Podcast
151- Chris Rock
Darknet Diaries
- Middle East Job
- Chris Rock, a security researcher, was hired for a job in the Middle East.
- It involved investigating a suspected theft of money and intellectual property. Transcript: Jack Rhysider And I’m not even sure what kind of job this was. It’s not exactly a penetration test and it’s not exactly an incident response. Chris Rock Research and engagement is probably a better word for it. So when I was doing pen testing, people would say, Chris, you seem like a guy that would do outside activities. And then I’ll get approached for these outside activities and then, you know, around the world to, you know, hack into this person, hack into this company, you know, get these secrets And that sort of stuff. So essentially, both paths are working. Jack Rhysider So through word of mouth, there’s someone in the Middle East who needs a hacker’s help and heard that Chris is the guy to call for these sort of things. So he calls him up and says, can we meet? Chris Rock Usually they do it in person. So in this case, I flew to a neutral area. So I flew to Istanbul and Turkey and then met over dinner to talk about the exercise that he put forward. Jack Rhysider That’s quite a, I mean, already I’m intrigued, right? Because it’s like, hey, we have this job. If you want more details, meet me in Turkey. Chris Rock Yeah. And I say it off the cuff because that’s natural for me. And I know a lot of, you know, pen testers don’t see that side of the world. You know, they see it in a forensics report or, you know, instant response. But once you live it and you go through it, it’s very interesting. Well, like it’s, you know, Jack, you know, I’ll use you as an example. You know, you get paid every week slash fortnight slash whatever and you get your paycheck, tax comes out of it, stuff like that. But when you’re on that other side, you know, it doesn’t work like that, obviously. You know, there’s no tax, but you’ve got to get your money and things are expensive, burner phones, you know, burner laptops, crypto, peer-to money and getting your money washed, all That sort of stuff. Different world. It’s, you know, a great learning curve, but a lot of us don’t get to experience that sort of stuff. Jack Rhysider Well, yeah. What is this engagement? Tell me more about how this was pitched to you and what’s the job and stuff. Yeah. So I met this guy. Chris Rock Warden’s calling Mike. I met Mike and Mike worked for a company and they were rich Middle Easter’s who, essentially he was one of five brothers and each of the brothers was worth about a billion dollars, but He was only worth $200 million. So he was like the poor loser of the family. So I know that sounds really weird, but he had to take bigger risks to compete with his brothers to get to that billionaire status. And that’s why he would engage hackers to assist him with his business activity. So in this case, it was put forward to me that one of his subsidiaries, he thought that they were stealing money and then moving that money to another company, another offshore company, And also the IP from that company. So he asked whether they’d be interested in finding out whether it was true and then to recover as much money as possible. (Time 0:08:08)
- Plausible Deniability
- Clients in the Middle East often use intermediaries (“skirt wearers”) to maintain plausible deniability.
- This shields them from direct links to hired hackers. Transcript: Jack Rhysider So did you meet with this multimillionaire directly in Turkey? Chris Rock No, you always go through an agent. So I don’t want to sound rude, but when you’re dealing with Middle Easter you don’t actually deal with the Middle Eastern guys. You deal with, I’ll say, you deal with a white guy because they don’t want to have any direct link to the foreigner. So I met with an agent of the rich guy, and he was from South Africa, and him and I discussed what was required, the targets. Jack Rhysider Chris, this is not a normal incident response or engagement or exercise or whatever it is you called it. When I hear that they wanted this extra layer between the client and you, it makes me think that they want plausible deniability. So if you get caught, they can be like, we don’t have any Aussies on our payroll. I’m not sure who you have, but that’s not our problem. And they’ll just leave you in the dust. Do you see it that way too? Chris Rock So the answer is yes. You are spot on. It was essentially one level removed. And the reason I hesitated with my language before about talking about white guy, we refer to them as skirt wearers. So, you know, like the Middle Eastern with their long garb that they wear. So it was your skirt wearer will not meet a Western guy. So there’s always a Western guy dealing with a Western guy. That’s the language that we would use for these sort of assignments. (Time 0:11:48)
- Targeting Strategy
- When targeting someone like “Bob,” start by compromising their outer circle (level three, then two).
- This helps understand their communication style before targeting them directly. Transcript: Jack Rhysider So what are your first steps? Chris Rock What do you get going? What do you do? So the first step, so we had a number of targets. It wasn’t a single target. We had essentially eight targets on our list. So essentially, we essentially map out the person, you know, the internet dumb research on who this person is, how they live their lives, you know, LinkedIn, know social media all that Sort of stuff getting that sort of information obviously phone numbers email addresses physical addresses and stuff like that and then plan an attack okay who are we going to go after First are we going to go after the prime target first i’ll use the guy bob you know bob analysis is an easy one to use so in this case we were the prime target was bob but we had all these other Targets like alice and jane and all that sort of stuff and maybe we don’t go after bob first maybe we map out these other people first so when we do an exercise like this when and we’re talking Big money when we do exercises like this we own we don’t just send like a blind email and then just like oh you know they’re on to us or we got in successfully so we’ll essentially own their Whole world so we talk about level one, level two, level three. So level one is their inner circle. In this case, Bob’s wife, Bob’s kids, all that sort of stuff. Then you have a layer two, things like accountants, lawyers, gyms, all that sort of stuff at level two. And then you have the three, like the affiliates on the outside. So we might target, in this case, we would target level three, level two first. And when I say target as in own emails, so you can actually, if we sent an email to Bob, he would reply to it and wouldn’t think it’s dodgy, if that makes sense. Not from, you know, dodgyidiot at gmail.com. It’s actually a real person. So we would, you know, target level three, level two. And then once we’re comfortable with all those assets, now I know that sounds like very exhaustive, but when you’re doing these sort of gigs, those level two, level three come in handy Jack Rhysider Down the track. Whoa, this guy’s serious. I’ve told you many times, don’t open attachments on emails or click on links from texts from people you just don’t know. But what Chris is doing is he’s targeting people this guy Bob did know, getting into their emails and their network first, so that when it’s time to target Bob, he’ll be sent an email from Someone he does know, and perhaps even a document that he’s been expecting. Like, for instance, if you get an email from your doctor with the lab results included, that would likely be an attachment that you would think is safe to open. This is the kind of stuff that Chris was trying to do to avoid any suspicion that Bob is being hacked into or spied on. (Time 0:15:17)
- Office Infiltration
- Chris built a custom device with a tiny Italian motherboard and Linux for Wi-Fi hacking.
- He easily gained building access, planted the device, and compromised the target’s WEP-encrypted Wi-Fi. Transcript: Chris Rock First plan never works. It’s just one of those things in life and it never works. And if it does, it’s like, man, that was the one in chance. So you’re right. Multi-gear. It’s of those things you have to plan for the worst. The goal was to get access to this company’s network. Jack Rhysider But where’s that company’s network? And how do you get into it without being caught? This is where the more you know about that company, the better. He discovered this company had a Wi-Fi network set up in the building. And what’s more is the Wi-Fi they were running was using WEP encryption. This was years ago when WEP wasn’t so uncommon. Today we use WPA, which is much more secure, but WEP had some vulnerabilities. If you could get a radio near the WEP Wi-Fi router, you could intercept enough beacons and packets to get on their Wi-Fi network. So that was the goal. Get in the building, get within range of their Wi-Fi router, and plant a device to listen to and capture the web packets. Chris Rock We actually had to do custom-built stuff. So I got an Italian motherboard that was the tiniest motherboard at the time, and then built up my own Linux stack with Wi-Fi hacking. And things like party and reverse shell tools like Pl and stuff like that that we would use that we would plant close to the VC firm. Jack Rhysider So he loads up his kit full of cool gadgets and flies over to that country. Chris Rock You got any sort of way you dress up when you go out to these things? Just, look, black or blue suit with a white shirt and tie. Like it’s just, even if it’s 50 degree heat like in QA, that’s what you wear. That’s not what a black hat hacker looks like. I know, I know. Exactly right. So, yeah, so hoodie, all that sort of stuff, that doesn’t command respect over there. But suit guy over there, in their eyes, respect. Jack Rhysider He goes to the office building and starts planning out how to get in. Chris Rock That’s the easy part. A white guy in a suit with a laptop, with someone holding lots of books, someone will open the door for them. You know what I mean? It’s one of those pen testing stories that you’ve probably heard a million of. But that works in the U.S. Jack Rhysider Or even in Australia. But if you’re a white guy walking into a place with a bunch of people that don’t look the same, now you’re out of place. Your thinking is right. But when a white – let me show you. Chris Rock Middle Eastern companies like a Westerner in there because these people have been trained outside of the Middle East. We trust them. They’ve been to, you know, Cambridge and MIT, all this sort of stuff. So it comes with an inherent trust. So you’re right, Jack. Your thinking is, oh, you know, the white guy sticks out of place. But no, over there, a white guy, you do what they say. Because if you’ve done any work in the Middle East, they employ, you know, the best German engineers and the best, you know, English, you know, financiers and stuff like that. It’s not unusual for a white guy to come in pretty much run the show, if that makes sense. Jack Rhysider So he’s let in the building, no problem. And it’s a co-working space, which means there’s a lot of small businesses working out of this building. And he can use that to his advantage because everyone is used to seeing strangers roaming around. Chris Rock Getting access to the building was really easy because it was, like you said, it was a co-working space. And then finding out that they were on a floor that had one of those communal kitchens, like for us, it was easy as. I didn’t have to get past a receptionist or someone, what are you doing here? It was essentially a guy making a coffee, pulling the microwave forward, sticking something behind her, and then boom, we had a device planted in to get this last VC firm. You (Time 0:21:06)
- Evidence Gathering
- Chris gained access to file servers and email servers, uncovering folders related to IP theft.
- The operation lasted over nine months, involving extensive email monitoring. Transcript: Chris Rock Correct. And then we had access to file servers and stuff like that and email servers. And that’s how we got into that company that we couldn’t get in through the whole remote PDF stuff. Jack Rhysider At this point, Chris has a huge amount of visibility into this investment firm and the suspects who might be stealing this money and intellectual property. He’s got a ridiculous amount of listeners in place, full access to the network. Like he can look at all the files on their file servers and email servers, full access to some of the suspects computers through remote access trojans that were put on there. He’s able to see every email in and out. And he also has key loggers on their computers so you can see what their usernames and passwords were. But he also has access to emails and computers with people around the suspects, family members, friends, doctors. He’s also looking to see what kind of bank accounts these people have, just in case he needs to get in there and take a look to see where money’s going. So with all this access, he starts finding stuff that the client might be interested in. Chris Rock On file service, you’d start seeing folders, like a folder. And then we’re talking about in the investment firm, you would see like, you know, bulbs, and then you would see things like IP and stuff like that, which we would then run past our clients Saying, is this the sort of stuff that you’re worried about leaking into somebody else’s hands? And then we would send that to our handler who’d say, yes, no, yes, keep targeting that sort of stuff. So you start starting building a picture. And I mean, this exercise went for a long time. I don’t want to exaggerate, but I think this one went for nine plus months on this exercise. It was just a continual stream. So over that time, you’re reading every email back and forth. And so you would get all that sort of information and learning how they speak and how they think and proper language. So you start piecing the puzzles together on what this guy is actually doing. And because I’ll say this, we don’t give a shit what he’s doing. It’s essentially here’s what he’s doing, client. Is this what you want? Is this what you suspected? There’s no emotion. We don’t give a fuck. It’s just a job. And then we would give that, say yes, no. How do you want us to proceed? And then go from there. The (Time 0:26:37)
- Bank Heist
- Chris’s client, fearing legal delays, wanted the stolen money returned immediately.
- Chris successfully retrieved $2.5 million by compromising the bank and acting as a teller. Transcript: Jack Rhysider The payment for this, was it sufficient? Because I can imagine them saying, here’s a briefcase of money. And then you’re like, well, dude, okay, we’ve been working on this for three months. If you want us to keep more, we need another briefcase. Chris Rock Yeah. How we operate is we’ll have an initial fee, a finalization fee, and then we will have what we call an ongoing fee. So the jobs like this we’d like to have over within a month. So initial fee, completion fee, but if you want us to continue to monitor these eight people and this outside company, you’re going to have to have a monthly charge, almost like a subscription Model, where they would pay to just find out what’s going on in these people’s lives. So you don’t want them to think they’re idiots. So you’ll put a quote in front of them and they’ll say, we agree to that quote. You better stand by that quote. You know what I mean? Like if you want referral jobs going forward, like if you said half a mil or a mil or two mil, whatever you quote, that you stick to that. You don’t say we need more. Like you make it crystal clear because this is, this is repeat business that you want. Jack Rhysider Yeah, I’m just starting to put the picture together of how much you charge versus how much they’re losing. It’s worth more to them to pay a million or two million to you. Chris Rock And if they’re going to recover, how much money do you think was being stolen here? In this case, I know exactly how much money was being sold. I think it was $2.5 or $2.75 million in this case. But you’ve got to think when you’re in business, Jack, I know you’re in business, but when you’re working with a customer, their initial first year spend might be, let’s say it’s half A million dollars for the initial spend. Once they see how useful you are and then you do repeat business, it’s like it’s an investment firm. They’re always investing shit. So they’re always going to use your services down the track. So you might do, it’s a bit like a drug dealer. Like you might give them a taster for half a million and the next job is going to be worth two. So you know what I mean? Like you just, they know your work, they know your style. And then you know you’re going to get repeat business with higher stakes. I mean, he’s dealing with wealthy people here, billionaires, oil money. Jack Rhysider If he can prove that he’s the go-to person to these folks, yeah, these could be long-term customers of his. And in this case, they were very happy with him. Chris Rock They got enough evidence to take action on this thief. They then got lawyers involved from their side. They had to be really careful about what they presented to the lawyers, but it was, we believe, XYZ, and then get the police to arrest the ringleader, Bob, at that moment. So that was essentially their goal, to get him in jail, because they took it personally. Like I said to you, you’ve got to treat them with respect. And if you disrespect them, they get really emotive. And for them, jail was the worst case of action for them. (Time 0:32:52)
- Mercenary Mindset
- Chris operates like a mercenary, prioritizing repeat business and reputation.
- He views the bank heist as returning stolen funds, not theft, thus morally justifiable. Transcript: Jack Rhysider There was enough evidence to prove that this guy Bob stole the money and the intellectual property. But they told Chris they were worried about the money. The customer worried that Bob was going to use that money in defense. Chris Rock He was going to, you know, get on all these bloody Shapiro lawyers to fight his case and use the funds that he’d stolen to fund that exercise. Jack Rhysider So they asked Chris, get us back that stolen money. Do your job as a hacker by any means necessary and return the money to us. Which, in my opinion, is crazy because why not just have the police return the money? Chris Rock They didn’t want to wait because you’re thinking American system, not Middle Eastern system. They didn’t want to fuck around with that sort of stuff. They didn’t want to go through, we want the money, you know, we want this, we want, you know, and then put a brief together, stuff like that. They don’t roll that way. So his objective was clear. Get into this guy’s bank account while he’s in jail and move the money out. Jack Rhysider This job has essentially turned into a bank heist at this point, and it seems to me that Chris doesn’t have any moral concerns about robbing a bank. No, no, no. Chris Rock And Jack, I’ve listened to a lot of your sessions, and that comes up quite a lot. I don’t have that boundary. Does that make sense? So for me… Jack Rhysider Okay, so this doesn’t make sense just economically, right? So if somebody pays you $50,000 to go get a million dollars out of a bank account, why don’t you just go get the million dollars and be like, you know what, forget you. Chris Rock I’m just going to go steal my own money. And that’s actually happened on jobs before where you take your share as well. But you… So in our case, remember, we were returning the funds. We didn’t return the funds and a little bit extra. Yes, we could have taken money from somebody else’s account, but that raises flags in case. So we were essentially returning the money that was stolen. So there’s no actual victim. Does that make sense? The money was returned to the rightful person. Yeah, it does make sense. And remember, we’re after repeat work and word of mouth, which is how you work over there. Jack Rhysider It’s like building a business. Chris Rock Yeah. (Time 0:37:10)
- Bob’s Escape
- Bob, the suspect, used a feigned illness to secure bail and escaped the country.
- Chris tracked his movements via email headers and suspected a planned escape. Transcript: Chris Rock He’s a kind of guy that I actually have respect for this guy because he’s pretty cunning. And because I’ve been reading his emails, I knew him so well inside and out. You know what it’s like when you’re reading, oh, maybe you know Jack, but when you read someone’s emails, you have a relationship with them whether they don’t know it, but you actually Know them inside and out. So Bob’s quite crafty, but Bob used the I am ill card, and he worked with his doctor to get a bail hearing that he could get out on bail while this case is going forward. So he was essentially in jail for a week and then the doctors wrote, you know, my client is sick note, which we could verify because we talked about level two and level three. We had access to his doctor. So we got to see what was going on, that he used his doctor to get out of jail after two weeks in jail. What happened is we were reading some of the emails when he was in jail, obviously, and then outside of jail, and his language changed. He almost like he was putting it on. You know, like when you’re an actor, you act. And when you’re not an actor, you look like an idiot. And Bob was essentially looked like he was acting in his emails. And I said to the customer, this is not normal emails that he’s sending out this like he was going on fishing trips he was planning a fishing trip and you know the kind of never been fishing You know it was all these sort of i’m going to be here at this time and it was it was too much information that the thing i think you know he’s on he knows that you’re we’re reading his emails And he’s he’s putting it on and i said look what this guy’s a flight risk and they said he went no no no he’s fine. Jack Rhysider We’ve got his passport and blah, blah, blah. So because Chris had such a deep level of visibility into Bob, he watched him closely to see where he was going. Chris Rock Bob didn’t actually go fishing. He was smuggled across the border in a bloody burka. And we tracked his headers of his IP saying, look, the guy’s not even in the fucking country anymore. You guys think he’s there. He’s not. He’s in Amman. So, you know, all this shit talk about, we’ve got your passport. He’s not going anywhere. And he actually escaped the system on a second passport. Because this was in real time over maybe a 12-hour period, I’ll say 24-hour period, essentially the guy was moving fast, you know, car, he was in a car. We later found out that he was in a boot and then he went into the backseat with a burr car and then he hopped a border and then he had another passport and then he used that. But because we had the IP headers, we could see where he actually was. Like he was, I’m not saying he’s stupid because a lot of people don’t, in that world, don’t understand IP headers. You were in his phone? No, he was sending emails out from his device. I will make that clear. Normally, we do get into phones, but this case wasn’t a phone. It was just email headers, not IP. Don’t get me wrong. I don’t normally talk about this, but sometimes we’ll send a ping packet. So you get the odd SMS and you know, Jack, you’ll get an SMS and you’ll click on it, you know, your UPS mail is late. You’ll click on it and go, oh, it’s just some fucking scam. It’s asking for my username and password. But what it does is it just tracks your location from your phone. We used that a couple of times on this project, but it wasn’t a tool that was needed. Does that make sense? We had enough from the IP headers that we didn’t need a GPS location. Jack Rhysider Once Bob left the country, there was nothing Chris’s client could really do about it. So they said, thanks for letting us know. I guess that’s it then. Here’s your final payment. That’s the end of the engagement. Weird question. Have (Time 0:50:04)
- Fake Identities
- Exploiting online death registration systems, one can create and “kill” fake identities.
- Obtain necessary license numbers and addresses online; flaws remain unfixed. Transcript: Chris Rock Of my career as a pen tester, mercenary, scene founder, is research. And one of my first DEF CON talks was I was watching the news in Australia and the news report was a hospital accidentally sent out 200 death notices instead of 200 discharge notices. And I went, what the fuck? How is that even possible? And then that led me down the rabbit hole of researching the death industry, the medical component and the funeral director component on how the system has moved online and the flaws That involves where you could actually physically create a real person, like a fake person, and how you could kill them. Okay. So walk us through this step-by how to kill someone. Yeah. So in America, actually, it’s very similar around the world, but in the US, they used to have a paper-based system where the funeral director would fill out half form on how the person Died or where the person died, like where they’re buried and all that sort of stuff, next of kin. And the doctor would fill out the first part of the form, which is the cause of death and those sort of details, name of the victim and then how they died. That one piece of paper would go into essentially the birth, deaths and marriages system, and then that person would be declared dead. What’s happened now is that’s moved online. So essentially when somebody dies, the process is the doctor will log onto a US system called EDRS, so log on with their username and password, and actually put in what caused that person To die, a pulmonary embolism or whatever, a heart failure, that sort of stuff. And then that information would then pass to the funeral director. A funeral director would complete their part, again, username and password to log in, and that would form essentially the death certificate in the EDRS system. Now, the flaw in the system is both the medical and the funeral director component is essentially if you want to be registered to declare people dead, you essentially put in your license Number, your medical license number and your office address. Now, if anyone’s looked up a doctor before to see if they’re a real doctor, all this shit’s online. There’s databases all around the world to say whether your doctor’s license to practice, their registration number, and their office number. So you could register yourself as a doctor, and then you could actually kill somebody off the first part. And again, with the funeral director component, it’s pretty much the same as a doctor, where you can declare yourself a funeral director and form the second part of that form to kill Somebody off and get essentially a death certificate. (Time 0:54:10)
- Exploiting Birth/Death Systems
- Create fake identities for various purposes like insurance fraud or evading prosecution.
- Register fake births even up to five years after the supposed birth date to exploit system flaws. Transcript: Chris Rock Someone? Well, there’s multiple reasons why you want to kill someone. First of all, if you want to kill your parents, for example, like you’re waiting for their will, but they’re not giving you the money, you could actually kill them off. You could kill your boss. Your boss was being an arsehole. You could kill him just to fuck with them. Or if you’re under investigation, say you know, you’ve got, you know, prosecution and judge and all that sort of stuff, you could actually kill them off to make their life more difficult. Oh, my gosh. You’re ridiculous. Jack Rhysider And so you’re saying this flaw in the death system can also be done in the birth system? Yes. So it’s exactly the same. Well, it’s a different system, but exactly the same as ERS for deaths. Chris Rock And you need two parties. So you need the doctor or midwife and you need the parents. So then, you know, the name of the child, the weight of the child and stuff like that. So the two parts would then make the birth certificate, very similar to the funeral director and the doctor making the death certificate. And if you have a home birth, you may not even have a midwife. So it’s something actually done by the parents. And so once you have an online system, you have a birth certificate, that person is then born. So in theory, you can create fake children. And then when they hit a certain age, you could kill them off and get their life insurance and build up their credit and all that sort of stuff. You do both of the things. Jack Rhysider Well, I really like this idea of making a fake persona to use as a second identity in case I’ve embezzled some money from a Middle Eastern millionaire and I need to leave the country. Chris Rock Exactly, Jack. And why have one when you can have 100? So you can have 100 fake people that have different credit. And so if you screw up your life and you go to jail and you have to come out and you go get another job or whatever, you have another clean identity, like another virtual ID. And it’s real. Like it’s not like someone entered it in the back end. It’s actually a registered person that you can have. I suggest you keep yourself looking young because you might create someone who’s zero. But there’s little flaws in the system as well. And I may have mentioned that they don’t want people going through life without being recorded. So you have up until the age of five to get yourself registered. So if you have – you can take five years off your virtual person by registering five years after they’re born because they want to capture people as they go into the school system and they Don’t want them to be prevented from going to school or getting driver’s license or stuff like that. (Time 0:56:40)