In short
The 404 Media Podcast: Episode Summary
Episode Title
Telegram is Working With the Cops Episode Description In this episode, the hosts discuss two primary topics: a significant policy shift by Telegram in which it will now comply with valid legal requests for user data, and the ongoing legal challenges faced by a notorious hacker referred to as "Judish." The episode also touches on Nintendo's lawsuit against Palworld, with additional insights available to subscribers.
---
Key Topics
- Telegram's Policy Change
- New Stance on Law Enforcement Requests
- Telegram announced it will process legitimate legal requests for user data from authorities, including IP addresses and phone numbers of users suspected of criminal activity.
- Previously, Telegram had a reputation for not complying with such requests, often citing user privacy.
- Context of the Policy Change
- The change follows the arrest of Telegram’s CEO, Pavel Durov, by French authorities, which raised concerns about the platform's previous lack of cooperation with law enforcement.
- Durov's arrest was linked to Telegram's refusal to provide data in an investigation involving a sexual predator.
- Impact on User Base
- Discussed the implications for Telegram’s user base, particularly those involved in illicit activities. Some users might migrate to other platforms like Signal or Tox due to fears of increased surveillance.
- Comparisons with Other Platforms
- The hosts compared Telegram to Discord, noting Telegram's lack of moderation compared to Discord’s responsiveness to illegal activities and content.
- The Snowflake Hacker (Judish)
- Overview of Recent Breaches
- The episode highlights significant data breaches this year, including incidents involving AT&T and Ticketmaster, all linked to the hacker using Snowflake, a cloud data warehousing service.
- How Judish Operates
- Judish exploits stolen credentials facilitated by “InfoStealer” malware, which is distributed through pirated software and captures user login information.
- The hacker is noted for extortion, demanding payment from companies to delete stolen data.
- Current Status of Judish
- Investigators, including Mandiant, are actively tracking Judish, who has made critical mistakes that may lead to his capture.
- Mandiant has been analyzing Judish's activity through public and private channels on Telegram, correlating it with data breaches.
- Possible Consequences
- The episode discusses the ongoing cooperation between cybersecurity firms and law enforcement to close in on Judish, raising questions about future actions and potential capture.
- Nintendo vs. Palworld Lawsuit
- Brief Overview
- In the subscriber-only section, the hosts discuss Nintendo’s lawsuit against Palworld, sharing insights on why Nintendo is likely to win.
- The implications of this legal battle within the gaming industry were explored, though details were reserved for subscribers.
---
Key Takeaways
- Telegram's Shift: Acknowledges the balancing act between user privacy and legal obligations to law enforcement, potentially reshaping user trust.
- Judish's Tactics: Exposes vulnerabilities in cloud storage systems and highlights the dangers of inadequate cybersecurity measures among companies.
- Ongoing Investigations: The dynamic between hackers and cybersecurity firms illustrates the evolving landscape of digital crime and the constant cat-and-mouse game.
Conclusion The episode serves as an insightful exploration of pressing issues in digital privacy, law enforcement, and cybersecurity, emphasizing the multifaceted nature of technology's role in society and the challenges faced by both users and platforms.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:03Hello, and welcome to the 404 Media Podcast, where we bring you unparalleled access to hidden worlds, both online and IRL. 404 Media is a journalist founded company and needs your support. To subscribe, go to 404media.co. As well as bonus content every single week, subscribers also get access to additional episodes where we respond to their best comments. Gain access to that content at 404media.co. I am your host, Joseph. And with me are 404 Media co-founders, Sam Cole. Hey, what's up? And Emmanuel Mayberg. Hello. So when do you think we'll ever record a podcast where it's all the 404 media? I can't remember the last time we did that.
0:48It's been like weeks, right? Early August, probably. Oh my God, that's crazy. We're not trying to avoid each other. It's just that I thought this was going to be a little bit quieter around a one-year anniversary, and we are still going to record our subscribers only one-year podcast. But now Jason's very busy with travel. as well. So soon, soon, you know, we'll see how it goes. But to get to the stories for this week, a ton to talk about, especially of this one, a massive policy change at the, well, I think we call it a social network rather than a secure messaging app now. The headline is Telegram changes policy says it will provide user data to authorities.
1:37I think many listeners will know that Telegram has a reputation for not providing data to the authorities. That is now apparently changing, allegedly changing, I guess we'll see, but this is what their policy now reads. Quote, if Telegram receives a valid order from the relevant judicial authorities that confirms you're a suspect in a case involving criminal activities that violate the Telegram terms of service, we will perform a legal analysis of the request and may disclose your IP address and phone number to the relevant authorities. Before, it just said, if you're a terrorist suspect, we might do this.
2:23Also, this has never happened before. Obviously, this shift in language and shift in policy comes after the French authorities arrested Telegram CEO, Pavel Deroff, and we'll get into that context a bit more as well. I just wanted to ask both of you first, starting with Emmanuel, how would you describe Telegram as it relates to sections of its user base and crime, and maybe some of the stories you cover, or even just ones you've seen? Like, what is Telegram to you when it comes to some of its shadier user base? So in my world of non-consensual content and the people who make it and sell it and share it, Telegram is just a place where you can do that with very little repercussions.
3:18And also there's some easy ways to monetize on Telegram. And also a lot of the Nudify apps that we talk about, they have a web presence. But the way they work is that you enter a Telegram channel and there's a bot there that actually does all the work. and is how those images are delivered. In your world, and this description, I think, overlaps with some of what I cover. I mean, the way I would describe Telegram, it's like Discord, but more evil. Discord, for all its flaws, has really responded to stories in the press and researchers saying what is happening there, and shutting that stuff down fairly quickly.
4:10They're also very responsive to our requests. And Telegram offers a lot of the same features, and also is discoverable in the same way. People share links that let you join different groups. But basically, up until this point, offer as close to zero moderation as you can find on the internet without going to the dark web or something. Yeah, totally. Sam, have you had similar experiences when looking into stories that sort of intersect with Telegram? Like, what have you seen on the platform as it comes up? Yeah. I mean, pretty similar. It's like, I think the only time I've really interacted with the app is when we're like doing a deepfakes story.
4:56So, that's like Emmanuel said, it's like that's where a lot of this stuff goes down. um i find it like hard to use hard to get into in the same way that like discord might be for people who aren't used to using discord like there's like a curve a learning curve to me personally so like i don't know maybe that's why more people aren't on it for like normie purposes like they might be on whatsapp or uh even like signal it's like i don't know and it's like you described it as more of a social network in one of your recent stories which i thought was interesting um to me it's like oh this is a chat app but you're right that it is it's like it's more like a board or a social network than it is anything else which is i thought that was an interesting framing of it but not obvious to me but um it's obviously right yeah well i think i got that from a manual to be honest if i'm remembering correctly or somebody sort of recontextualized it as that.
5:58And it has come from how I see the app is used. So I'm in these very large, well, there's two things. I'm in these channels, which are owned by, you know, one or a few administrators, and they're followed by hundreds or thousands of people. And here, hackers will publish details about their latest breach, or they'll try to intimidate their rivals, or they'll shit talk each other, that sort of thing. So there's sort of that broadcast capability, which is pretty unique. You don't really have that on other social networks. But then there's also these massive group chats, again, often with thousands of members.
6:44And here, criminals are selling their services. They're getting into beefs with one another. They're coordinating their commissioning acts of real violence. And, you know, some of the most significant data breaches that we've seen probably over the last 12, 14, 18 months have had some sort of telegram nexus. And I do think the social network stuff applies definitely more here than it does for Discord because, I mean, I kind of hate the Discord UI. I don't really know how to navigate it, to be perfectly honest. But I have Telegram open right now. I'm going to just type in KYC, which is know your customer.
7:26I'm going to type in KYC bypass. And now I've just got a bunch of channels which tell you how to do KYC bypass. Like, is that easy to find something which is criminal in nature? And funnily enough, I just went to one of these channels and it looks like they wiped all of their messages, which I think we'll probably get to in a minute. So it's not like Signal in which is that's very much geared for one-on-one communication or it does group chats as well right and some people are moving over there but it isn't like a bulletin board sort of as you suggest Sam and like Telegram is much much more like that absolutely.
8:05So why is this the policy change? I mean I think it's very fair to say that it's due to the arrest of Dorov, who is Telegram's CEO, just very briefly to run through the timeline of that. In August, late August, he lands in France at an airport from his jet. He is very swiftly arrested by the authorities and, you know, they initially detain him and then they eventually do charge him with various crimes, but one of them centers around Telegram's refusal to engage with the authorities in response to lawful and valid requests for user data. Now, we haven't really actually seen those requests themselves, but Politico reported one example, which is that French authorities were investigating an alleged sexual predator on Telegram.
9:00They engaged in an undercover conversation. This predator allegedly admitted to raping a young girl. The French authorities then go to Telegram and say, we would like information on this user, and Telegram refused. So the French authorities pivoted to investigating Telegram, you know, the people behind it and the service in its own right. Very similar, which will bore everybody because I don't shut up about it, but it's very, very similar to the encrypted phone companies which sell encrypted devices to organized criminals and drug traffickers in that they have now been treated as criminal entities in their own right.
9:38And that's sort of the context in which you see Telegram, especially because the French authorities have been instrumental to the hack of one of those companies called EncroChat. And even, we're not even going to talk about this story, but we also covered this week. Authorities hacked another encrypted phone provider and platform called Ghost. The French authorities were instrumental in that as well. So, I mean, what do we think about this policy change? I mean, I've been talking to some people with an interest in the outcome of this, and sort of my takeaway was that, well, Dharav and Telegram are trying to spin up a sort of division to respond to law enforcement requests for hundreds of millions of users.
10:27It's an absolutely enormous app, and you're spinning it up yesterday? Now? It just seems insurmountable. Because presumably, they didn't have a division before because they weren't responding to any data requests, you know? I mean, Emmanuel, what do you think of this? Do you think people are going to be worried in your channels? Do you think they should be worried? or is it kind of different for you because you're sort of on the deep fake side which isn't necessarily criminal and I'm on like the clear criminal side if you see what I mean so generally I think that last time we talked about this and Jason wrote a piece reacting to the arrest we all sort of shared how leading up to that point we have often talked about how wild telegram is and have wondered out loud and talked about writing about how is it possible how is it possible that this widely used app that has many uh legitimate uses is so wildly harmful and openly harmful and the company refuses to do anything about that so in a very simple way I feel like this is, it just so happens that it's France in this case, for this particular reason, arrested him and kind of brought him into reality, as opposed to him being a secluded billionaire in Dubai, I believe it is.
11:55And it's like, yeah, if you want to be traveling around the world where there is law enforcement that cares about this stuff, then it's like you're going to have to do something about your wildly harmful app. And I think that's fair. I'm curious if you think there is like some dangers to this decision, but I see it as just like getting in line where with all the other major players in this space. In terms of what I'm seeing in the communities that I follow, the legality of it depends on where you are. And that is one thing that people are talking about, right? So people are reacting to the news.
12:35Everyone's sharing the news and joking about it. And some of what I'm seeing is, well, in my country, these deepfake, non-consensual images are not illegal, so I'm fine. fine. Surely there are people who are doing this in California or New York where there are laws on the books or laws in the works against this stuff. Does that mean that people will go after them? That depends on how badly someone wants to chase this down and file one of these requests with Telegram. Is it going to stop all the non-consensual activity that is happening on telegram i'm not seeing that yet um but it's possible that people will start moving somewhere else yeah i mean we're definitely already seeing some people moving elsewhere um after the arrest we did just a short piece where we went through some channels and you know there was um i think actually a kyc fraudster said they were moving um i spoke to a hacker who we're actually going to speak about in the second half of the show.
13:39And they said, um, that they were moving contacts over to Signal. And, you know, I've seen, uh, even more of that since the announcement of this, um, policy change. Um, one message said, fuck Pavel, obvious reference to the CEO. Uh, there are some, which I would say are a lot more rude than that. Um, even more, even more than that. One channel that distributes hacked data from an underground sort of fraud and hacking forum, they already say they're moving over to Tox, which is like a, I think it's a Tor-based instant messaging client, very different to Telegram, not going to have the same amount of reach.
14:23And that is like the key thing with Telegram. It's about reach. It's not even about secure communication because you can go do that in a million different ways. And especially as we've said with Signal, it's being able to reach people on a very large scale very, very easily, and regroup very, very quickly as well. And I've seen recently some of the sort of hacking channels I follow, they've been shut down for whatever reason. Like, I'm not entirely sure why they've been shut down exactly. Sometimes it happens, sometimes it doesn't. And they've made a replacement channel, and like, it's way smaller.
14:53And there's just like less chatter in there. and I think it shows that disruption can annoy some of these criminal actors on Telegram. You brought up like, you know, are there any real concerns here? And I think there definitely could be later. And I think there are legitimate questions around how Telegram is going to handle quote-unquote valid requests from different law enforcement agencies and different countries. obviously obviously a law enforcement request from u.s authorities european authorities british authorities can be bad there are like bad american warrants for sure when they're asking for like all of the viewers of a single youtube video or something like crazy overbroad stuff that should not be allowed the google reverse location data warrants where they say we want to know every single android device was it was in this location at a particular time like really crazy stuff that being said a lot of them are also pretty narrow and i would generally take a uk a us a european warrant uh targeting a specific um crime than i don't know iran going to telegram and saying we want all of the details on people who are protesting which you know may technically be a crime under Iran's laws or wherever.
16:22But you would hope that Telegram would have sort of the mature systems in place to recognize, like, we should not hand that data over. And I'm sorry, but I'm not going to give Telegram the benefit of the doubt when they haven't even, like, done this for years and years and years. And now they have to spin it up quickly. Like, they're going to get completely flooded with requests, I'm absolutely sure. So, like, now the devil is in the details about whether they're actually going to do this effectively, proportionately, and, you know, keep all of the normal questions in mind that, you know, like a Discord would.
17:00Like, I mean, maybe I'm wrong. I haven't seen a warrant like this, but you would hope that if the FBI went to Discord and they say, we want the IP addresses of everybody who viewed this one video across all of Discord, across all of the servers or something like that would be a ridiculous request you would hope that telegram um would not do something similar um do you think that rings true emmanuel do you think that's like a valid a valid concern or it is it totally is but i think it just brings telegram into the realm of every other serious technology company right they are now they are now dealing with the same problems that Facebook and Twitter and all these apps have dealt with forever, as opposed to the previous state of things where they were just like, fuck it.
17:48Which was not a good situation either, and I think why there's so much criminality in there. Yeah, it was the ease of use, and criminals know that Telegram did not give a fuck, basically. It's like, we can just hide here, basically, in plain sight. So there, as part of this shift, and you know what, to be fair, let me just briefly read out a bit of Derov's statement. He posted something to his own Telegram channel, and he said that to further deter criminals from abusing Telegram search, we have updated our terms of service and privacy policy, ensuring they are consistent across the world. We've made it clear that the IP addresses and phone numbers of those who violate our rules can be disclosed to relevant authorities in response to valid legal requests.
18:38These measures should discourage criminals. And then he carries on a little bit and then he says, we won't let bad actors jeopardize the integrity of our platform for almost a billion users. Massive change in tone from how it's been, But yeah, it's like that bit in succession where the dad says you're not serious people. I know I'm being pretty rude to Telegram, but it's like, you're not. You can't run an app for a billion users and just not respond to law enforcement requests for data. It's crazy. You mentioned this on Slack and I've since seen other people on social media note this. But if you zoom out and you look at what France did to Telegram and Brazil has now managed to do to Twitter, there just seems to be like broadly some checking of like tech billionaire power in a way that seems, I mean, again, you brought up the potential issues, but broadly seems healthy to me to just be like, okay, let's actually push back on this like completely roving.
19:47and very powerful entity that doesn't want to obey the law. Yeah, makes sense. And I guess just the last thing is that last week I actually found this court order in the US for Telegram data. The documents are sealed, but the title of the docket, which is basically, you know, where the court records are stored, it says it's looking for data on a Telegram account related to a specific charge. and then you look up the specific charge itself and it looks like it's about child abuse imagery. So that was filed in February. A judge granted that application for a search warrant to get user data. It doesn't look like it was executed.
20:32I'm actually not 100 % sure if I would see that if it was sealed or not, but that's ongoing. And the reason I bring that up is because there is a bot on Telegram, an official Telegram bot from the company itself, where you can go and request transparency reports from the company. You know, same as Signal. You go to, I think it's signal.org slash bigbrother. Maybe I'm getting that wrong, but you can, they publish like court orders or subpoenas or whatever that they've received for user data. And often there's a gag order for a certain amount of time, right? But they eventually publish it. They include their response and that sort of thing.
21:07And that's good to see. I was wondering, oh, does Telegram do similar? I go to this bot last week and it just says, please come back later. This bot is currently under maintenance on 18th of September. I was like, this is not the time you want your transparency bot to not be working. But it turns out maybe they were doing a lot of stuff behind the scenes because over the last few days, and I literally just checked it now while we were recording, it now says, we are updating this bot with current data. Please come back within the next few days. So I'll be checking that every day and I'm sure any journalist who I've just unfortunately tipped off to this listening to this is now going to be doing the same.
21:43But yeah, I'm definitely going to keep an eye on that because if they start publishing transparency reports about how many data requests they've got, I mean, that will be very, very interesting, right? All right, let's leave that there. And when we come back, we're going to talk about how investigators and researchers are circling around a particular high-profile hacker, let's say. We'll be right back after this.
22:22Fuel up for fall with Factors No Prep, No Mess Meals. When I eat something quick and healthy in the middle of a busy day, I make a factor meal. Meet your wellness goals thanks to the menu of chef-crafted meals with options like CalorieSmart, Protein Plus, and Keto. Factors Fresh, Never Frozen Meals are dietician approved and ready to eat in just two minutes. So no matter how busy you are, you'll always have time to enjoy nutritious, great-tasting meals. Make today the day you kickstart a new healthy routine. With 35 different meals and more than 60 add-ons to choose from every week, you'll always have something new to try.
22:58Treat yourself to restaurant quality meals that feature premium ingredients like filet mignon, shrimp, and blackened salmon. And for me, this is the big one. With Factor, you keep kitchen time to a minimum. Factor meals are ready in two minutes. No shopping, prepping, cooking, or cleaning up. Head to factormeals.com slash 404media50 and use code 404media50 to get 50 % off your first box plus 20 % off your next month. That's code 404media50 at factormeals.com slash 404media50 to get 50 % off your first box plus 20 % off your next month while your subscription is active. We talk a lot about building a sustainable media company, which means doing our best to keep costs down.
23:45And it's better when I can make a simple switch to save myself money. No hoops, no BS. Mint Mobile makes it easy to get wireless for$15 a month with the purchase of a three-month plan. Turns out the longest part of the process is the time you'll spend on hold waiting to break up with your old provider. To get started, go to mintmobile.com slash 404media. Right now, all three-month plans are only$15 a month, including the unlimited plan. All plans come with high-speed data and unlimited talk and text delivered on the nation's largest 5G network. You can use your own phone with any Mint Mobile plan and bring your phone number along with all of your existing contacts.
24:27Find out how easy it is to switch to Mint Mobile and get three months of premium wireless service for$15 a month. To get this new customer offer and your new three-month premium wireless plan for just$15 a month, go to mintmobile.com slash 404media. That's mintmobile.com slash 404media. Cut your wireless bill to$15 a month at mintmobile.com slash 404media. $45 upfront payment required, equivalent to$15 a month. New customers on first three-month plan only. Speed slower, above 40 gigabytes on unlimited plan. Additional taxes, fees, and restrictions apply. See Mint Mobile for details. Lumen is the world's first handheld metabolic coach.
25:13It's a device that measures your metabolism through your breath. And on the app, it lets you know if you're burning fat or carbs and gives you tailored guidance to improve your nutrition, workouts, sleep, and even stress management. I've got a Lumen and first of all, it's really easy to set up and use. Every morning, I breathe into it to learn whether my body is mostly burning fats or carbs. With that data, Lumen gives me a personalized nutrition plan based on how my body is working that day. I also use it before a workout to learn if I need to fuel up and before or after exercise or eating to see how my body is working.
25:48Lumen has helped me understand my metabolism, showing me how my body turns the food I eat into fuel. And it's helping me work toward increasing my energy levels, feeling better during a workout, and even sleeping better. So if you want to take the next step in improving your health, go to lumen.me slash 404media to get 15 % off your Lumen. That's L-U-M-E-N dot M-E slash 404media to get 15 % off your purchase. Thanks, Lumen, for sponsoring this episode.
26:28all right and we are back um here is one i wrote the walls are closing in on the snowflake hacker um emmanuel first of all we had like a lot of big breaches this year right what are some of those exactly that come to mind? Yeah, so I think the biggest one this year is probably the AT &T one. I don't know the number off the top of my head. Do you? How many? All of their customer base, basically. The quote literally from AT &T is, quote, nearly all. End quote. Which is the worst. That's bad. And that data was very compromising. It shows when people texted each other or called each other when and who they contacted.
27:25Just extremely damaging leak. There was the Ticketmaster hack that we covered. There's the Bosch Health one that I think included some DEA data. Is that the one that they were? Yes. And the DEA numbers are these little unique numbers that the DEA gives to all doctors in the US so they can be able to get prescription drugs, because they're controlled substances, that sort of thing. Right. Yeah. So there was Lenny Tree and there were others, but the thing that they all have in common is this company that you mentioned in the headline called Snowflake, and I was hoping that you could once again explain to me what Snowflake is and why it is playing such a central role in all these hacks before we get to the actual subject of the piece.
28:13Yeah, and I'm not going to lie, I did not really know about Snowflake until these breaches, basically. It is one of these software as a service platforms where, you know, instead of storing all of your data on your own servers, because maybe you literally don't have the space, it can be very expensive, you want to move it into the cloud, obviously, right? And Snowflake is one of those. Like, it's not exactly the same as an AWS or something like that. But if you think about how we've often covered where there are, like, exposed S3 buckets from AWS, Amazon Web Services, containing sensitive data, it's kind of like that.
28:58I mean, we'll get into how the hacker gets in exactly. But something that links all of those breaches together is that they all relate to data that was being stored in slash on Snowflake. And this caused, you know, massive problems for Snowflake earlier in the year because, I mean, kind of justifiably so until you get the actual facts. but it was um people were suspected the suspecting that snowflake itself was breached but it turns out it was much more about individual accounts you know in the same sort of way that if you see that maybe a gmail account has been hacked it's like well it's less likely the gmail itself was popped it was like somebody going to that um individual account basically does that make sense Oh, it's also a data warehouse.
29:51I think that's the buzzword I'm supposed to say. Yeah, so it's... All these companies have accounts, let's call them, with Snowflake. And this hacker is getting into those accounts and pulling the data from Snowflake. But the data belongs to these individual companies. They just all happen to do business with this one service provider called Snowflake that we never heard of, but it's obviously very critical to how a lot of our data is stored and kept safe. Yeah, basically. And I mean, I guess that leads to how this hacker got... Before we get to the hacker, I'll just say briefly how they got in, because it's a little bit technical.
30:34So I brought up AWS before, and that was often just where people would put data onto these servers. And it would be sat there, basically on the open internet. There would be no authentication. there would be no login you could just go to it and start pulling data snowflake um is different in that these breaches relied on you know credentials passwords basically and the hacker was taking snowflake credentials and logging in in lots of the cases i mean i'm hesitant to say all because i don't know each breach in in great detail but at least in a lot of them there was no two-factor authentication.
31:16And actually one of the big shifts that Snowflake did was that it made multi-factor authentication mandatory for new accounts on the platform. But I think that was months, well, weeks, but I think months after all of this massive drama from the company. So how did this hacker get in? Well, it goes back to something I'm becoming increasingly amazingly obsessed with. Basically, I think there's a lot of room for more stories around this phenomenon, and that's called InfoSteelers. And these are pieces of malware that infect typically Windows PCs, cringe, and they are distributed in, you know, cracked software, pirated software.
Read the full transcript
32:07Don't go downloading like a pirated Photoshop or something like that. You I don't care about the theft. I care about they may include malware. And these harvest people's login credentials, but also sometimes like their browsing history, take screenshots of their device, all of that sort of thing. And these then get uploaded to Telegram. Again, this is why we're also bringing it in. And here you can sometimes buy early access to these credentials. You know, give the malware maintainers or the people distributing the credentials some money. You get early access so all the creds are nice and fresh and then you can log in.
32:49Or you wait a little bit and then they're freely distributed on Telegram. I mean again I have Telegram in front of me. I have a nice folder that a security researcher made for me of all of these different channels. I'm going going to click one. I'm going to scroll down to the bottom, and it says, here's a combo list of gmail.com logins. And these were probably harvested from InfoStealer malware. You take those, you log into Gmail, and you're fine. And again, that's not a breach at Google. It's that the individual computers of people were hacked, they stole the creds, and they uploaded. So go ahead, the manual we have to change the branding on info stealers this is why people are not aware of it what is an info stealer if not a hack what is a hacker if not a stealer of information yeah i mean yeah it's too generic we need a better better branding for this but sorry go on no you're right and i initially didn't really pay attention to it because it was like oh malware steals credentials i'm like yeah duh like obviously it does it's like banking trojans we've had like since what, the late 90s or whatever, or a very, very long time.
34:01It's like, yeah, malware steals data and login credentials, but it's now both the distribution of those creds, a lot through Telegram, and how it's dramatically lowered the barrier to entry for hackers to just take those. They download a file, they then search through them for Coinbase or whatever, or in the case of Snowflake, potentially, you just type in like snowflakecomputing.com or the domain or whatever, and then you have the credentials and you log in. And according to Mandiant, the cybersecurity company that's been looking into this hacker, that's how he was able to do it. Just be able to take InfoSteeler credentials and log into these Snowflake instances.
34:51So there's all this chaos. like global national chaos, all these companies, millions of customers, all this personal information. And at the center of it is like just a little guy, right? It's just like behind all of this stuff is just a dude. And before we talk about how it seems like time may be running out for him, what do we know about this person? What is like any biographical information we have about like this agent of chaos this year? Yeah, I mean, you're absolutely right about the chaos and everything I said about it causing a great amount of disruption for Snowflake, but also the individual victims as well.
35:30So this hacker goes by a lot of different names. ZFA was one. I've known him under various other ones as well. The one we'll just use for the benefit of this conversation is Dudish. That is a handle they've been using for some time. And this person has been in sort of the wider hacking scene for a long time, it seems. Brian Krebs reported that they were on some sort of sim swapper, almost like a billboard chart, almost like a high score sort of ranking that ranks like how much money each one has made. And this person was relatively high. when I spoke to associates, associates of them, they also brought up that they likely met another hacker called John Binns through sim swapping.
36:27John Binns also worked on the AT &T breach and he allegedly also hacked T-Mobile somewhat recently. He is an American currently in, well, was living in Turkey. Now he's detained in Turkey. But then after the arrest or that detain after Binns ended up in prison. Judish starts this rampage through various snowflake instances and just takes that methodology and keeps running with it to the point of even using their own software. I don't know exactly who made it, but Mandiant said it It was a custom tool that would find targets to then breach using these InfoSteeler credentials. And Mandiant's built up what they think is a pretty good, I mean, I say pretty good.
37:22They say moderate confidence to use like intelligence, you know, parlance. and they suspect that he is a 20-something male, likely in Canada, likes video games, likes geopolitics, and also likes cat girls. Sam, what is a cat girl? Because this was like a point of contention even while we were editing the story. Wow, okay. I would love to get off the bench and tell you what a cat girl is. It's just a cat girl. It's a cat girl. What do you want to know? It's a girl that has cat ears. It's self-explanatory. Well, that's what I thought. And then I got very confused when, like, Jason and Emmanuel were asking me in the copy, like, what is it?
38:02They were fucking with you. Okay. We were trawling. We were just like, I'd love to see Jill briefly define a cat girl for the audience. And I don't think I even did. No, you didn't. It is self-explanatory. Yeah. I mean, there's a Wikipedia page for cat girls, which I learned through the process of, because Emmanuel was like, we need a link here. And I was like, well, what would the link be for this? It's an anime thing. Yeah. It's girls with cat ears. Yeah, exactly. Listeners can't see me, but I'm making cat ears with my hands. And Judisha does often have an anime image as their profile picture.
38:40I just want to note also that it's funny that you said that he's been doing this for a long time because he is, we assume, 20-something, so possibly has been in the game since he was a teen. Yeah, which applies to a lot of people. nowadays. So why do we think the walls are closing in on him? So it's a combination of a few different things. As I sort of alluded to, Mandiant, the cybersecurity company, has been looking into Judish for a while. Specifically, there's a researcher called Austin Larson, who gave a talk at LabsCon, which is a cybersecurity conference in Arizona. One of these smaller ones that um looks pretty great to be honest maybe i should try to go to these rather than spending all my time in vegas and getting exhausted from just eating starbucks all the time um and like desperately trying to find some healthy food but he has been reading judicious telegram messages for months and months this includes the public ones which you know everybody can see i can see you just go to these telegram groups and you start reading it also includes some private ones as well.
39:56But crucially, Mandiant isn't just observing from sort of that perspective. Because Mandiant often works on the incident response to a hack, which is they send people out to, you know, I'm just saying hypothetically AT &T or LendingTree or whatever those breaches were that Mandiant may have worked on. They can go there and figure out how a hacker got in, respond to the incident. And that also gives them a lot of data, like what IP addresses were used as part of that intrusion. Maybe there were other sort of digital fingerprints the hacker left behind. So they're building up this picture, not just of who the person may be away from keyboard in real life, but sort of their activity as well, sort of when it comes to actually breaching companies.
40:47And what the hacker would do as sort of normal procedure, and I should have said this already, but they're an extortionist, as in they're not just hacking companies and stealing data for the hell of it. They will go in, they'll steal data, they will then contact the company in, I think, a various number of ways. And they will say, I have this very sensitive of data from you. I will delete it if you pay me a lot of money. And Wired reported that AT &T did pay several hundred thousand dollars to the hacker to have that data deleted. And as part of that, the hacker would often make these videos that would prove it.
41:31It would show their screen and they navigate to the data and they would remove it. And then, you know, that would be sort of the insurance that the data had actually been removed and then the company would pay. But what the hacker has done is a series of like pretty bad mistakes in those videos where at least one of them included their host name, which is basically the name the computer uses to identify itself on a network. And, you know, and to be clear, this isn't like their laptop. Oh, it showed the name of our laptop. No, it's showing the server they're logged into where they're storing the data and then deleting it.
42:12This is, of course, how often hackers store and exfiltrate data. They're not just pulling it down to an external hard drive on their laptop or their desktop. They're using a VPS somewhere to exfiltrate in there and then store the information as well. So armed with that host name, and I think some other identifying details, Larson and others at Mandiant were able to figure out where that server was by using the computer search engine Census, which can, you know, I was actually using Census today to report another ghost and crypto phone story. And it can show you sort of details about the server, its characteristics, you know, I think like what software may be installed on it, that sort of thing.
42:57They were able to figure out Judish's infrastructure is in Ukraine. They then informed the relevant authorities, and the server got shut down. All this time, I'm actually speaking to Judish because he's posting in these public telegram groups complaining about the SBU, the security agency of Ukraine, security service, seizing his server. And something you have to keep in mind about this is Judish often does something called D-Trace, which is where they'll post deliberate misinformation to try to throw journalists, researchers, investigators off. But sometimes they actually say some stuff is true, and that applies to the seizure of their servers as well.
43:39So, I mean, there's all of Mandiant's stuff. There's Brian Krebs is doing more reporting, and he actually published a few days before Larson's talk that it's likely somebody in Canada as well. I think Brian Krebs actually even got a little more specific than that. But I guess, well, and the last thing is that Mandiant confirmed to me they are coordinating with US and international law enforcement, which is obviously the biggest concern if you're a criminal hacker. I guess just last thing I'll say is I didn't really get into this in the piece because there's not really many details available at the moment, but the hacker is still active and they're still targeting other software as a service platforms.
44:23I don't think the disruption is going to be like as big as it was with Snowflake, but they're apparently still doing stuff, you know? So I guess we'll just have to see what they do next or if they get arrested first. All right. With that, if you were listening to the free version of the podcast, I will now play us out. But if you are a paying 404 Media subscriber, we're going to talk about how Nintendo will probably win its lawsuit against Power World. You can subscribe and gain access to that content at 404media.co.
45:02As a reminder, 404 Media is journalist-founded and supported by subscribers. If you wish to subscribe to 404 Media and directly support our work, please go to 404media.co. You'll get unlimited access to our articles and an ad-free version of this podcast. You'll also get to listen to the subscribers only section where we talk about a bonus story each week. This podcast is made in partnership with Kaleidoscope. Another way to support us is by leaving a five-star rating and review for the podcast. Here is one of those from Andrew Neil. This podcast is restoring my hope in tech media. Thank you very much.
45:38This has been 404 Media. We will see you again next week. Thank you.
From the publisher
We have two related stories this week. First, Joseph, Emanuel, and Sam break down their experiences with Telegram, and the social network's massive policy shift. The company says it will now process valid legal requests from law enforcement for user data. After the break, Joseph tells us how the walls are closing in on one of the most disruptive hackers in recent memory. In the subscribers-only section, Emanuel explains why Nintendo's lawsuit against Palworld is bad, and why Nintendo will probably win.
YouTube version: https://www.youtube.com/watch?v=90T71r3h7oc
Telegram Changes Policy, Says It Will Provide User Data to Authorities
The Walls Are Closing in on the Snowflake Hacker
‘Cold-Blooded Business’: Nintendo Is Patent Trolling Palworld Because It Got Too Big
Subscribe at 404media.co for bonus content.
Learn more about your ad choices. Visit megaphone.fm/adchoices
