator Mad Code, claiming it's for educational purposes only, despite it being a full featured credential harvester that targets over 20 applications. This is reminds me of like open source technology or that's can be used for bad ways, right? This guy has made a stealer. He's saying it's for education purposes only. I can see like a pen tester working for a company doing the same thing, and then it's legal because you know it's been made for a purpose to protect networks. Yeah. Why isn't this not the same case? If you catch my vibe.
John FokkerWell, first of all, where is it advertised?
Robby PeraltaYeah. Not in LinkedIn. So if it's on LinkedIn, it's okay.
John FokkerNo.
Jambul TologonovNo, but it's what's funny is that I'm usually seeing on dark dark web forums, they explain everything, how the malware works, all the inner workings of it. And at the end, after the uh big post or an article, they would put uh for educational purposes only. That that is an irony of it, you know. I don't know why they need the display this exactly disclaimer there, uh, with their uh sharing entire script and uh a code and everything in a package, and then they would that uh include that uh specific disclaimer at the bottom, which I find that uh there's your legal department, John. Yeah, yeah, yeah.
John FokkerThe fine print, what you see with all the pharmaceutical advertisements and then all the little things. So it's this is their get out of jail free car. We're not like, yeah, no, no, no, I just created it for educational purposes. But it's the same because you could also see these things being posted on like GitHub or whatever. So this is just an ongoing, you can call it cat and mouse game. There's different opinions about it. This is more Steeler, so it's more deliberate in the maliciousness and where it's being offered, and then the reputation of the fact and all that stuff. And it's just like, okay, that little label doesn't make it good in a way. But yeah, we can think about minicots or other tools that are out there that are being used and that were developed for a certain purpose. And yeah, there's a push-pull movement, right? It if you show that it's possible, then you're forcing the security industry to come up with a solution. So that's that's basically how it works. But yeah, there's ways of doing other things, and there's ways of like, okay, yeah, you're just trying to get your get out of jail free card. It's not uh that that label's not gonna hold up.
Robby PeraltaBut hey, they got they got some uh so they got some p free PR from the dark uh the dark way roast.
John FokkerSo yeah, we're happy the outum.
Robby PeraltaYeah. All right, last one for you, gentlemen. The Vietnamese data buffet extravaganza. I really hope they don't offer that in Norway or the UK now, because uh this one was a user which transformed identity theft into a subscription service advertising everything from SPA cosmetic surgery customer data to 2023-2024 car owner data and VIP customer data by region. Tamble's LLM commented that they're running a criminal Costco membership program. Uh-oh. Is this considered like a data broker then at this point? This is exactly what data brokers do, right? And that's legal. What do you guys think about that one?
John FokkerBut what kind of data are they selling? And how did they obtain the data?
Jambul TologonovAlso, where they're selling it, yeah. You know?
Robby PeraltaYeah, where they're selling it. It's like you guys came back to that one earlier. That's the where are they advertising the services, which is kind of like the the intent part.
John FokkerHow did they obtain the data? Was there a consent by whoever was the owner of the data? Hypothetically speaking, they can they can have a let's say a Zoom info or some kind of like business intelligence tool type of uh thing, subscription and and and just like take all that data. But looking at this, it's more like okay, I stole a bunch of data and I can get all this type of different information. Let's just tie this all together and offer a service around it. And that's uh and we see that quite often. And it and and this is what and and it's you're right for questioning it because it's it is trying to make things that are illegal of origin kind of more of a legal front. And we've seen this in the past with Instagram ads where criminals would would break into accounts, steal accounts, use those accounts, high value accounts with a lot of followers to post their content. And then on the other side, so they actually broke in and they stole, and then the other side, they were almost running a legitimate business saying, like, hey, yeah, we have um access to all these accounts, Instagram accounts, we can uh do advertising for you, it's gonna cost you X, Y, or Z. And then normal companies were paying for this, and they were actually advertising that on relatively normal platforms. But yeah, where is this advertised? What's the origin of the data? The person advertising it, all the circumstances around it is just it's it's fishy.
Robby PeraltaBut this is not just in Vietnam. There are third actors that can are selling this for every country in the world. Have you seen that? Can you verify that?
Jambul TologonovOh, yeah, sure, of course. It's not only for Vietnam, it's uh yeah, damn it.
Robby PeraltaAll right. Well, I'm gonna keep going with these uh data remover services of mine, even though they are really expensive and I'm not sure what they do. But anyway, gentlemen, thank you for the dark web roast. Uh, we all appreciate it. Do you have any closing thoughts? Any fun projects? Are you gonna continue with this roast of yours? You're gonna keep paying for those tokens. Please do.
John FokkerOur goal is to continue with this. It's our way of showing the human side and the human failure side of cybercrime. Way too often we see the industry focusing on the innovation and the bad and all that stuff. But for us, uh, that threat actors are untouchable and that they're like the elusive mythology, or you want to like make it into 20-foot figurines or whatever, there's elaborate names. For us, it's more like, okay, hey, if you can expose them in a way that they make mistakes, laugh at them, and at the same time expose how they're doing, you break the credibility, you put a human face on it, and that helps customers or organizations better fight against the threat. So it's like the scary movie, the suspense builds up, but as soon as you see, like, okay, I can see the strengths, the person is not really flying, and then you can see the humor of the of the of the situation, you're no longer scared, and you're you're trying to think logically, and now you're thinking about okay, how can I better protect? How can I better arm myself against these folks because just humans? You put a face on the threat, and then it kind of takes the sting out of it. So that's that's for us is a major thing. And like I said, yeah, we're contemplating setting up maybe a Jabber channel or a Jabber account somewhere where people can reach out to us, and otherwise they can reach out through our Twitter handle right now. But yeah, um, let's see if we can reach down to the people that were actually roasting, and they need to understand, these are just roasts. Come on, it's like if you put yourself out there and you put these things, you you're fair game, in my opinion. That's uh that's how it works with a roast. And if you and if if any threat actor is unfamiliar with a roast, well, they can either watch uh Ricky Gervais doing the Grammys, or they can watch all the roasts on Comedy Central, and then they get a good understanding of what the fun is around it. And it's yeah, it's a different tone of voice, a different tone in the industry. And I think we should uh we should be very serious about what we do, but sometimes we can also have a little room for a laugh.
Robby PeraltaI mean, you can't get mad at an LLM at the end of the day. Exactly. Right. Sabir disclaimer. Uh yeah, but just back to what you said, Mikko Hypponen one year, he compared like ransomware groups and I would just say everything on the dark web forums, they're kind of like biker gangs, right? They're like scary, they have this brand name, it's supposed to scare people. And if you take that scariness away from them, then you kind of take that power away from them, right? So and I definitely see that the law enforcement has changed their strategy, which it seems to be working, which is making it changing things up a little bit. So we have uh we we need to have a whole nother episode to see like where the this industry is headed, because now I have a bunch more questions that I did that I came into it. But I guess we'll save that for another time. Thank you so much, gentlemen, for your time. And uh I will definitely be asking you to come back on again in a few months once you've had uh once your LLM has had time to generate some new content.
John FokkerGreat, awesome. Well, thanks for having us, uh Robby.
Jambul TologonovGreat, sounds good.
Robby PeraltaTake care in the meantime, gentlemen. Ciao. Ciao. Thank you. Bye. Well, that's all for today, folks. Thank you for tuning in to the mnemonic security podcast. If you have any concepts or ideas that you'd like us to discuss on future episodes, please feel free to hit me up on LinkedIn or to send us a mail to podcast at mnemonic.no. Thank you for listening. We'll see you next time.