Thank you for deep diving into these data dumps and risking getting on the bad side of KZbin in order to raise awareness John. Truth be told most of these organisations most likely have very little idea to what extent they have been compromised and what types of data has been stolen from their systems.
@la_sn3ak3r192 жыл бұрын
KZbin loves MAP's...
@XiSparks2 жыл бұрын
Off-limit entities, rules, and pretending to be a professional IT service....... The mental gymnastics this group is going through to attempt to morally justify their behavior is next level.
@user-jw1ry2zq3l2 жыл бұрын
for those who don’t know Babuk is defunct afaik, one of their developers first leaked their builder, & then leaked the src to the ransomware. Fun fact: Babuk is the second fastest ransomware behind Lockbit.
@modotu2 жыл бұрын
Fun…
@xAngryDx2 жыл бұрын
As usual, amazing content John. Thank you.
@ThejKilla2 жыл бұрын
I saw you at Blackhat! I was working as one of the conference associate team leads and couldn't step away 😥
@QuickTrueStories2 жыл бұрын
Hi
@roslinked2 жыл бұрын
Interesting series. I've been enjoying these.
@_Kevin_kipz2 жыл бұрын
Love your videos, keep it up.
@faran_siddiqui-d3t2 жыл бұрын
Feds to John - Why are you visiting the Dark Web 👮? John - For educational, historic and scientific purposes Feds - Alright, have a nice day
@k4m1kazep1lot42 жыл бұрын
Visiting Dark web is not illegal tho
@zaubermaus81902 жыл бұрын
@@k4m1kazep1lot4 that's why they just ask and wish him a nice day. curious bunch the feds ^_^°
@Zaulao2 жыл бұрын
This series is so interesting, thanks for sharing this! You're a cyberhero, John
@rationalbushcraft2 жыл бұрын
The term "audit" cracks me up. We are not stealing we are auditing.
@louislove7952 жыл бұрын
just like everyone else in the comment section - great work - thanks for your time John
@Alisson-Faoli2 жыл бұрын
You should totally go in Jack Rhysider's Darknet Diaries podcast. You're my hero!
@bekkaician2 жыл бұрын
Thank you for drilling down into this for us, was very informative
@killerskincanoe2 жыл бұрын
I've really been enjoying this series. You should team up with the mob reporter for one of these haha
@themadichib0d2 жыл бұрын
I can get and to a degree respect the notion of "Hey we dont target these X targets, it crosses my personal moral barrier" (which if you dont believe, do you think every thief is willing to commit murder? Most criminals are still going to have that ceiling for how much harm theyre willing to commit and that ceiling is gunna vary from person to person). But oh boy that about us is such a weird mix of gaslighting and copium lol Its gotta be a joke that they just think its funny to couch things in that language.
@Wastelander19722 жыл бұрын
Hi John. I’m work as a cybersecurity specialist for an organization here in the U.S. Out of curiosity, where do you get your sources to find sites like these? They may come in handy for future research.
@sleepyxuras912 жыл бұрын
His previous video #8 went into this a little bit some index of sites that listed some of these organisations Onion addresses.
@r00tx62 жыл бұрын
There’s a clear net site I’ve used with tons of success called ransom wiki or something similar.
@Riborwahz2 жыл бұрын
From 36k to nearly 500k sub you're amazing man
@debarghyadasgupta19312 жыл бұрын
Loved it. Always insightful.
@xaero2122 жыл бұрын
That was great, more of those, please!
@blackhatvisions2 жыл бұрын
Great insight
@mpkbt41982 жыл бұрын
quick technical question: They say they use symmetric encryption. I am somewhat confused about that, wouldn't it make more sense for a ransomware to use asymmetric keys? If my understanding is right, with a symmetric key, the same key used for encryption could be used for decryption, this doesn't defeat the purpose of the whole attack, since theoretically the key could be extracted from the ransomware executable?
@k4m1kazep1lot42 жыл бұрын
they use the key to encrypt it and delete the key
@xaero2122 жыл бұрын
@@k4m1kazep1lot4 could you please elaborate?
@joelsschwarz2 жыл бұрын
Such a good people. Non-malicious activity and out of a good heart for sure
@velho62982 жыл бұрын
"Don't feel good about this" - while uploading this to youtube for all to see.
@MrsCyImsofly2 жыл бұрын
Thank you John 😊
@cybersploit73782 жыл бұрын
Nice content!
@MsSoldadoRaso2 жыл бұрын
John has discovered that videos about the dark web have more visits
@Antimated2 жыл бұрын
Where can I find the other 8 video's? Is there a playlist for this?
@kobiassvilli2 жыл бұрын
One interesting thing I picked up quickly was the views number. They are all suspiciously similar. I suspect they are fake. Not the most important information or takeaway from this but thought I'd point this out as another pin in the list of dodgy things you can pick up from just looking at the sites.
@CB-RADlO-UK2 жыл бұрын
KEEP GOING BRO
@mossdem2 жыл бұрын
I always sit and wonder if the people from Anonymous, Babuk or other groups might be watching these videos, chuckling to themselves in a dark room with a singular desk lamp on and their hood up 🤣
@justethical2802 жыл бұрын
Just forget the hood.
@ajaktamkorniszo27452 жыл бұрын
Hello, I know it's not on topic, but in Ur old videos (atleast those are what im watching) You always say, "well that's how it is on linux, and if U're not on linux You should wonder why You aren't." And it really made me wonder what's the difference in everyday life usage? if we dont count executable like playing games and maybe being the real owner of OS/PC, that just leaves us with different libraries for programming? I really am curious, because there's defienietly something that im missing, would much appreciate, a link to a video explaining (if one as such exists) or just a reply. Anyway Thanks a lot for the content U have made in the past and probably future, once I get to that point :- D
@Iwantapplez1092 жыл бұрын
12:35 that text right there is based
@ares1062 жыл бұрын
Just think what going to be further…. 🤔
@Simbaaya2 жыл бұрын
hey my brother , thank you first of all , and ll have fews question for you if u have times ... let me know .. im definetely better in french or spanish but lm able to talk with u in your language sorry if ll look weird . thank u again.
@techmasters40132 жыл бұрын
Best series
@joewharton77352 жыл бұрын
You could try hashing things like the date or the name of the effected company and see if you can produce the same hash and then enumerate with a wordlist of known victims of babuk / iterate the date
@guilherme50942 жыл бұрын
Thanks👍
@ThunderMarks_2 жыл бұрын
My question is, how do you find these websites?
@samuelbarber50972 жыл бұрын
5:36, got it, they threaten stochastic cyber attacks under ransom.
@custume2 жыл бұрын
good video
@f.andersen3824 Жыл бұрын
Sinister folks
@Elkasinox2 жыл бұрын
Just by reading their text I can tell that someone russian wrote it lmao
@TheHaircutFish2 жыл бұрын
The name reminds me of Babadook, spooky, haha
@falcon__43162 жыл бұрын
600,000+ views is disturbing
@isaacjohnson2 жыл бұрын
There's a lot of fake view counters on these sites.
@Susanoso2 жыл бұрын
It's always nicer when someone who is stabbing you out of nowhere tell you : "Good day, do you want to buy this bandage for me ? You are welcome" :) By the way it did say "penetration of the entity Elon Musk" right ?
@Adnankhan-dr7qn2 жыл бұрын
Greate job
@Chris-ry7kj2 жыл бұрын
Quite the predicament to end up in. Do you pay with whatever good faith you can scrounge together for this extortion ? Do you ignore it and hope it’s not real? Do you assume it’s already been leaked and it’s a loss loss ? None of these outcomes are good
@Chris-ry7kj2 жыл бұрын
@Hoxton interesting point!
@dieSpinnt2 жыл бұрын
That's true what @Hoxton says and it is effective. Make paying ransom a crime and the gangs have to seek another "business model". Trivia: For example, in Italia it is even a crime to pay ransom in real kidnappings.
@vnmlnk2 жыл бұрын
Pronounce like BabUk with hard U. Russian transcription = Бабук.
@tharikmohd23502 жыл бұрын
Is their any way to decrypt RSA SALSA20 encrypted files?
@tini_2 жыл бұрын
yes, with the key.
@datascienceandpythonprogra48722 жыл бұрын
Mr. John
@realworldhacking15312 жыл бұрын
babuk! I haven't been able to ask anyone 😂😂
@yacce4463 Жыл бұрын
Crimes have different severity associated. I do think its respectable and seen as less "evil" if they don't do it to hospitals or non-profit institutions. I understand why you smirked and frowned upon these supposedly "ethical" boundaries, but give it a second thought, its not about them thinking that its "alright to do it to big companies", its them thinking that it's worse if they do it to those who're helping society in a more direct way.
@DigitalicaEG2 жыл бұрын
Certainly non kosher
@blinking_dodo2 жыл бұрын
Am i shadow banned here? 😨
@blinking_dodo2 жыл бұрын
LOL everything that even remotely looks like an URL gets your comment *silently* removed. This is a very shitty practice that makes me want to un-heal their Board of Directors or something like that... 😠
@FaZekiller-qe3uf2 жыл бұрын
Too early
@Spitfire_Cowboy2 жыл бұрын
*Shivers* I do believe we in the community should "audit" groups like babuk and encrypt their crap. Or fry their gear. I prefer the Fry option.
@_AN2032 жыл бұрын
Sounds like ransom for me 😂😂😂
@viduraranathunga60002 жыл бұрын
2nd :D
@abhishek_k72 жыл бұрын
noice
@keccak322 жыл бұрын
3Rd
@bc1petar2 жыл бұрын
fifth :)
@javiergonzalezsilva35302 жыл бұрын
First :D
@h4gg4972 жыл бұрын
Here's a business plan. Pwn zoominfo, exfil the website access logs, see who's looking up xyz company that's just been ransomed, grab the perp's IP (these groups are shit so probably bad opsec), blackmail the perps, profit.