6 ms·
It’s notable that there were ShinyHunters members arrested by the FBI a few years ago. I was in prison with Sebastian Raoult, one of them. We talked quite a bit
by joshmn 11mo ago
It’s notable that there were ShinyHunters members arrested by the FBI a few years ago. I was in prison with Sebastian Raoult, one of them. We talked quite a bit.
The level of persistence these guys went through to phish at scale is astounding—which is how they gained most of their access. They’d otherwise look up API endpoints on GitHub and see if there were any leaked keys (he wasn’t fond of GitHub's automated scanner).
https://www.justice.gov/usao-wdwa/pr/member-notorious-international-hacking-crew-sentenced-prison https://www.justice.gov/usao-wdwa/pr/member-notorious-intern...
- ants_everywhere 11mo ago> (he wasn’t fond of GitHub's automated scanner Do you mean they thought the scanner was effective and weren't fond of it because it disrupted their business? Or do you mean they had a low opinion of the scanner because it was ineffective?
- joshmn 11mo agoHe would complain that it disrupted their business, and that it doesn't catch all keys—it catches the big ones that he certainly found to be very valuable.
- rkozik1989 11mo agoGenerally speaking, humans are more often than not the weakest link the chain when it comes to cyber security, so the fact that most of their access comes from social engineering isn't the least bit surprising. They themselves are likely to some extent the victims of social engineering as well. After all who benefits from creating exploits for online games and getting children to become script kiddies? Its easier (and probably safer) to make money off of cyber crime if your role isn't committing the crimes yourself. It isn't illegal to create premium software that could in theory be use for crime if you don't market it that way.
- deleted 11mo ago[deleted]
- Thorrez 11mo ago>It isn't illegal to create premium software that could in theory be use for crime if you don't market it that way. Who is making money off of selling premium software, that's not marketed as for cybercrime, to non-governmental attackers? Wouldn't the attackers just pirate it?
- dheatov 11mo agoFeel like IDA Pro counts.
- Thorrez 11mo agoI'm pretty sure nearly 100% of IDA Pro usage by underground hackers is pirated.
- ronsor 11mo agoThis type of software is being sold on many forums, both on the clearnet and darknet. > Wouldn't the attackers just pirate it? Sometimes the software is SaaS (yes, even crimeware is SaaS now). In other cases, it has heavy DRM. Besides that, attackers often want regular updates to avoid things like antivirus detections.
- Thorrez 11mo agoI assume the forums you're talking about are cybercrime forums. So I think that counts as "marketed for cybercrime". I'm asking if there's anything not marketed for cybercrime.
- edm0nd 11mo agoTons of companies like Portswigger (Burp Suite) or Cobalt Strike (their c2)
- 11mo ago
- red-iron-pine 11mo ago> The level of persistence these guys went through to phish at scale is astounding—which is how they gained most of their access. explain
- the_gipsy 11mo ago[flagged]
- ChrisMarshallNY 11mo agoThat’s standard practice, on HN, and has been, before AI was a broken condom on the drug store shelf. Unpleasant, but comes with the territory (I don’t like it, when it’s done to me). That said, I’m not sure that kind of scolding is particularly effective, either.
- oersted 11mo agoNot every culture has the same standards of politeness. I didn't think it was rude, I think it can be even respectful of their time and intelligence to be concise, plain and direct, as long as you are not literally attacking them. I mean, the comments under the GPT-5.1 announcement just today were full of people wishing that AI actually responded to them like this. https://news.ycombinator.com/item?id=45904551 https://news.ycombinator.com/item?id=45904551
- edm0nd 11mo agodamn that sucks they threw you in fed prison for running a sports streaming website. did you have bulletproof hosting and they caught you through other means like going after your payment providers or you made opsec mistakes or how exactly? was it a website like Sportsurge where it simply linked to streams or did it actually host the streams?