5 ms·
BetaMonkey/TouchMe was in fact the person I was referring to who was providing support for his botnet drone builder until he dissapeared with no trace at a late
by christina_b 9y ago
BetaMonkey/TouchMe was in fact the person I was referring to who was providing support for his botnet drone builder until he dissapeared with no trace at a later date. Just could not recall the nick at the time of making my original post.
- ryanlol 9y agoI always assumed the two to be different people. The log shows the two of them talking at the same time, and I remember the two of them having very different attitudes in general. I know TouchMe is malwaretech but would be inclined to assume that BetaMonkey isn't. TouchMe was still a malware developer though, and apparently used to run voidptr before handing it over to BetaMonkey.
- christina_b 9y agoI was pretty sure TouchMe was BetaMonkey's new nick, I don't think it was Ntoskrnl (MalwareTech). From what I've heard TouchMe continued support of his drone's users until he dissapeared without a trace. This was so long ago and my memory isn't amazing.
- ryanlol 9y agoTouchMe is MalwareTech, 0 doubt https://twitter.com/touchmymalware https://twitter.com/touchmymalware If BetaMonkey==TouchMe then they were trying really hard to conceal that. Here's a hackforums thread mentioning some other malware TouchMe was distributing though https://hackforums.net/showthread.php?tid=3786935 https://hackforums.net/showthread.php?tid=3786935
- fweespeech 9y ago> TouchMe is MalwareTech, 0 doubt https://twitter.com/touchmymalware https://twitter.com/touchmymalware If I was a bad man in the security profession who was certain he was anonymous, I'd point to someone else who was a security professional on twitter when I vanished too. It just y'know, wouldn't have been me.
- blaquee 9y agoThat tweet was in 2013 however.
- fweespeech 9y agoIf you tweet and stop using an account that is what happens and that was a shady group of people in 2013.
- ryanlol 9y agopfft. I used to talk to this guy on a malware dev IRC on a daily basis, he started a blog "TouchMyMalware" which eventually evolved into Malwaretech. This is all easily verifiable with google and archive.org. And lol, apparently some twitter user dug up logs of him offering to sell me a rootkit for $20k https://twitter.com/jeremiahg/status/893207272154734592 https://twitter.com/jeremiahg/status/893207272154734592
- sugersvoltet 9y agoThat just looks like standard IRC bantz though. Do you know if he was actually trying to sell/weaponize the malware he was developing? (I assume he was, given the indictment, but can't hurt to ask.)
- ryanlol 9y agoI'd go with "no doubt" for both. Although I'd assume he'd have loved the $20k if it was actually on the table.
- stickers_ 9y agoSup ryan, remember me? i used to chill on voidptr sometimes too. I don't know why everyone is so surprised by this "he's a fucking genius because he got us all" https://twitter.com/x0rz/status/893203106338680832 https://twitter.com/x0rz/status/893203106338680832
- 9y ago
- goatsi 9y agoBetamonkey was someone different. The reason he disappeared without a trace was that he was so bad at PHP that people got sent to prison (his support site was owned by a whitehat and all the customer information was harvested and distributed to law enforcement)[0]. Touchme/Marcus was a close friend of his though, one of his first articles on the site that eventually became malwaretech.com was an attempt to disprove the claim that betamonkey's malware was banking malware. This had gotten him banned from selling on hackforums, his main source of customers at the time. You have to read the article on the way back machine, for some reason he deleted it from his site later on [1]. If I were betamonkey I would be sweating pretty hard right now, his malware is also still being used and Marcus will be looking hard for someone else to drag under the bus. [0] http://www.xylibox.com/2015/04/betabot-retrospective.html http://www.xylibox.com/2015/04/betabot-retrospective.html [1] https://web-beta.archive.org/web/20130625172146/http://touchmymalware.blogspot.com https://web-beta.archive.org/web/20130625172146/http://touch... (halfway down the page)