Snook - 3+ Hours of Disturbing Dark Web Websites
Episode Date: August 9, 2026This is 3+ Hours of Disturbing Disturbing Dark Web Websites! This is a megacompilation of some of the most wild, disturbing and scary internet rabbit holes... I hope you enjoy! And let me know if you ...would like to see more videos like this in the future! Thank you all for listening! Make sure you rate the podcast 5 stars and follow! Thank you all so much for listening! Make sure to subscribe to the Patreon for early access videos and many more perks! https://www.patreon.com/SnookYT Also! Go follow me on Spotify and Instagram! Yes, my voice is human. The channels subscriber goal is 1 million, so subscribe! Learn more about your ad choices. Visit podcastchoices.com/adchoices
Transcript
Discussion (0)
Most of you have probably heard of this Silk Road, the infamous dark web marketplace where drugs were
freely sold. You might not know of its successor, though, even though at its peak it had 10 times
the users that Silk Road ever had. Founded in 2014, a few months after its predecessor was shut down
by the FBI, it reached nearly 370,000 listings at its peak with 400,000 users and saw
over $800,000 flow through the site in the form of crypto transactions.
every single day. The creator, Alexandre Kazas, under the moniker Alpha O2, was well known in
Carding Forums, the Black Market for Stolen Card Info. He would help out over there and eventually
would decide to start his own marketplace, and Alpha Bay was born. It was modeled after a conventional
e-commerce site. In its About Me section, Kossis said that its goal was to become the largest
eBay-style underground marketplace. He was well aware of the illegal activities he was facilitating, and
even advised vendors on how to avoid law enforcement. He charged each vendor a fee so they could
sell on his site and charged a commission on each transaction, around 2 to 4%. A staff on payroll
helped him maintain the site, which included a security administrator, D. Snake, who had similar
access as Alpha O2, several monitors who could help refund Bitcoin, scam watchers who would look out
for efficient attempts, etc. And even a PR manager who would manage outreach.
by posting on Reddit and other public forums.
However, just like Silk Road, it would fall too.
And for the same reason, too.
Laffably, sloppy, security.
When Alpha Bay was launched, an associated forum was launched to allow customers to discuss.
When you signed up, it asked you for an email for password recovery.
And to that email, Alpha Bay would send an email, welcoming them.
Sounds like a good idea, right?
Customers should feel welcomed after all,
except for the fact that the email address that sent these emails was actually Kassas' personal email.
Whenever you wanted to reset your password, you would also get an email from the same address.
Obviously, law enforcement very easily found out who owned it.
Kazas' name and date of birth was revealed in his LinkedIn profile showed that he worked at
EBX Technologies.
EBX Technologies was supposedly a web design firm, but its website was barely functional itself,
not a very good first impression for potential customers.
In fact, as you may have guessed, it was a shell company to manage his crypto holdings and liquidate them without too much trouble.
Currently, the website displays this message.
Following the sudden death of Mr. Alexandria Cazas in July 2017, Sikai acquired a portion of the assets of EBX Technologies.
If you are a company or an individual who has done business with EBX technologies in the past and have pending work or other needs,
please contact us at your convenience.
We would be delighted to meet you and discuss how we can help.
We look forward to hearing from you.
When it comes to the company that supposedly purchased the assets of EBX,
Sikai is a very unique web design and development website.
There's a chance that EBX technologies very did service web development for clients.
They soon found out that Kassas was living in Bangkok, Thailand.
The Royal Thai police working together with the FBI arrested him.
Incredibly, his laptop was open, unlocked,
and unencrypted. It was logged into the Alpha Bay website as admin, and he was in the process of
rebooting the server as it went offline from an outage that the law enforcement created themselves.
Every single password, including the website and server passwords, were listed in an open, plain
text file. Obviously, they seized everything. Apparently, Cossus liked to be organized as there
was another file that identified all, I mean, all assets and holdings that Cossus held.
It was very detailed, listing in the story.
storage and location of all crypto and assets like cars and property that he had bought.
Pretty convenient for the police to find and seize everything.
It turns out, he was also trying to obtain citizenship in Cyprus, where it is possible
to gain residence by investing in the country.
He had sent $2.38 million to buy a villa to a Cyprus bank and had successfully bought his
way into the country.
And you may wonder why Cyprus.
Well, causes probably chose it for its unique extradition laws.
Before the formation of the European Union, countries would refuse to extradite you for crimes you committed in another country.
However, after the formation of the European Union, this changed, and now EU countries consider each other as domestic for the purpose of extraditions.
Despite Cyprus being a part of the EU, its extradition laws are different and would reject any foreign interference.
And side note, the U.S. is actually the only real exception to this, however.
Cypriot banks only interface with the EU so it does not get involved.
Furthermore, they are very careful to not conduct business with any U.S. citizens.
Combined with the fact that citizenship can be easily bought, and the banks don't really care
where the money comes from, it makes it a very attractive location to launder money through.
In the end, he had a total net worth of $23 million from his underworld empire.
A few days after his rest, he was found dead in his cell, allegedly committed.
S-word. Many in the dark web community felt like he was murdered. This was not the end of the story for Alfa Bay, though.
You might remember a site administrator that had a similar level of access to the site, DeSnake.
Four years later, he relaunched as the lone leader to make the Alpha Bay name be remembered as more than the marketplace that got busted and founder made out to have committed S-word, in his own words.
This time, however, the site would not compromise on security.
One of the reasons Cazes was caught was through Bitcoin blockchain analysis, but now the site only
accepted Monero, another cryptocurrency network, which the same hack would be almost impossible to
replicate on.
In an interview with Wired, he detailed his security practices.
He runs an Aminusack operating system which wipes all data on reboot.
Furthermore, he claims to not store any incriminating data on hard drives and has a USB kill
which would wipe his computer's memory in seconds. He shuts it down every time his PC leaves his
site, even for bathroom breaks. In his own words, biggest issue is that regard is the human needs.
I would say that is the biggest inconvenience. You make sacrifices, though once you get used to it,
it becomes second nature. While Kazas made plans to go to a non-extradition country,
the snake actually managed it and says that he is located in the former USSR. Alpha Bay always had ties to
Russia, its rules had always banned the sale of data stolen from victims from former USSR countries,
which is a common practice among Russian hackers to prevent scrutiny. Now, DeSnake implemented a blanket
ban on discussion on USSR countries such as Russia, Belarus, Kazakhstan, Armenia, etc.
Still, DeSnick says he has traveled to several continents in the last four years and was living
freely all because of him always being technically ahead of the law. It didn't live up to its former glory,
however, with only 500 listings in the beginning of its relaunch. But it does have a few flashy
new features, mainly AlphaGuard. Disney claims that it lets its users withdraw their funds even if
Alva Bay went offline as it automatically rents and sets up new servers if Alfa Bay is detected
as being offline. This way, customers can be sure that they won't lose any money. A new I-2P
Mirror was launched, which is a project designed to be a fully encrypted private network layer
and his fortifications aren't fully built yet, apparently.
He plans to make a fully decentralized marketplace with no singular point of failure
where he plans to host Alpha Bay.
The community is more skeptical, however,
such as a threat on a majority Russian forum,
XSS, where many users are distrustful of Disnake.
It's fake and 99% sure and feds opening it again.
One commenter wrote,
Disnake's utopian vision didn't last long.
In January 2023, the site went offline.
This wasn't unusual, and the site was supposed to come back shortly.
However, time stretched on and there was nothing.
The snake was radio silence.
A month later, one of the Alpha Bay admins posted a message on Reddit,
going by the handle Alpha Bay the Cypriot.
They claimed that it was not law enforcement.
The signs were just not there.
Instead, it was partially shut down because one of the canaries used by the site was not signed on time.
A canary is a way to tell users that a website may have been compromised.
It requires the administrator to regularly sign a public message containing some independently
verifiable information with their key.
If it is not updated, it may indicate a security breach.
The Snake, as part of his moat, implemented this directly into the security.
It would basically initiate a lockdown on the market because the Snake had not signed it with
his key for a month.
This was not the first time this happened either.
Similar incidents had occurred previously, but the site had always come back.
This time, though, it looked like it was gone for good.
So where was the snake?
One theory that makes more sense is that he was a casualty of the Turkey-Syria earthquake.
He did say that he lived in a non-extradition country and had some strong links to Russia.
Syria is mostly under the control of the Syrian Arab Republic, which is backed by Russia and Iran.
24,000 Syrians died in the devastating earthquake, and a snake could very well have been one of them.
However, there is no concrete proof, and what really happened to a snake remains a mystery, just as he would have wanted to be.
Cannibal Cafe
Everyone has their unique tastes, but most of the time they're legal, and while weird, are usually harmless.
But there's a disgusting group of people out there whose interests and hobbies are borderline psychotic.
Started in 1994 by Peroloco, Cannibal Cafe was a website for, well, cannibals.
Loco was well known in these dark corners of the internet and was hailed as somewhat of a celebrity,
popularizing a quote-unquote artist who would depict Bollich and cannibalism in his art.
This artist went by the pseudonym Dalslet.
While it was just a moniker, the word Dalsit is defined as a pretty terrible kick.
It's a fash about some well disgusting stuff, and I'll leave it at that.
Loco would continue posting and popularizing Dalsit's work, and after a while,
Dalsit gave him full permission to post it online and was pleased that he was getting the free promotion.
This is what prompted Loco to create the Cannibal Cafe.
It lasted for eight years before it was shut down by a distributed denial of service attack by German authorities.
In those eight years, however, it managed to produce some of the most gruesome stories of documented
cannibalism ever.
And this would range from people signing themselves up as livestock to Loco killing and eating an entire human being.
The website would feature a gruesome livestock marketplace, which was constantly filled with individuals, both men and women, looking to eat or be eaten.
People would apply to be livestock and go through training.
You can use your imagination as to what the training might have been.
They would call these people who signed up to be livestock as cows, and it was outlined in the subhead of the webpage that there is no limitation of the intended or actual use of any of our cows.
But should any leased livestock be terminated during the lease period,
you'll be invoice for the full purchase price.
I'd rather not find out what some people did with their purchased livestock,
but it only gets worse from here.
Chelsea Loco, Paroloco's supposed daughter, was on the website,
and the description is, well, horrifying.
Daddy, I'm ready.
Hope I taste as good as mom.
And then it goes on to describe her height, weight,
and some general descriptions of her body parts,
and I'll leave that out, but it's just horrifying.
Another livestock listing was Cowtina, who supposedly engaged in S-word and her meat was up for sale.
Cannibal Cafe wasn't only for genuine savages who wanted to own and sell humans to eat or do even worse things with, but it had several other branches.
Stuff shows are adult videos which involve murder as a form of, I guess, fun video for some people, you know, psychopaths.
Let's get into the disclaimer.
Our websites are subscription or pay-per-view entertainment for adult audiences only.
Our sites contain nudity and simulated violence intended purely as fantasy entertainment.
We do not encourage nor condone real-life violence against others.
There is no pornography at these sites, and no one is actually hurt during the making of our photo stories and videos.
It linked to several other websites, which would contain videos of men, but mostly women in other
adult videos. Despite the very convincing disclaimer, the videos on the sites were real, with real
women and men taking part in these heinous acts. The website encouraged heavy participation of
viewers, that being through one of two ways. The first being a guest book where users would sign,
leaving recommendations, opinions, or really whatever they felt like saying. This guest book had a
concerning amount of sign-ons, each with increasingly concerning messages. Great site.
Looking forward to see more ESP, more cows from Europe available for different slater.
Wish more wild stuff went on there.
Hope that this site rolls for you.
Hey, looks nice so far.
Can't wait for the human livestock to be bred and cattled.
Right from the start.
The Cannibal Cafe also hosted a message board,
which is what would lead to its eventual shutdown.
But what brought this site to the attention of the authorities was the Mewis Juergen case.
A user of Cannibal Cafe, Armin Mewis,
had started talking to another user on the website.
44-year-old burned Yergen Brandeis,
who lived 250 miles away from Armin.
They started talking after Armin responded to an ad posted by Brandeis
on the Cannibal Cafe message board,
who was looking for someone to eat him alive.
On March 9, 2001, Armin brought Yergan home
and had sex with him before killing him.
While Brandeis did consent to this,
it's still very illegal.
The following events were recorded.
on a video camera. And of course, I can't show any of this on YouTube since it is way,
way, way too disturbing. Maywees performed a series of disturbing in illegal acts on Brandeis,
which involved severe bodily harm. Brandies had taken medication beforehand to help with the pain.
Warning, the following details are still very graphic and unsettling. Viewer description is strongly
advised, and if you have a weak stomach, please skip to the time stamp on screen. Following these initial
acts the two prepared and shared a meal involving Brandeis's body. Brandeis later requested to be left
to pass peacefully, succumbing to his injuries overnight. His final words were reportedly,
I have to piss, before he collapsed. In the months that followed, Moise continued to consume parts
of Brandeis before being arrested in December 2001. He was initially charged with manslaughter,
but after a retrial in 2006, he was convicted of murder and disturbing the peace of the dead.
So that was a YouTube-friendly description of what happened that day.
Maywee is currently serving life in prison.
Paraloko is still out there, the creator of Cannibal Cafe.
After posting an announcement on the message board reading,
I am in the process of putting up an all-new website, which is called...
And the site is dedicated to the concept that there are real doll-set girls
and we are going to explore our darkest desires, or at least I am.
And you're welcome to join me for the fun.
One thing in particular that I'm going to do is set up a photographic diary or logbook, if you will,
following the progression of our doll set girls from the relative innocent submissive through training
as the ultimate submissive to cattle status and ultimately to meet on the table.
In addition, the site will feature my entire collection of doll set art and doll set style art as well as photographs,
both real and Memorex.
We already have at least one real doll set girl and, of course, are looking for more.
I'm sorry that I haven't been keeping up on the posts here in this forum.
I'll try and do better.
I'm wondering if Terry is interested in becoming a real Dalset girl,
since I know that most of you would love to see photos of her training in what follows.
By the way, the best way to reach me is always via email.
I can be reached through either of my addresses, which are,
thanks for your attention, parolocal.
This website is still up and running, the one that he recently created,
but I will not say it and don't go looking for it.
Big disclaimer, do not go looking for this website.
This is still an active forum site and has a very extensive registration agreement.
The agreement does have some interesting and concerning aspects to it, though.
The first paragraph says this.
You agree through your use of this form that you will not post any material which is false, defamatory, inaccurate, abusive, vulgar, hateful, harassing, obscene, profane,
state-oriented, threatening, invasive of a person's privacy, adult material, or otherwise
in violation of any international or United States federal law. The website will force you to provide
your legal legitimate information. After you register and log into this forum, you'll be able to
fill out a detailed profile. It is your responsibility to present clean and accurate information.
Any information the forum owner or staff determines to be inaccurate or vulgar in nature will be removed
with or without prior notice.
Appropriate sanctions may be applicable.
And if for any reason, they're finally caught,
they politely inform you that they will outright leak your personal information.
You remain solely responsible for the content of your posted messages.
Furthermore, you agree to edemify and hold harmless the owners of this forum.
Any related websites to this forum, its staff, and its subsidiaries.
The owners of this forum also resolves the right to reveal your identity.
or any other related information collected on this service, in the events of the formal
complaint or legal action arising from any situation caused by your use of this forum.
So it's very clear why I haven't decided to probe deeper.
Please note that with each post, your IP address is recorded in the event that you need
to be banned from this forum or your ISP contacted.
This will only happen in the event of a major violation of this agreement.
Also note that the software places a cookie, a text file containing bits of information such as your username and password in your browser's cache.
That is only used to keep your logged in slash out.
The software does not collect or send any other information to your computer.
Now, I don't know about you, but I'm having a hard time trusting that, especially after seeing what these guys get into.
There's two options once you've signed your rights away, one being that you're above the age 18 and that you accept
the terms or that you're younger than 18. In most cases, a button which says that you're younger than
18 and accepted terms will probably kick you off the website. But with this, who knows what it does?
The website was insanely popular all the way up until 2011, where it was reported that it received
over one million visits each month, with even a U.S. congressman being an active user. The average user
age was around 40, and the website was under constant scrutiny by the FBI, with local
himself having been hauled into questioning numerous times. Paroloco believes he's doing no harm by
encouraging these activities, believing that consenting adults should be able to do whatever they want,
even if that involves killing each other. Except this doesn't reflect on the issues where there are
young, impressionable children and teenagers who may stumble upon these sites and grow up with a
deeply sick and twisted worldview. In the Maywee's case, it was reported that his fetches came upon him
as a result of his twisted upbringing paired with his environment at the time.
He grew up with a psychotic mother who had heavy, misandrous views, making him
Mayweese dependent on her completely.
It would go as far as her accompanying and practically chaperoning him to dates and even work
trips.
She would guilt-trip him, humiliate him, and her psychoticness was further solidified by the
fact that both her ex-husbands left due to mental cruelty.
Maywees' cannibalism f*** developed during his adolescence, after he was introduced to
home-slaughtering of cattle, poultry,
hogs and dears, and being taught how to gut small animals like rabbits since he was just six years old.
In most cases, this would have led to anyone else turning into a well-adjusted and
equipped an individual with strong survival skills and a pretty fun and cool childhood.
But due to his upbringing being so lonely and in early exposure to the internet,
it led to him murdering a man instead.
Consent or not, murder is still murder.
Dark web organ trade rings.
They call it a market.
as if human bodies were inventory in a shop.
Behind layers on the dark web and a veneer of legitimacy,
the dark web organ trade runs on hospitals that won't ask questions,
middlemen who smooth over the paperwork,
and buyers desperate enough to risk the force of the law.
The blatant objectification of humans into numbers
allows heinous organ sales to flourish.
On these forums, brokers,
Anonymously list kidneys, livers, hearts, and other body parts, using Bitcoin to hide from the banks.
The Dark Web essentially runs a auction house for human organs.
Undercover journalists and agencies have confirmed that the illicit organ trade thrives online.
These groups span the globe, connecting suffering refugees, willing to do anything to survive with wealthy patients,
also willing to do anything to survive.
This issue is further exaggerated by the legal retailers.
For example, one Florida Clinic, Active Science Parts International,
actually lists human lungs for $40,000 and hearts for $85,000,
all on the clear web.
While they pretend to operate secretly,
they all contribute to the same shady underground,
often linking to hidden network brokers, effectively bridging to the dark web.
Most of the actual trade happens on encrypted chat apps such as Telegram.
Newsweek infiltrated some of these channels built around organ sales,
one called Kidney Organ for Sale USA, is run by a self-proclaimed California doctor
who claims to have a network of 20 surgeons worldwide.
For the satisfaction of the customers, he apparently uses machines to preserve organs for shipments
and even boasted about the millions of dollars in cryptocurrency he made from these deals.
Other groups have list price menus like they're a bougie restaurant,
and another style themselves like a mall calling itself the largest shopping center for kidney, liver, bone marrow,
and advertising entire transplant packages.
The utter lack of respect for the poor humans selling their body in desperation is truly disgusting.
But clearly these doctors lack empathy and have no qualms about exploiting the anguished.
Newsweek found forum posts from sellers who lost everything.
I want to sell my kidney because I need money.
Explaining, when you are dying due to hunger, everything is legal.
One of the most chilling examples is of Fabian Hildenbrand, a German man who came so close to becoming a part of this horror.
Hildenbrand was an apprentice graphic designer, struggling to pay the bills and support his girlfriend at the same time.
Exhausted and feeling cornered by life, he desperately needed to find a way out of it.
So he turned to the dark web.
Initially, he just browsed randomly.
He found normal sites, privacy enthusiasts and programmers.
Then he hit the dark side, human trafficking, organ sales, and hitmen.
He thought they were fake until he began to realize the harsh reality.
Reaching a breaking point, he actually offered to sell one of his own kidneys
and posted an ad on one of the many sites advertising medical exchanges.
Within days, he received an offer.
From a middleman.
He offered him 90,000 euros.
Life changing money for him.
It looked like the answer to him.
But the more he spoke to him, the more he grew wary.
The man refused to reveal any identity and insisted on total secrecy.
Eventually, he shook himself off.
He stopped replying to the kidney body.
and grounded himself again, thanks to support from his friends and family.
The underground organ trade is a massive industry.
Experts estimate that over a billion dollars of revenue is generated annually.
Even in poorer countries, organs can fetch thousands of dollars, which is life-changing money for some.
Despite the scale of the issue, catching these traders is notoriously deadly.
difficult. Advertising transplants is obviously illegal, but as you should know by now, policing
the entire internet is hard. They operate in thousands of channels, and just like the Silk Road
and all the other drug markets on the dark web, when police take one down, another pops up
in its place. To avoid detection, traffickers on the dark web use bizarre codes. Chat groups have
rules. No direct mention of transplant or organ is allowed. Instead, they use hints and symbols.
For example, one group used color-coded heart emojis in place of words. Furthermore, law enforcement
is overwhelmingly focused on terror and narcotics, so organ rings often slip under the radar.
A number of initiatives target this underground economy, such as tip line, specifically for organ trafficking.
Some tech firms are developing crawlers to comb onion sites for phrases like kidney for sale.
The dark net organ rings show how technology can turn human despair into currency.
The people selling their organs are rarely criminals.
Usually they're victims of poverty, war, and hopelessness.
Behind those words are parents trying to feed their children.
Refugees trying to escape or students drowning in death.
The horror isn't only in the surgeries.
It's in the quiet normalization of it.
The dark web has erased the line between humanity and currency.
We think of the internet as a tool for good, something for connection, learning, and fun.
And it mostly is.
It has helped countless people to do countless things, and without it, the world would be a very different place.
But every invention casts a shadow.
The dark web is that shadow.
shadow. Anonymity is a right of the people, but here it is used as a sanctuary for the
unspeakable. It's not the technology that's horrifying, it's the people using it. For every victim
identified, there are a hundred more that vanish without a trace. Somewhere, someone is logged on
scrolling through horrors that should not exist. And most of us will never see it, and that's for the
best because when you see things that the light doesn't touch, you never really come back.
Boys Town
We've covered a lot of stories on this channel about different dark web websites that host illegal content involving minors.
On one hand, telling these stories is important.
With crimes like these, it's important that disgusting criminals who direct their sick
desires on children aren't allowed to hide in the dark.
They need to be exposed and their crimes talked about to,
ensure that future generations are protected.
And on the other hand,
none of these stories I've covered
are as casually despicable,
disheartening,
and downright horrifying
as the one I'm about
to cover now. So if this kind
of content is too much for you,
please feel free to skip ahead
to the next topic. Because
we're about to cover, Boys Town.
June, 2019.
A German website launches
on the Tor browser.
registered in Moldova.
It's built like a video sharing platform, but with multiple different forums.
Over the next year, it amassed a following of dedicated users, all of them sharing illegal content involving children.
The site encourages original uploads, a mix of never-before-seeing content and videos that had been circulating for years.
In order to get access to the site, you had to become a member.
The details of this part are obscure, but,
It involves paying a fee in some regard and a thorough vetting process.
Oftentimes, people would meet on the surface web.
We've talked about it before.
Secret illegal content involving minors circulating around the internet.
Maybe it's an Instagram page dedicated to Barbies with odd captions and cryptic messaging.
Maybe it's a video of a middle school swim club posted by a mother with a comment that reads telegram.
Disgusting stuff.
Regardless, people meet communities on the surface web and are introduced to the dark web once they're trusted.
This is when they're introduced to Boys Town.
Boys Town is a community center living beneath the surface web, hiding in the shadows of the Tor browser.
In this community, like-minded people can share their like-minded interests.
It had two chat rooms, L-O-L-I pub and
and Boys Pub.
And I know I didn't have to spell it the first one,
but for guideline reasons I had to.
And they share images,
talk about their favorite boys,
explore each other's perversions,
and when all is said and done,
they comfort each other,
encourage each other to continue indulging
in their disgusting fantasies
and continue consuming.
I like this quote by Dr. Nancy Falkner,
CEO of Safeguard,
are children, United Mothers.
Quote,
computer technology and the internet enables
people who commit crimes against children
to locate and interact with other deviant
criminals more readily than ever
before. The long-term
organizational aspects are terrifying.
The common gathering place and the
results in support they are providing each
other is probably their most significant
advantage and the most
troublesome for a concerned
public. The computer,
a common household fixture,
is now a place where disturbed, perverted criminals can go to hear others say,
you're okay and what you're doing is okay.
Don't listen to the rest of the world.
Just listen to us.
As the site survived for a year, then two, then three,
it began to evolve from a community forum and the video sharing aspect became more thorough and insidious.
And just like Dr. Faulkner said,
they began to organize.
Site administrators created categories, art, kindergarten, toddler, spy cam, and there's more,
but just honestly, too disgusting to even mention.
These categories were all dedicated to the exploitation of boys below the age of adolescents.
And this is beyond horrible in and of itself.
It's disgusting, unbelievably disturbing, and cruel, but
it didn't just stop at categories.
Criminals needed to fill these categories with videos.
And how did they do that?
Well, they created their own videos.
This wasn't like other dark web websites we've talked about before.
This was a community of people producing and distributing illegal content involving minors.
Some of it was recycled content, but most of it wasn't.
I mean, it's already horrifying enough.
that people watch these videos,
but they're producing it and then sharing it,
it just takes it to another level.
And they were scouting on the surface web,
day and night,
looking for others just like them,
and looking for minors to commit crimes against.
The site administrators and communication with their many users
recommended ways to avoid law enforcement
and continue consuming illegal content
without getting caught.
Never use your real name.
Always use a VPN.
Keep everything password protected.
Only communicate with other criminals,
with just a few of the rules that they stuck by.
As of May 2021,
two years after launching,
Boys Town was considered one of the largest online platforms
for the distribution of illegal content involving minors
with 400,000 registered users.
And just for reference, that's only a little less than the population of Tampa, Florida.
In underground, dark web city of people who prey on the week, sharing thousands upon thousands of videos.
And unlike any other dark net site we've talked about, all of these people were in tight, coordinated communication.
Quote, age is not the consideration, but the maturity level is.
I've met some 14-year-olds that were more mature than some people in their 20s.
Everyone is different and some people are ready sooner.
Which is just disgusting.
Even though Boys Town had gone to extreme lengths to hide their community from authorities,
they still garnered unwanted attention.
And before long, they caught the eye of the German police.
German operatives, in coordination with Interpol, infiltrated the site,
pretending to be one of their community members,
which I imagine was both terrible and exhausting.
They cataloged the big contributors,
who was providing the most photos,
who was the most active in the community,
and who was organizing their massive following.
With this information,
they began to suss out the administrators,
the people responsible for creating the insidious Boys Town.
But for some unknown reason,
the site was more difficult to crack down on
than other similar sites on Tor.
The Boys Town defenses were strong.
Their cyber footprint was almost completely clean,
and the security was very, very well developed.
Someone had spent a lot of time ensuring that the users of Boys Town
and its administrators would never be caught.
But the investigators were clever.
You see, most people think Tor is completely anonymous,
Anyone or anything you put on the Tor browser will be hidden, and you in turn will be untraceable.
And the first part of that is true. Things will be hidden on Tor, but what is hidden can ultimately be found.
It isn't easy tracking someone down on Tor, but it can be done.
And here's how the German police did it.
Basically, Tor has a series of checkpoints for sending encrypted data.
These are called nodes.
When you send or receive messages, a particular series of nodes will activate.
Think of it like ripples on a pond.
Well, German police would send a message of a certain size.
It would create ripples on certain nodes, and they'd crack each one for a ripple of that same size.
The nodes that received their characteristic ripple acted like breadcrumbs to what's known as an entry node.
In other words, once they found the...
entry node, they found their suspects. And by the end of the investigation, they had information
on four administrators they wanted to prosecute. Now, we don't know their real names. German privacy
laws and modern investigations prevent law enforcement from sharing their names, but we do
have their descriptions. A 40-year-old man from Paterborn, a 49-year-old man from Munich,
a 58-year-old man from North Germany, then living in Paraguay.
These were the administrators, the organizers of the insidious Boys Town,
and a fourth suspect, a 64-year-old man from Hamburg,
who was one of the largest contributors of illegal content on the site,
uploading over 3,500 videos.
And that to me is just beyond ridiculous.
That is so many videos.
In April of 2021, the site was seized by Interpol, and all of these suspects were arrested.
The man living in Paraguay was later extradited by Germany for trial.
And normally, that would have been the end of it.
These disgusting men see prison time.
The side is shut down, and that's that.
But immediately, things were different about Boystown.
And by the way, most of the stuff I'm about to cover isn't widely talked about, and there isn't much detail.
But I think these next few details are of the utmost importance when it comes to discussing the terrifying ordeal that was Boys Town.
Firstly, the press and the public were excluded from the trial.
This isn't particularly unusual for German cases like this.
They often exclude the public in order to prevent retramatization of victims.
and in the case of highly disturbing material,
will refuse to let details circulate,
which on the surface isn't a bad take.
I can see wanting to protect victims.
I'm all for it.
But this wasn't consistent with similar cases.
Now, we don't know exactly what was on this website.
And frankly, I don't want to know.
But just for reference,
the trial of another huge illegal child content distributor,
the Elysium Dark Web website,
was also held in Germany.
And that trial was open to the public.
Just to give you a rundown of Elysium really quickly.
Elysium had 87,000 active users and had thousands of similar videos.
In that way, the two websites were very similar.
So why was Boys Town privatized while Elysium wasn't?
Well, there's two options here.
Option number one, whatever was happening on the Boys Town website,
was much, much worse than we could possibly imagine.
I won't even speculate on what that could be,
but to warrant a public exclusion,
it would have to be very, very bad.
But more details surfaced that made their exclusion seem
a bit more intentional and a lot more suspicious.
You see, the suspected administrators and content creator
of Boys Town were interrogated,
and what information they did give was incredibly damning.
You see, they claimed that,
one of the members of their inner circle responsible for managing the website was a high-ranking
employee in a German security agency. Allegedly this man on behalf of the German government
was responsible for regularly, quote, checking the security of certain processes. Whatever that
means, I have no idea, but allegedly he was a useful government agent. And remember how I said
Boys Town was very difficult to crack. It had very, very good security. Well, according to the
arrested suspects, this man was also responsible for creating Boys Town security and optimizing
their programming scripts. So option two. And this is just an allegation proposed by the four
men on trial. So take it with a grain of salt. There was someone in the German government
who helped create Boys Town. A high high
ranking government official and trying to avoid scandal, they privatize the trials.
No jury of peers, nothing. Whether that's true or not, we won't know anytime soon.
But the implication is tremendous. And it might explain why the government didn't want the public
present at the trial. It might be the case that there was a complete government cover-up
in defense of a sickeny man who worked for their own government.
Again, this is just an option and based on supposed information, but I still think it's valuable to talk about.
Even if it's a possibility, I'd rather discuss it because if it is true, that's just despicable.
After the completely inaccessible trial had finished, the four men were served sentences of 12 years, 10 and a half years, 8 years, and 7 years in prison.
And once again, as I seem to say every single time I cover this sort of topic, this is not enough time spent rotting in jail.
12 years, 10 years, 8 years, and 7 years? That's ridiculous.
These people should never, ever be free under any circumstances.
It never ceases to amaze me how there are people who have committed tax evasion that are serving more time than actual goddamn monsters who consistently,
and continuously commit crimes against children.
Once again, I am left stunned, angry and disappointed in our global governments
for not protecting the most innocent, defenseless demographic on earth.
It disgusts me to no end.
And we're still not done.
You see, I said when we started this story that Boys Town was different, and I wasn't
lying.
After the government was shut down, government agencies expected it to die silently.
But unfortunately, they were dead wrong.
Just hours after the Boys Town shut down, an unknown user posted a dump of Boys Town online, back on the dark web, for anyone to access.
And now what does that mean?
Well, it means that not only was Boys Town not dead, someone had secured the entire site.
All of its data, all of its user information, and stored it just in case of a shutdown.
And what's worse, the actual German government had no intention of wiping any of that information.
None of the videos, none of the chat logs.
They weren't interested in protecting these children or their identities or even stopping the consumption.
They were only interested in getting the arrests, which, again, the public was excused.
excluded from and moving on.
It was actually a small group of journalists working for the popular German media company Funk
who went in guerrilla style and wiped 13.5 terabytes of data across various file hosting sites.
They actually have a YouTube channel called STRG underscore F, which, given their heroic choice
to help remove this system content from the internet, I think it deserves a shout out.
And just to give you a reference, 13.5.
terabytes of information is about 1,500 hours worth of YouTube videos on average.
You could watch my channel 10 times over, every single video on my channel 10 times over,
and that's almost the amount of data they deleted.
The funk journalists commented on the malpractice of their government,
stating that the German police were, quote,
only interested in hard drives of perpetrators,
but not removing offending material from the internet.
And you'd think Boys Town would lay down and find,
finally die already. But unfortunately, it proved to be something of a hydra. When you cut off one head,
two more take its place. We know that three successor websites were shut down on Christmas of 2022,
and all of them had the same admin, a remaining member of the inner circle of Boys Town. Another
three administrators were arrested the same year, and the German police secured, according to their
statements, hundreds of thousands of images. I think this.
This problem stems from what Boys Town represented.
It's sick, twisted, disgusting mission statement.
This wasn't your typical website for illegal content involving minors.
It was a dedicated community of despicable people,
treating their crimes and offenses like unwanted taboos
rather than the malignant cancer they are in our society.
A community creates longevity.
We saw this when I covered Nambla.
couple of months back. When these people get together and start discussing how they aren't monsters,
we see these crimes not only escalate but permeate. They linger in the shadowy cracks beneath
genuine websites, hunting children and acting like it's normal. And when they retreat to the
dark web, it just gets worse and worse. They're like roaches. And that's why I think it's so
important to cover these type of topics. It's incredibly difficult to talk about these stories.
It genuinely breaks my heart, and it's more than just disturbing. But in my opinion, it's our job
to talk about these issues. Secrets keep them safe. A lack of information that keeps these
people out of jail. Or like always, they're given ridiculously short sentences. We see it
time and time again. And for that reason, we need to discuss these issues.
and keep discussing them
because the crimes I've described here
aren't a foreign issue.
It's happening all around us
every day in our online and offline communities.
The fact a YouTube channel
had to seek out and delete
all of that data from Boys Town
simply because the government refused to do so
is actually so incredibly disheartening.
We need to continue to expose the people
who are responsible for these.
horrible crimes, and maybe, just maybe, we can protect the people who are the most vulnerable,
the ones who are unable to defend themselves.
Cracked, nulled, Cellix, and Stark RDP.
Do you need crack software, hacked accounts, tools to take down a website?
Well, for years, sites like cracked, nold, Seleks, and Stark RDP,
where they go-to hubs for online crime, running wild in plain sight.
although on January 29th, 2025, they disappeared.
Operation Talent, a massive international sting led by the FBI and Europol, shut them down
overnight.
Raids, arrests, and millions in damage.
Here's how it went down.
Operation Talent was a multi-state operation involving serious coordination and efforts
between multiple global law enforcement agencies of several different countries,
namely the United States, Romania, Australia, France,
Germany, Spain, Italy, and Greece.
This operation, like I said, was targeted on the following sites,
Cracked, Nulled, SELICS, and StarkRDP.
These sites specialized in providing users with crack software,
such as Adobe products or video games,
as well as selling information and illegal cybercrime services.
These services could be anything from OnlyFans leaks
to even taking down entire websites, doxing people,
and it could even go as far as blowing up routers.
These cyber criminals from all around the world would advertise their services,
where they'd provide people with OnlyFans leaks for free,
or even paid at times, paid high-balanced PayPal accounts, etc.
These sites operated for years without being caught.
That was until the 29th of January, 2025.
The following banner was uploaded on all of these sites.
This banner, as fake as it looks, is completely real.
The operation resulted in the following.
Two people were arrested in Spain.
Seven different properties were searched.
17 servers were seized.
50 different electronic devices were seized,
and over 300,000 euros were seized in cash in crypto.
According to seizure warrants unsealed today,
the cracked marketplace has been selling stolen logging credentials,
hacking tools,
and servers for hosting malware and stolen data,
as well as other tools for carrying out cybercrime and fraud
since March 2018. Cracked had over 4 million users, listed over 28 million post-advertising
in cybercrime tools and stolen information, generated approximately $4 million in revenue,
and impacted at least 17 million victims from the United States. One product advertised on
Cracked offered access to billions of leaked websites, allowing users to search for stolen
logging credentials. This product was recently allegedly used to sex stort and harassed a woman
in the Western District of New York.
Specifically, a cyber criminal
entered the victim's username into the tool
and obtained the victim's credentials
for an online account.
Using the victim's credentials,
the subject then cyberstocked the victim
and sent demeaning and threatening messages
to the victim.
The FBI.
Nold had been in operation since 2016
and had over 5 million active users.
It had advertised several cybercrime tools,
stolen login details,
stolen IDs, detailed guides on fraud,
and much, much more. The site saw over $1 million in yearly revenue, with one ad claiming to have
the names and social security numbers of over half a million American citizens. The site operated on the
ClearNet, but on several other channels such as Telegram, where the staff had confirmed the
takedown moments after it had happened. They claimed it was a sad day indeed for our community.
Saan, an active admin of the site had been arrested, alleged to have performed escrow functions
on the site and that his services would be used to complete transactions which involved stolen
ID and credentials.
He's been charged with conspiracy to traffic and passwords and information, conspiracy to solicit
another person for the purpose of offering an access device or selling information regarding
an access device and conspiracy to possess, transfer, or use a means of identification of
another person with the intent to commit or to aid and abet or in connection with an unlawful
activity that is a violation of federal law. Put simply, he's in a shitload of trouble if convicted,
facing up to 30 years in prison for all his charges. Some users online, however, believed these
takedowns never stick, speculating that the domains are already back up somewhere else.
Rip, I'm sure they will be back up within the week on new domains, or sometimes even the same
domain. Yeah, this or it just means it's some other sites turn. These takedowns are kind of useless,
LOL. Some others, however, believe that these hacking forms were simply just scams.
Me, in a way, hacking forms have been basically dead for years. A new one will come and continue
to just be a scam, like these were, all scams. But according to the FBI, this takedown
did make a huge impact. Russian Anonymous Marketplace
Silk Road has had many successors, but none have had the longevity of ramp, also known as
Russian anonymous marketplace. Inspired by the Silk Road's model of anonymous cryptocurrency-based
e-commerce, it was a marketplace used to sell substances. It offered one of the widest variety of
narcotics on the entire dark web, but with one key difference. It only served Russian-speaking
clientele. After the OG marketplace of the Silk Road was shut down, many clones popped up and were
quickly shut down by authorities. The biggest of them, Silk Road 2, lasted exactly one year to the day
after Silk Road got shut down.
For comparison, Ramp lasted nearly five years from September 2012 when it was launched until
July 2017.
It was actually less of an eBay-style marketplace and more of a Craiglist forum where buyers
and sellers would find one another.
Then, once a connection has been made, most users leave the forum and go to the other
sites such as Off-the-Record to finalize the deal.
Off-the-record messaging is a cryptographic protocol that is basically an encrypted
fully secure version of the instant messaging apps we use today.
It provides something known as deniable authentication.
In short, that means that the people communicating can be sure of who the person is
while messaging them, but it cannot later be revealed to another third party.
In this case, police.
While Ramp does provide an escrow system similar to Silk Road,
most sellers and buyers prefer to use off-the-record messaging
and then pay in Bitcoin or with the Russian Payment Service, QIWI.
Sellers are known to be very cautious on the site, triple stealing the substances or even going
as far as to delivering them to a dead drop where the buyer can go pick it up from.
Buyers can also leave reviews on the seller's pages, with one particularly happy seller
leaving the follower view on a seller's page.
In the nose, it is without foreign flavor and is not bitter and scent, and it does not burn.
So how do people at ramp make money?
Simply, they charge the top buyers a certain fee for their own private sections on the forums,
$300 a month.
For another $700 a month, you can pay for your very own banner advertising your product.
And if you are really serious about this and you want to sell some of the most potent substances
to the extremely demanding Moscow market, you have to pay $1,000 a month in order to sell
from their restricted quota list.
The site administrator, also known as Darkside, agreed to an interview with Wired, conducted
on Ramp's very own private messaging system on tour.
Darkside stays completely anonymous,
not even revealing his gender and his location,
set as a galaxy far far away.
He does apparently speak good English though
and share details in the above.
He claimed that it made over $250,000 a year,
but compared to its predecessors,
that is much less,
but also compared to its predecessors,
it stayed up much longer.
According to Darkside,
six figures is just a regular income
in the local area he stays in, wherever that is.
He says,
I can be perhaps considered a rich guy for a local,
though you can't live well on your legal salary here.
We ain't dollar millionaires,
just upper middle class guys who do their job and feed their families.
He is also supposedly planning to expand the site
to include a payment system like Silk Road had
or even cater to the English audience,
like similar sites did at the time.
So how did it survive so long
when during that time,
a Silk Road clone would be seized every,
other week. It may simply be that the Western authorities didn't want to target it. It caters mainly
to a Russian audience and is also speculated to be hosted in Russia, where authorities usually turn
a blind eye to online crime. In Darkside's own words, we never mess with the CIA. We work only
for Russians, and this keeps us safe. We can't the whole world and remain safe. The site is also
extremely primitive because it doesn't have its own payment system or any complex features.
so it is hard to hack. Ramp also focuses exclusively on substances, banning the sale of weapons,
stolen credit cards, counterfeit documents, and even legal, which is much more restrictive than similar
sites. It also did not tolerate any political discussion at all. Darkside said that the politics
attract extra attention and that they did not want that at all. While it did suffer from frequent
DDoS attacks, it would always come back up until July 2017 when Russian police confirmed the news.
They had officially shut down the largest remaining dark net market.
In the same month, two other online substance markets similar to Ramp, Alpha Bay and Hansa
also went down.
Even though many believe that law enforcement ignored ramp, that was apparently not the case
as Russian authorities released the following statement to a Russian news agency.
As a result of the activities carried out in July 2017, the largest Russian language trading platform ramp, Russian Anonymous Marketplace, the largest in the Russian language segment, was terminated.
The MVD has permanently implemented a set of measures aimed at identifying and suppressing the activities of members of criminal groups engaged in the distribution of synthetic substances, potent substances, and precursors in a non-contact way using the internet.
The main efforts are aimed at suppression of substance supply channels and elimination of organized groups and criminal communities engaged in their sale.
Pink, and I can't say the other word because of YouTube's guidelines.
So pink crystal.
Think about the breaking bad substance they cooked up.
So yeah, Pink Crystal.
In 2015, the world's biggest adult content website, you know the one, implemented a method for people to report revenge videos on their substance.
From that point on, if you came across some illicit content of yourself, which I imagine is horrifying,
one click will take it off the website.
But not every website is so inclined to help you.
In fact, some have made a business out of it.
Revenge videos became a prevalent problem in the early 2000s.
Before then, it wasn't unheard of.
Many people were caught sharing illicit photos of their exes, but the differences, these incidences were isolated,
often shared among close friends, which is gross to say, but that's like max 20 people.
Your standard loser didn't have the resources to humiliate their X on the macro.
But when the 2000s rolled around, people had more reach, social media, chat forums, emails, cell phones, and cell phone cameras.
Gone were the days of professional adult videos.
Now anyone could make one.
And worse, anyone.
could share it. Not with a couple of people, but with countless thousands. Now, with every bad
breakup loomed the possibility that private images or videos could be leaked onto the internet. And I hate
to say this, but there's a ton of people who couldn't care less about consent. In fact,
they enjoy non-consensual exposure. Now, thankfully, this stuff doesn't survive on the surface
web anymore. Most adult websites have safeguards in place to prevent it.
but the dark web has no such rules.
For the purposes of this video,
I can't say the actual name of the website,
so we'll refer to it as Pink Breaking Bad Crystal or Pink Crystal for short.
Pink Crystal was a website dedicated to Revenge Videos.
It was built in a similar way to 4chan,
designed as an image board,
where users could post illicit photos.
But like we just discussed,
none of these photos were posted consensually.
In fact, some of them weren't even acquired consensually.
I'm not sure of the actual details, but essentially, pink crystal users would hack into people's accounts and steal their intimate photos.
One example is a woman named Shelby.
I won't say her last name for privacy reasons who actually sued Pink Crystal.
She was a college student at the time, living in Texas and enjoying an uneventful life.
But her days of peace were about to come.
to an end. According to court documents, Pink Crystal somehow gained access to Shelby's private
photos, ones that had never been shared with anyone, and posted them. When Shelby found out,
she was horrified, obviously. She contacted the administrators to take it down, and they not only
refused, they harassed her. How you might ask, well, they had a Twitter page where they would
post about people who were being exposed. I'm not joking. These people were
demented. They would take
non-consensual videos,
post the links to Twitter, and then
tag the person's social media pages,
rallying their fan base to go
harass these women.
Shelby received death threats,
threats of assault,
and by the time she had discovered
the images, it was too late.
The damage was
done. Previously, she
had dreams of joining law enforcement.
Of her own omits,
the dream was made impossible,
by Pink Crystal. To make matters worse, the lawsuit failed. In similar cases, the defendant
often receives a settlement from the people who operate the website, and those people typically
receive jail time because revenge videos are criminal. But there was a problem with Pink Crystal.
No one knew who was operating it. To this day, no known person has ever been charged for the
indecency allowed on pink crystal.
When an official investigation began, they tried to track down the owners.
When they discovered that whoever was running it was functionally untraceable, domain registration,
admin accounts, operator records, all purposefully obscured.
How?
Well, the host company, Katz Global Media, offered a service to register untraceable domains.
Even they couldn't figure out who these people were.
After the attempted lawsuit, Pink Crystal was under heavy screwing knee.
Before then, they operated on the surface web.
But after a public backlash, the cowards retreated to the dark web to avoid a shutdown.
Now, normally, a shutdown wouldn't matter too much.
After all, they're just sick people looking for a rush, but Pink Crystal was different.
Pink Crystal was monetized.
Most of the time, these kinds of websites run banner ads and pop-ups.
So even though we don't know an exact figure, we can use similar websites like,
Is Anyone Up to approximate their earnings.
Is Anyone Up was a similar revenge video site, the first one to ever hit the mainstream.
And because of its shutdown in 2012, we know that the owner, Hunter Moore,
was making $13,000 a month on ad revenue alone.
For two more years, the site continued to torment its victims from the dark recesses of the internet
until 2014, when the FBI, inaction with Europol, successfully shut down Pink Crystal.
Over the years, the anonymous owners have attempted to relaunch the site to no avail.
Luckily, today, they are permanently offline.
The Iron Troll website has archived some Twitter posts.
All of the names and links have been redacted or are inactive.
But scrolling through, it's easy to see how horrible this website truly was.
I can only imagine the lasting impact it had on the people who were exposed.
And unfortunately, I'm sure there are other websites just like Pink Crystal.
Surviving Today.
Somewhere down deep in the dark web.
Base of Mafia.
The base mafia was, as you might expect, not your typical organized crime syndicate that
had unusually strong ties to Mediterranean countries. Instead, it was a new age assassination marketplace
hosted entirely online. Hitman were freely available for hire to carry out your dirty jobs
from maiming to kidnapping and of course murder. For the ambitious, you could even apply to be one.
Soon, however, the facade crumbled. Chris Montero, a systems administrator who runs IT security
for a firm in London is a digital vigilante,
working as an independent cybercrime researcher in the off-hours.
In 2016, he stumbled on the website, BASA Mafia,
and wrote a scathing critique on its blog, Pirates London,
claiming that it was a scam and exposing its many security flaws.
Reputation was very important to the owners of Baysa Mafia,
and the supposed site administrator, Eura, messaged him,
furious, imploring him to take it down and then attempting to bribe him.
Montero, of course, refused.
believing that it was an all-empty threat.
Eura seemingly wasn't all smoke, however.
A few days later, he sent to Montero a YouTube link of him sending a car on fire
holding a sign that said that it was dedicated to Pirate London, Montero's blog.
Now worried that maybe it was actually a genuine hitman marketplace,
Montero, along with an anonymous cyber cop going by the name of Judge Judy,
shut down the website entirely using a vulnerability that allowed him to see every order,
which he later leaked online to be picked up by the FBI.
Yura did not fall at this hurdle, though, and continued sending up similar sides with similarly
threatening names such as Sickolin Hitman and Azerbaijan Eagles, Camorah Hitman, and a host of others.
They all worked the same way, an aspiring criminal would set up an anonymous account,
select their desired job, and upload the details.
They would start a chat with Yura where he would coax them into trusting him and the Bitcoin would be sent over.
Now, some of you may have had the suspicion from the beginning,
that it was actually a scam, and there were no real murders looking for the
a job, and you would be right, of course.
Europe did not put much effort into making it believable either.
His English was poor and his knowledge of the U.S. geography even worse.
For example, one user ordered a hit on somebody in Hawaii.
You responded by saying that he had a hitman in the nearby state who could drive there
and do the job no problem.
For those unfamiliar with the United States, Hawaii is an island roughly 2,500 miles away
from the near state.
Not to mention that driving there would be very difficult with the Pacific Ocean between it
and the U.S. The user still paid $3,000. The site used stocked pictures of assassins and results from a
Google search for scary-looking hitman on its front page. It would be laughable, if not for the real
and despairing loss of lives that did actually occur due to this site. In February of 2016,
a username Dog Day God ordered a hit on a middle-aged woman posting. For reasons that are too
personal and it would give away my identity, I need this bitch dead, so please help me. The target was
Amy Alwine of Cottage Grove, Minnesota. She had a husband, Stefan, who worked as an IT professional,
and was also an elder in the United Church of God. They had an adopted teenage son.
Dog Day God transferred around $6,000 in Bitcoin to Yura, feeding him information on when
Amy would be alone in the house or places outside she would go where there would be no one else.
First, they discussed a hit and run. Dog Day God liked this idea, as it could be seen as an accident.
And then, Arson. You're promising him that it would be done soon.
But the hitman were failing, and he couldn't do anything about it.
Of course, there were no attempts at all, and Eura kept asking for more money after each supposed
failure, and Dog Day God grew angrier.
I do not care about date or method.
You have a picture and a dress, so you can tailor or do whatever you need to do to get the job
done.
One curious request, however, was that the husband and kid be left alone.
He claimed that the kid was a friend of their child, and he did not wish to see him
orphaned, a surprising amount of thought and empathy from someone who's planning to murder the
kid's mother. Thankfully, though, a couple months later, nobody was murdered and nothing came from
it. Another hacker by the name of BRSPD broke into the website and dumped all the chat logs online
in May of 2016. The FBI picked these up and alerted all the targeted victims. They hold Amy and
Stefan to bump up their security so they bought a home security system and a gun to protect themselves with.
Stefan shot aiming the head with the very same gun six months later.
Stefan was Dog Day God all this time.
Makes sense why in their quest he made it that the assassin shouldn't kill the husband or child.
The truth was that he had been having affairs through Ashley Madison,
which was a website for married or people in relationships to find other like-minded individuals to cheat with.
He could not divorce his wife because of his position in the church,
and so we took this drastic measure.
Before it all started, he took out a $700,000 life-endarmine.
insurance policy in his wife's name and have been sending her threats and pressuring her to end
her life online. He attempted to make it look like an S word. However, a police investigation revealed
that the Bitcoin signature of the payments he made with Eura recovered from the chat logs matched
the hard drive on his laptop, proof that it was in fact not a S word but a long planned murder.
Convicted of first-degree murder, he was sentenced to life in prison. Stefan is still serving out
a sentence to this day. The inhumanity of the users really showed when another order
orderers afield. Another user by the name of Agent Sy inquired about a possible hit on a 14-year-old.
It was no prank or some sort of morbid joke either, as the user actually transferred roughly
$18,500 to Euro. And so somewhere in New Jersey, a kid is walking around with a nearly
$20,000 bounty on his head. Another chat log revealed that a woman from Nevada ordered a hit
on her ex-husband and transferred 12 Bitcoin to base of mafia. She was arrested and sentenced to five
years in prison on the charge of a murder for higher plot. Thankfully, Basa Mafia was a scam
website, so the major loss from its creation was the Bitcoin wallets of criminals, but innocents
were still hurt or killed, as in the case of Amy Alwine. Hansa Sting.
If you remember, in one of my old videos, I covered Alpha Bay, which was basically a drug-selling
website and its downfall, in quite some detail. In the end, the FBI dismantledic
completely, but what many don't know is that there was more to this masterfully executed
trap than just a simple takedown. Just a single month prior to Alfa Bay's demise,
Dutch investigators seized a leading tour-based drug bazaar known as Hansa Market. Most importantly,
it was done in complete silence. It came from a single tip. A security company's researchers
believed that they found a Hansa server and a data center in the Netherlands.
Normally, the site was protected by Tor, which is the dark web, which would make it almost
impossible to trace, but this was a development server, one where they would test new updates
before publishing it to the users.
It was exposed to the public internet and the Dutch police latched onto it.
Immediately, they gained access and installed network monitoring equipment, which let them
spy on every message sent. They found that there was another server at the same location
that ran the live site and another pair in another data center, all three protected by Tor.
Still, even with a copy of the entire hard drive, including reports of every transaction and message,
Hansa should have been safe. All of the admins and visitors used pseudonyms, obviously,
and they couldn't track IP addresses normally, as it was all routed through the Tor network.
But there's a great quote from the IRA.
We have to be lucky once.
You have to be lucky always.
And the Dutch got lucky.
After going through the contents, they found an incredible slip-up.
There were IRC chat logs between the founders.
IRC is an antiquated messaging protocol made in the late 80s that isn't used much anymore.
More importantly, it wasn't encrypted, and they could read the conversation which went
back years. As you could guess by now, it included both of their full names and even one of their
home addresses. The pair were actually already under German police's radar for a much lesser crime,
however. They were being investigated for the creation of Lull, a site selling pirated e-books and
audiobooks. This provided a brilliant opportunity for the Dutch. They could use the existing
investigation for cover, letting the Germans take suspects for e-book piracy.
and take over Hansa all without anybody knowing.
Unfortunately, somehow the admins noticed something suspicious and moved their service locations.
Still, the Dutch did not give up.
For months, they examined the evidence, looking for any clues.
Their lucky break came when they found out that the admin had made a Bitcoin payment,
using an address that had been in those IRC chat logs.
Using advanced blockchain analysis, they traced the recipient to,
another hosting company in Lithuania.
Fortunately, both of them had a mutual legal assistance tree, so it was short work for them to gain access.
While all of this was happening, the FBI was also working hard.
Hellbent on taking down Alpha Bay.
When it eventually went dark, the drug traffickers panicked.
This was their business, and they needed a new place to sell.
If you couldn't figure it out by now, they would go to another marketplace.
one which was already well established and soon to be in Dutch police control.
With extremely precise timing, the German police raided the two men and took their hard drives,
unencrypted.
Meanwhile, the Dutch immediately began the migration of all of Hansa's data to a new set of police hardware.
Now they were in complete control.
The users, oblivious.
They kept logging in and kept trading all.
while handing over their data to Dutch authorities.
Meanwhile, the Dutch rewrote the site to betray even the most careful criminals,
such as changing the passwords into being stored as plain text, not encrypted hashes.
Basically, they read a book on information security and did the exact opposite.
All communications were logged, the encrypt button was now a placebo,
even the metadata in the images, such as the hidden location tags, was also stored.
In a stroke of genius, Dutch agents staged a fake glitch that supposedly deleted Hansa's
image database, so that the sellers would upload new photos that pinpointed exactly where they
were, whereas before, all of the metadata was removed, so they were useless.
In the most daring move yet, they offered sellers a file that served as a backup key to their
site so they could recover their precious Bitcoin even in the case of a site shutdown.
This existed even before the police takeover, but now it was replaced with a malicious Excel
file.
When the seller opened it, their device would connect a URL that logged their IP.
64 sellers fell for it.
These guys stole more data than Facebook does.
Now, that's impressive.
And for legal reasons, that's a joke, and alleged.
Within days of the shutdown, Hansa's user registrations went up by eight times as suppliers
and buyers tried to reach out to each other again.
And all of it was recorded.
Hilariously, people were very satisfied by the level of service at Hansa, which was
even better at the hands of the Dutch according to them.
It went on for four more weeks, remaining fully functional.
With the exception of all, which the police deemed too deadly,
all other illicit goods, I mean any drug you can think of,
continued to flow freely throughout the site.
The police weren't very conflicted about this,
saying that it would have taken place anyway,
just that they wouldn't know about it.
Approximately, 27,000 illegal deals occurred during surveillance.
all painstakingly logged, and finally, after roughly four weeks, the sting was reaching its end.
Hansa was abruptly unplugged from the internet and replaced by a seizure banner, taunting the community.
We trace people who are active at dark markets.
Are you one of them?
Then you have our attention.
In total, authorities claimed that they had harvested data from over 420,000 transactions,
including about 10,000 real postal addresses of buyers, which they later shared with Europol and
U.S. investigators.
Dozens of vendors were arrested all over Europe and North America, and the Dutch seized
over 1,200 Bitcoins from Hansa's escrow by exploiting their own code.
And also, 1,200 Bitcoins is worth about $132 million today.
This sweep was just one piece of Operation Bayonet, a coordinated global effort designed to show the
dark web drug lords that they couldn't hide.
Hundreds of other sites, just like Hansa and Alpha Bay, were also hit, sending shockwaves
through the drug trafficking underworld.
This operation was different.
Before, like a Hydra's head, one site would be taken down and another would pop up in its place.
A post-operation assessment noted that criminals fleeing.
Hanza actually did not simply resurface on another site.
They were scared. Whether it was a teenager in Ohio looking for drugs or a lawyer in
Germany hooked on booger sugar, they thought they were making an anonymous
purchase. Instead, they'd just given their real identities to law enforcement.
The message was clear. The police could find you anywhere. As Wired put it,
the police used their position at the top of Europe's largest dark web market to pull off increasingly
aggressive surveillance. The dark web was not a safe haven anymore. Dark Ode. If the dark web had a
Wall Street, Darkoad was its stock exchange, a high-stakes marketplace for the world's top hackers
bought, sold and traded illegal goods like stolen identities, hacking tools, and botnets. It didn't
look like much from the outside, just another hidden forum.
But behind the scenes, it was a slick, highly organized operation.
If you wanted to hire someone to break into an email, grab stolen credit cards, or control a massive army of hijacked computers, Darkoad was the place to be.
This wasn't some messy underground chat room.
It was a polished marketplace where cyber criminals dealt in secrets and malware as casually as people buy apps on their phones.
Professional, efficient, and dangerous.
Compared to its competitors, Darkoad was generally regarded as the most dangerous by authorities
as it had the largest group of criminal hackers and represented the biggest threat to data
safety. In fact, a prominent attorney, David Hickton, said that Darkoad was the most sophisticated
English-speaking forum for criminal computer hackers in the world, which represented one of
the gravest threats to the integrity of data on computers in the United States. You can see the
scale and impact this dark web criminal form had. Started in 2009 by a coder named Aserdo,
it was originally created to sell their bot called Butterfly Bot. If you're active in the cybersecurity
space, you might know this bot as Mariposa, which was a botnet used for denial of service
attacks that was discovered in 2008. It would install itself onto unprotected computers and start
monitoring for sensitive information and then would propagate into other computers. After the
computer is fully infected, it would contact the malicious actor's server and serve as a bot for
their purposes. For example, a DDoS attack. It costs an estimated tens of millions of dollars to remove
and over 800,000 individuals' personal data was stolen. By the end of 2009, U.S. Authority seized
control of the bot network, but unfortunately, the owners took it back and launched a revenge
attack, which actually knocked out internet connectivity for many Canadian universities and government
agencies. The following year, in Spain, the suspected leader of the group that created the botnet
was arrested along with two others. The creator of Butterfly Bot, where this all started, Aserdo,
also known as Matjaz Skornik, was arrested in Maribar, Slovenia, but was released due to lack of
evidence. Around this time, Matzjas gave up control of the Dark Ode Forum to Crim, who created
an exploit kit named Crime Pack that was sold in the early days of the forum. Mottjazz was arrested,
arrested again in October of 2011 and finally convicted in December 2013 in Slovenia for
creating a malicious computer program for hacking information systems, assisting in wrongdoings,
and money laundering. With nearly five years in prison to look forward to, you would think that
Majaz was done with the internet. However, just a year later, he founded Nice Hash, a cryptocurrency
mining marketplace. He was detained yet again in 2019 in Germany when the FBI reopened the
Pauasabotnet case with new charges.
Anyway, back to the main topic.
After Mott Jaws started selling his bot, the forum grew very popular and turned invite only.
Existing members were given invites who they could give to whoever they want, and this only
made Darkoad a more exclusive and trustworthy forum.
A few years later, in 2012, a new access model would be announced.
There were now two layers to the membership.
Level Zero, also known as Fresh Fish, was given to the new member.
after they were invited by another member and were vetted with an interview with the admin.
The next level up was level one. To gain trusted access, you would have to prove yourself
and then you could access the real meat in the level one marketplace. Further on, the system
was revised to ban fresh fish from inviting people. Level two was created for the highly trusted
members. With Darkoad becoming such a hot spot, it stumbled upon the bane of many forums, trolls.
You might think that the invite-only model would have avoided this problem, but that only works if all the members really care about the site.
This is a criminal form after all, and like most criminals, money can easily sway their allegiance.
There was always somebody willing to give you an invite for some quick cash,
and researchers would exploit this and gain easy access to the site.
Obviously, the forum moderators didn't sit and watch,
and began implementing measures such as mass demoted accounts and banning strangers in even talking.
targeting researchers directly.
Hackers were becoming wary with researchers becoming common,
and then in 2013, the downfall began.
A username Special First was voted as admin.
They had a rather extreme strategy for rooting out researchers.
Even though they banned people who invited them,
researchers always came back and Special First would start handing out bans to anyone
with even the slightest suspicion.
Soon, Darkgoat consisted only of security researchers,
the FBI and a very small selection of actual hackers who were highly trusted.
Of course, a marketplace can't function without buyers,
and Special First started basically removing the exclusivity of the site
and spamming invites on regular hacking forums.
They even went as far as sending messages to mailing lists from old hacking forums
and even posting in the comments of the cybersecurity researchers' blogs themselves.
The heyday of Darkoad was clearly over,
and just a couple years later, the site was shut down for good.
codenamed Operation Stroud of Horizon, the FBI along with law enforcement agencies from 20 different countries, seized the site and arrested several members.
Over a period of 18 months, they collected evidence for a variety of crimes, including but not limited to, conspiracy to commit computer fraud, conspiracy to commit wire fraud, conspiracy to commit money laundering, conspiracy to commit bank fraud, conspiracy to send malicious code, spamming, identity theft, and,
racketeering, and extortion. Around the world, around 70 people were arrested, but this is
obviously only a fraction of the users and many of Darko's frequent visitors are still out there.
Just two weeks after a shutdown, however, the site relaunched on the Tor network with supposedly
increased security, although shortly after, it was hacked and the database leaked.
Arctotype Market
Now, this might just be because I'm a YouTuber, or I'm chronically online, but
From my perspective, everyone and their grandma knows about the Silk Road by now.
We've talked about it before on the channel, and for the few of you who haven't heard of it,
the Silk Road was a website running from 2011 to 2013 that operated as an online drug marketplace.
And frankly, I'm sick of hearing about it.
I'm sick of writing about it.
And I think it ties into a problem YouTube is having when it comes to dark web material.
When the internet was new and scary, the websites hosted on untraceable browsers seemed like the most horrifying things online.
But as the internet got older and I did too, I started to notice that most of the videos talking about dark web websites were the same old, tired, recycled ones we saw 10 years ago.
It's interesting to say that something like the internet's first drug dealer marketplace, hidden from the surface web, feels more like history.
to talk about than an actual story. And personally, I don't like covering old news. So when I came
across archetype market and my research, I was very excited to share it all with you. Let's start at the
beginning. A boy is living his life in Germany. He was young when the Berlin Wall fell, five years old,
and grows up in the shadow of poverty it created. He's in close contact with drugs from an early
age and begins experimenting. When I was younger, I thought I was invincible. I thought I was
smarter than everyone else so I skillfully ignored every warning and did what I felt like every
day. Since I was a teenager, I've tried different drugs, but I have to say that alcohol was the
worst drug for me. But this is probably also due to the environment and the circumstances.
But like any young man, he wants to create something of his own. Him and his buddies get drunk
and start thinking up ideas for a website. Something new, something that would bring them out of poverty.
but it never gets anywhere.
He's stuck.
Then at the age of 20, he began his journey with hallucinogens.
When I consumed hallucinogens for the first time,
I felt like someone had just given me the gift of critical thinking.
I started to question a lot of things.
Firstly, why I'm drunk almost every day.
I realize that I'm very far from what I imagined for my future
when I was still a child.
As a child, I always wanted to practice a,
social profession and do something good for the world and for my fellow human beings.
But at that time, I actually did exactly the opposite.
I showed anti-social behavior and got on everyone's bad side as best as I could.
I think that was also my ego death.
I realized and perceived many things that I did not perceive before.
After my first trip, I wanted to do it again, quickly, and took four more trips within a few
months.
After the fourth trip, I had a new self-image and didn't want to drink.
alcohol anymore. I stopped drinking alcohol overnight and haven't had to drink for over a year.
I started to focus on the goals of my childhood, and of course I have also set myself some new goals.
Q the Silk Road. The boy, now a man, sees the work of Ross Ulbryke, creator of the Silk Road,
and is inspired. He starts to develop his own ideology, a belief that drugs shouldn't be illegal.
He believes that drugs in all forms aren't necessarily evil.
They aren't good.
They aren't bad.
They just are.
And he begins to believe that drugs shouldn't be criminalized in Europe.
After all, it's a victimless crime.
If he created a marketplace, it would be to further his political ideal.
That true freedom means illicit substances are legalized.
But he doesn't like the actions of Ross Ulbrick.
It was clear to our young man here that Ross was motivated by greed.
He believed that a new website could do some good, give freedom to the people, and destigmatized the industry.
All of what I just described was from a German interview conducted with our young man in 2021.
He had developed an archetypal sense of manhood.
He wanted to do what he believed was his duty.
His name was Mark Hegemeister.
And he founded Archetype Market, the longest running online drug marketplace ever created.
Launched in 2020, Archetype Market hit the ground running, wanting to be different from the Silk Road.
Arms trafficking wasn't allowed.
No personal listings.
It was an unadulterated online store solely for drugs.
The website had six vetted distributors, covering a couple of different bases.
I won't list what drugs were sold.
I don't want YouTube to flag me, but they sold most of the popular narcotics we see today.
Mark studied the Silk Road and learned from Ross Ulbriks mistakes.
He made sure no communications were done from personal emails,
no identifying information was on the site,
and everything was deeply encoded.
He implemented a cryptocurrency called Monero for transactions
to keep everything totally anonymous.
Most other drug marketplaces today are taken down quickly, but because of his efforts,
archetype markets survived for five years, which is basically unheard of in 2025, but it
wouldn't last forever. Europe was hot on his heels.
Agencies all over the continent were on the hunt for this new drug lord.
Audiology or not, good intentions are not, he needed to be taken down.
The fact of the matter is, freedom or not, people die on drugs.
Hundreds of thousands of people have lost their lives to the free-minded ideology
Mark Hegemeister supported, and unfortunately for him, he was the top marketplace on tour,
and with that exposure came his downfall.
Operation Deep Sentinel was born.
A Sentinel is a guard, a soldier, whose job is to keep watch over something and keep the
people safe. Operation Deep Sentinel was a joint effort between Europol and police agencies from
44 different countries to protect the people and clean up the dark web. And after half a decade,
they finally seized the website and arrested Mark in June of 2025. Now, let's not get it twisted.
Mark was a drug dealer, plain and simple. His actions probably resulted in deaths, countless families,
being damaged or destroyed, and I only wish he would have used his passion for something else.
Because maybe he could have done the world some good.
But today, Mark is in jail, awaiting trial.
And archetype market joins the graveyard of similar marketplaces, never to return.
Operation Playpen
The Hansa Sting proved that even the most secure criminal networks could be dismantled from the inside.
But as one operation ended, another began and one far more disturbing.
Whereas Hansa was built on drug trafficking and stolen identities, this one was much, much worse.
Based on a tip from the Europol partner in early 2015, the FBI stumbled upon Playpen,
a vile exploitation site buried deep within the dark web.
Hidden behind layers and layers of encryption, the site hosted images and videos depicting crimes too vile to name committed by the most abominable people on Earth.
The administrator, Stephen W. Chase was a 58-year-old from Florida, who operated the sites from his home computer.
They uncovered thousands of, and I have to say this acronym because, unless I don't, this video will be taken down and you guys won't even see it,
but they uncovered thousands of cheese pizza pictures and videos and evidence of him moderated the site through server logs at its peak playpen had more than get this two hundred and fifteen thousand registered accounts and hosted 23,000 cheese pizza posts insane I mean
215,000 registered accounts.
That is just beyond disgusting and ridiculous.
That is so many.
And even more disturbing, the moderators would rank users based on contribution quality.
In one of the most controversial decisions in FBI history after finally seizing control,
they did not shut it down.
Yes, you heard that right.
The FBI instead relocated to an FBI-controlled server in Virginia and ran it themselves for two weeks.
For those two weeks, they were effectively one of the world's largest cheese pizza forums.
Hiding in the suburban warehouse, agents continued to update Playpen's content and allowed the community to access it while running a sting operation.
According to court documents, during those 13 days, Playpen's users accessed at least 48,000 images, 200 videos, and 13,000 illicit links.
Each time anybody accessed the content, the FBI's hidden malware would log their identity.
And what was truly horrifying was the true scale of it.
In just those two weeks, nearly a hundred thousand.
thousand unique individuals logged on to Playpen.
They weren't just any random lurkers.
Many were international criminals actively trading or hoarding the material.
Within months, using the amassed evidence, over 200 people were charged as a direct result of the sting.
Most of them didn't even have any other criminal activity.
Many were parents, teachers, police officers, and IT workers.
They looked like good people while hiding their sick habits from their public persona.
Imagine how terrifying it would be if your next-door neighbor, who seemed like a saint,
had secretly been on the forum, your child's schoolteacher, your boss, your employee.
Operation Pacifier has drawn intense controversy.
Despite the good ulterior motive, many were appellate.
halt by the fact that the FBI essentially became a top producer of cheese pizza for two weeks.
Defense lawyers argued that the Bureau actually committed a more severe crime by distributing them
than those who were arrested. Children were effectively further victimized by the more widespread
distribution so that the other children could be identified. And so the question remains,
Where does decency end in the pursuit of justice?
Furthermore, the government refused to reveal the hacking exploit they used, instead choosing to protect its methods.
This actually led to some charges being dropped, and many offenders could have even escaped conviction due to this technicality,
just so that their methods remain a secret.
For example, while many of the defendants pled guilty, Jay McLeod did not.
he was identified as a playpen user and indicted for possession and receipt of cheese pizza.
He was also a well-known teacher from Washington.
For his defense, he fought for the disclosure of the exploit the FBI used.
Basically, he said that if they didn't explain exactly how they managed to hack into the vulnerability on the Tor network,
it would prevent their lawyers from mounting an effective defense against the charges put on Jay.
Apparently, they thought that the government should not be able to impose a mandatory five-year sentence
while supposedly severely undermining his trial rights because the FBI did not want to reveal their exploit.
The judge agreed to this and ordered the U.S. government to hand over the source code
and explain in detail how they circumvented the anonymity of Tor.
The prosecutors, the government, was forced to choose between jeopardizing future investigations by revealing the code,
which criminal coders could easily defend against them,
or make sure this one person goes to jail.
Obviously, the government agreed to dismiss this charge,
and McCod walked away free.
Because the government remains unwilling to disclose
certain discovery related to the FBI's deployment
of a network's investigative technique,
NIT, as part of its investigation into the Playpin Cheese Pizza site,
the government has no choice but to seek dismissal
of the indictment.
Federal prosecutor, Annette Hayes, wrote in the court filing on Friday.
She noted that the DOJ's work to resist disclosing the NIT was part of an effort to balance
the many competing interests that are at play when sensitive law enforcement technology
becomes the subject of a request for criminal discovery.
It is also important to note that this vulnerability was zero-day, meaning that no public
patch existed for it.
In fact, Mozilla even filed a brief asking that the government tell the company about it
if it was also present in Firefox, as it would also endanger the users.
The concern was that if the government kept hoarding it, criminals could also discover it on their own
and maliciously exploit them.
Mozilla has reason to believe that the exploit that was part of the complete NIT code
that this court ordered the government to disclose the defense involves a previously unknown
into potentially still active vulnerability
in its Firefox codebase,
Mozilla wrote in its May submission to the court,
absent great care,
the security of millions of individuals
using Mozilla's Firefox internet browser
could be put at any risk
by a premature disclosure of this vulnerability.
I'm sure we would all agree
that the more criminals caught the better,
but is it worth letting one sick individual walk away
free on a technicality?
Beyond this, the operation truly showed how many disgusting dark web users are among us.
Once again, over a hundred thousand people logged on in just two weeks.
There is an enormous global clientele for this filth.
As one FBI memo said, it is a proof of a sickness that hides in plain sight.
agents obviously experienced severe trauma while reviewing the content and several retired early,
citing psychological stress.
In the end, Operation Pacifier tore away the curtain hiding the darkest corners of the dark web,
revealing how deep sickness can run unchecked in anonymity.
It was a glimpse into a world where morality, empathy, and respect for human dignity,
does not exist.
Only human depravity.
It shows that for every reason to believe in humanity,
there is another reason not to.
Doxpin.
Many of you are probably active on various social media online
and follow a few internet celebrities.
They usually stay anonymous because they want to protect their privacy
against the many followers they have.
However, sometimes that celebrity might irk the wrong person
or get on the wrong side of a particularly vengeful community,
and they might dox them as a kind of petty revenge.
If you don't know what doxing is,
it's basically revealing personal information
such as their name, address, banking information,
without the person's permission.
Obviously, this is dangerous and also illegal,
as the internet isn't exactly known
for containing the most mentally stable individuals.
People get death threats or get SWAT teams called on them
all the times as some sort of prank.
Of course, doxing is illegal in most countries around the world, but some dark web websites don't really follow the law.
One website explicitly made for this purpose is Doxbin.
Doxbin was a paste bin, which is basically a website where users can store text files and can then share a link to allow others to view the content.
It describes itself as judge, jury, and executioner for all matters relating to Onion Land.
It first attracted major attention when one of the site admins, known as, Intentia,
Tangar hacked the hidden wiki.
The hidden wiki is a sort of strange page to the dark web that contains links to many
illegal websites.
It also used to include links to sites that provided, which Entangir objected to, and so
he hacked the website and scrubbed the site clean.
On the Doxman's website, he posted the following message, saying that he would support the
hidden wiki if they, A, don't link to sites, and B, allow community editing.
Entangir said that he wanted to do something good while showing that the hidden.
hidden wiki had terrible security and took its domain as well. Some people on Reddit didn't take
this news well. Of course, they weren't defending existing, but instead had a problem with the
inherent censorship. One Reddeter wrote that it's about keeping Tor free. Another felt like that the
supposed excuse for the kids would be used to control other things such as the UK's ban.
The UK planned to make websites verify the age of the users similar to what is implemented in some
U.S. States now, but the plan was canceled a couple years later. And to anger didn't really
seem to care as he wrote on Dockspin. What I love about these neckbeards complaining about
censorship is that if someone put their docks up, they'd be following up my inbox with things
like, take this down, internet freedom, et cetera. And I would just add the crying to their docks
and make fun of them. If someone added a pro NSA page to the wiki, they'd probably edit it,
or at least spam the talk page about having it taken down. Yet they're okay with links. After the hack,
the hidden wiki came back, promising to not include any links to those websites anymore.
In an interview with The Guardian, the site's admin, Natchash, says he does it to expose shitheads
who had it coming. One of his first targets, or Patient Zero, as he called him, was Jason Lee Van Dyke.
Van Dyke is a lawyer from Texas who represented a student from a Texas University who was a victim
of a revenge website called Pink Meth. He attempted to sue the Tor project, and Natchash was not happy with this,
seeing it as an attack on Tor.
The Tor project is how the majority of Darkweb websites are hosted.
It is a network that enables anonymous connections
and therefore hides the people who use it.
Natchash was also close to those who ran Pink Meth website
and soon after Van Dyck's personal information was uploaded to Doxbin.
Another person who was targeted by the internet was Robert Whitney,
who was doxed after an argument online
when he claimed to have discovered a security flaw for a coding website.
People sent SWAT teams to his house.
saying that they were in grave danger when in reality nothing was happening.
In one case, police were informed that people were being held hostage at gunpoint.
Of course, the police didn't want to risk it, so they usually do turn up heavily armed,
even if they suspect it is a prank call.
The site was eventually seized in November 2014, along with several others in Operation Onomus.
Authorities did not reveal how exactly they managed to take it down,
but the main theories are that either the website had some security issues in its code,
or it was a direct attack on the Tor network itself.
However, ironically considering the sites,
no personal information of the site's admins was found and no one was arrested.
It is rather easy to take back control of a seized site on the Tor network,
so the Doxman's site could come back up any time.
This is because the admins haven't been arrested
and still have access to the private key that controls the website
and can freely access it and do whatever they want with it.
But Natchash has no such plans, apparently as in his own.
own words. It's a 12-year-old skid shit show, and it's not worth my time.
Deep. Web and Dread. For some of the websites we discussed before, some of the information
sources linked to a site called deep.combe. But like me, if you try to go to the site,
we'll find that it no longer exists. Deep.combe is actually a news website dedicated mainly
to the dark web and its surrounding topics such as the Tor network, cryptocurrency, and privacy.
Major news about dark web markets would be posted here first, for example, the hacking of Silk Road,
and then mainstream news outlets would cover it.
The site even included comparisons between websites to help the confused customer choose the best
site to buy substances from.
Technically, this is not illegal, as the site itself did not sell any substances or have any illegal
activities going on.
It was just a news site, right?
It's actually not even illegal to post links to any black market sites,
even if they themselves are shady.
Like most free news sites,
Iran ads on his website and had an affiliate marketing system.
You might see this on some YouTuber's descriptions
where they post an Amazon link to some product,
and if you buy through the link,
the creators get a small percentage of it.
Deep.Web had a similar system
where it would post links to dark net markets
and would earn some revenue whenever a user bought from there.
In an investigation by Israeli police,
the site owners Taupra Har,
and Israeli who lived in Brazil and Michael Fawn, also of Israel,
were raking in millions every year from these affiliate deals.
The Department of Justice reported that 23.6% of all orders on Alva Bay
involved Deep.Web.
Although, that wasn't what they were charged for.
It was the common enemy of every shady businessman in the U.S., the good old IRS.
The owners were arrested for conspiracy to commit money laundering
and both pled guilty to their charges and were sentenced to 97 months in prison.
Approximately 8,155 Bitcoins of revenue were transferred to shell companies and then to their
personal wallets.
It was worth $8.4 million then, but today, it would be worth about $890 million.
All of it was forfeited.
After the arrest, the website was seized by authorities and only archives of it exist on
the internet. But this is the dark web, and new websites pop up after its predecessor is shut down.
Dread is a Reddit-style dark web discussion form that is the successor of deep dot web. It rose in
popularity in 2018 after Reddit started banning lots of darknet market discussion subredits,
and people needed a place to discuss their favorite Silk Road clone. Do this day, it does remain
online, and there's even a dedicated subreddit for its current status, R-slash Dread Alert.
One of the biggest blows to Darknet markets occurred on this site when a prominent site known as Wall Street Market fell.
The site was going through a turbulent period when the owners committed an exit scam on the users running away with approximately $14 million worth of crypto.
Basically, an exit scam occurs when the owner of a business runs away with the funds of people who participated in it without ever delivering their product or service.
This scam is especially popular in the online darknet market space, as most transactions,
are in crypto and you cannot charge back crypto like you can with normal currencies and banks.
One of the WSM moderators named Medellin started blackmailing the site users in the middle
of this as they were trying to leave. They would ask for 0.05 Bitcoin threatening to leak their
private info to law enforcement. A few days later, Medellin apparently had had enough and posted
the IP address and logging credentials for the WSM servers on Dread. Law authorities quickly
latched onto this and the site was taken down eight days later and three were arrested. Dread itself
is not completely innocent either. Stolen credentials are sometimes sold on the site. For example,
in 2020, a vendor known as Exploit Dot tried to sell KYC documents which would include ID such
as driver's licenses. They were selling 100 documents for $10 and even offered bulk discounts.
In an independent investigation by CCN, they got access to a few free sales.
and they seem to be legitimate KYC verification documents for Binance, a popular cryptocurrency marketplace.
However, Binance is known to have very good security practices and supposedly no leak had occurred, so they may be fake.
Dredd also has in-depth guides on how to manufacture substances.
In one of Dredd's versions of subreddit's substance manufacturer, you can ask questions for every step of the process.
The only rules are no sharing personal information, no revealing the source of your raw materials for
your chosen substance and strictly no selling substances.
In darknet markets, another kind of subreddit on this site, you can find reviews of the most
popular markets, so you can be sure that you won't be getting scammed.
Welcome to Video.
Of all the entries on this list, this one is the most sickening, bar none.
In June of 2015, a website launches on the Tor browser, and very quickly, it picked up traffic,
their service selling videos.
many videos
some had been circling
around the internet for years
some were brand new
but the owner wanted a place to keep them all
a marketplace for sharing
these videos to the widest possible audience
and as you may have guessed by now
these videos were
terrifying and about children
now I want to say really quickly
I read the comments
I hear you all
and I don't want to keep saying
cheese pizza
But unfortunately, even the more respectful term you've all been recommending gets flagged by YouTube.
I know many of you have been requesting, I begin using the other term and I want to.
I want to be as respectful as possible when covering these cases.
But unfortunately, YouTube doesn't like us even using those terms.
And with that said, I think stories like these are very important to talk about.
Exposing these disgusting people is one way to help combat the problem.
the problem and the only way I can do so is by using cheese pizza as the acronym. So I'm sorry
in advance. I'm going to try to say it as scarcely as possible. Now most websites that host
cheese pizza are small. It's not very often we hear about one with more than a couple
thousand articles of cheese pizza material, which is crazy to say. Obviously any cheese pizza
the material is terrible, but a couple thousand is, unfortunately, the standard.
But it doesn't typically get above that, because these kinds of websites garner ridiculous attention,
which is disgusting to say the least, but law enforcement puts the boot on the neck of these sites with frequency.
Just this year, there was something called Operation Grace skull,
which executed an effort to shut down four dark web websites that hosted cheese pizza.
In total, 18 people were arrested, receiving 300 years of jail time altogether.
The assistant attorney general Matthew R. Galletti had this to say.
Today's announcement sends a clear warning to those who exploit and abuse young people.
You will not find a safe haven, even on the dark web.
Thanks to the relentless determination of our prosecutors and law enforcement partners,
we have exposed these perpetrators for who they are, eliminated their websites,
and brought justice to countless victims.
So it's very clear,
law enforcement wants these people arrested,
and they put a lot of effort and energy
into shutting down these websites quickly.
But Welcome to Video was different.
I mean, it makes Operation Gray's Skull
look like a shoplifting case
because Welcome to Video
wasn't just pushing a couple of videos.
Like I said,
this was designed to be,
a marketplace and welcome to video was a very successful very insidious marketplace.
They hosted over 200,000 videos.
Yeah, you heard me correctly, a quarter of a million videos on one website.
And those numbers don't turn up overnight.
No, this website was active for years and they had an unbelievable one, one,
1.2 million registered users.
I wish I were making this up.
It makes me genuinely sick to say that out loud.
But unfortunately, it's true.
There were 1.2 million accounts on Welcome to Video.
Just for reference, if a podcaster on Spotify had 1.2 million followers,
they'd be in the top 15 most popular podcast on Spotify.
The city of Philadelphia has a population of 1.5 million.
That's how disgustingly large that number is.
In researching this video, I also discovered that this website had memberships,
which is terrifying in and of itself,
with most of these users having the free membership
and 4,000 being paid members.
Sick, absolutely sick.
A lot of these videos were acquired from another site that was shut down,
called Aves No, but the growth that welcomed to video saw was undeniably massive.
As more users joined, they uploaded their own materials.
Until an unfathomable, 45% of its videos were unique, over 100,000.
That's unheard of.
And it also means that these weren't recycled videos.
The crimes were happening live.
Active exploitation,
on the macro. When the U.S. government became familiar with this website, needless to say,
they wanted to catch the monsters responsible. And that's not to say other governments weren't angry as
well. This website was a global issue, and its victims spanned continents. But the U.S. didn't
waste a second. Homeland security in the IRS started working to identify them. Thankfully, the servers
for Welcome to Video weren't very secure, and they were able to track the IP back to a rough
location, South Korea. Now this was a good start, but in order to pinpoint who exactly was
running the website, they'd have to dig deeper. Now welcome to video took payments through Bitcoin.
Bitcoin, as we all know, is an anonymous currency. And most people think it's untraceable,
but it isn't. Not really. You see, if you try to track any cryptocurrency from the surface,
it wouldn't go anywhere.
You'd be chasing a ghost.
But this is the IRS and Homeland Security we're talking about,
and they had an idea.
The blockchain.
If they could follow the transactions through the blockchain,
through the dark web,
by surveilling suspects with less secure networks,
they'd be able to pinpoint who was receiving all the money.
And in March 2018,
three years after Welcome to Video was published,
which is three years to goddamn late,
South Korean resident
San Zhengwu was arrested
for creating the now infamous website
along with 337 other people.
Those 337 people
weren't just active users.
During the investigation, they discovered
that a lot of the videos were from
active crimes of exploitation
and each of them was arrested.
In this process, many
children were saved.
Happy ending, right?
Nope.
The guy is free to do.
day. How you might ask? Well, when he was convicted of the crime, South Korean courts gave him an
18-month sentence for the production and distribution of cheese pizza. That's it. Now, the maximum
sentence for cheese pizza in South Korea was five to seven years, which is still unacceptably
low, but he got a lighter sentence because he needed to support his family. I wish I was lying.
The U.S. attempted to extradit him so we could charge him here, but South Korea refused.
When he was released after a year and some change, they charged him with fraud for gambling with the cheese pizza money,
giving him another 24 months for a total of 42 months or three and a half years in prison.
Now, keep in mind, the maximum sentence at that time in South Korea was five to seven years.
That's it.
nothing more than a slap on the wrist.
Now, if this makes you ridiculously angry, you aren't alone.
The citizens of South Korea were absolutely infuriated by how short this monster's sentence was.
And eventually, they took it to the Supreme Court of South Korea,
who later raised the maximum sentence time from 5 to 7 years to 29 years,
which, yeah, glad they changed it, but that doesn't detract from the fact that this man is walking free today.
He can't leave his country or he'll be re-arrested, but he's free.
I have nothing else to say about this website except I'm glad it's gone.
And I wish the other 1.2 million people involved would face some consequences.
But today, it looks like that isn't going to happen.
But at least the laws got changed in South Korea, so maybe next time, more people don't have to get hurt.
And more people like Sun Jong-Wu can be people.
properly punished.
A1 or A1
was a huge
online image board. It had
barely any moderation, if
any, at all, leading to the posting
of some very disturbing and
usually outright illegal videos,
images, and messages.
It was created in October 2013
after a computer programmer
Frederick Brennan came up with the
idea for a site which was a free
speech-friendly alternative to
4chan, which he felt was growing to be
authoritarian. Brennan had grown up with brittle bone disease or osteogenesis in perfectia and lived his
life in foster care suffering over 120 bone fractures by the time he was 20. He had been using
4chan since the age of 12 in 2006, quite the tragedy and pretty telling when it came to where things
went wrong. When his father put him and his brother in the foster care system of New York, he felt
isolated and would browse 4chan for hours, dominating his childhood. He was a self-taught computer
programmer and grew up to live in Brooklyn, work in freelance. He was becoming increasingly frustrated
with the moderators on 4chan, who he felt were too strict on what was supposed to be the wild
west of the internet. Unsurprisingly, he was high on shrooms when the idea formed in his head,
but what was conscious enough to write it down, so he wouldn't forget about it when he was sober.
It took him two days to research and then compile 8-10, releasing it online. But this functional
little free speech message board experiment would turn incredibly drastic in ways you'd never imagine.
11 months after his creation, they became home to the GamerGate campaign. If you don't know,
GamerGates was a misogynistic far right wing campaign which lasted from 2014 to 2015.
It started from a blog post written by the ex-boyfriend of Zoe Quinn, an indie video game dev.
He made false claims that Quinn had slept with a journalist to get good reviews for her video game.
This quickly spread to 4chan and a mass harassment campaign was launched.
They didn't spare any woman who defended her either, with doxing, arward threats, and death threats becoming common.
After extreme backlash, 4chan then banned any mention of Gamergate from its site and the angry misogynist migrated to the 8-10 website
where they continued to coordinate attacks on any who didn't agree with their supposed agenda.
As Gamergate slowly faded from popular culture, the users remained and their agenda shifted to other individuals who,
their mainly right-wing ideology.
One such movement is the famous Q-Anon a conspiracy.
An anonymous user,
Q, named after his supposed Q-level security clearance in the U.S. government,
would often post his conspiracy theories on sites like 4chan and A-chan.
For those who don't know about this outlandish conspiracy,
it basically outlines a theory that President Trump is waging war against elite Satan worshippers
that run the government and inhabit other powerful positions in America.
They believe that a day of reckoning will come,
prominent leaders of this cult, such as Hillary Clinton, would be executed.
Q predicted that Trump would win in the 2020 elections, but as you might already know, he didn't
win.
QAnon conspiracists were suspected to be behind the January 6 riots where Republicans stormed
the Capitol building in an unprecedented attack.
If that wasn't enough, the site was also a platform for three mash shards who used it to
advertise themselves.
Brent and Tarrant live-streamed himself murdering 51 people in the devastating Christchurch
Moss shooting in New Zealand, and he posted a link to his Facebook live stream first on 8 with a message
saying, well, lads, it's time to stop posting and time to make a real-life effort post.
I will carry out an attack against the invaders, and will even live-stream the attack via Facebook.
His manifesto was also posted there.
The Poway stated in aagogu, where one person was fatally shot and three injured, posted an
extremely racist and anti-Semitic letter on A.
T.C. trying to mirror the Christchurch shooting.
The El Paso shooting, where 22 were.
killed and further 26 were injured also posted a manifesto on a ranting about immigration.
All of these hate-filled posts received a sickening amount of praise from the A-SAN user base.
Cloudflare, a service that protects DDoS attacks, immediately stopped supporting A-San as a client
after these shootings. His founder, Frederick Brennan, is disgusted by these events. He felt at least
partially responsible for the hurt caused so many due to his website. Until 2016, he served as an administrator
and his misgiving started soon after the days after the Christ Church.
He said that he didn't care if it was shut down,
wondering whether it was a good thing that he created a man.
Keeping it online soon became a struggle for Brennan,
as bandwidth limits kept exceeding and nobody really wanted to host it for obvious reasons.
Hope came from Ronald Watkins, along with his father and A&'s current owner, Jim Watkins,
who owned NT Technology, said he would host it while Brennan acted as the public figurehead
of the site.
They did not charge him.
only taking 60% of any profits A-Han made.
Brennan soon moved to the Philippines where he stayed in a fancy villa in Manila,
provided by Watkins who also lived there.
Jim Watkins made his money by helping Japanese corn stars evade the country-strick regulations
by hosting a corn site called Asia McKinney Bar and allowing them to host their content on it.
In 2016, after a fallout with Watkins, Brennan soon left A-10 and gave up a complete control to the Watkins,
who were prominent supporters of the QAnon conspiracy.
After Cloud Fair took down their services, the site rebranded to A-German and relaunched through a Russian host known for enabling cybercriminal activity.
But its return was brief until a Vancouver-based software company, Bonwatech, started providing services to A-Man.
Bonwatech is known for hosting a variety of far-right and neo-ex websites such as the Daily Stormer and Kiwi Farms, a website responsible for multiple S-words in the online community.
While Brennan now be appalled at what his vision had become,
It is too late to salvage anything of A-10 or now A-11, as it becomes the home for the extremist
far right and has a reputation so bad, it leaves a bad taste in your mouth every time you talk about it.
Rotten.com
You might all know about LiveLake, the infamous internet forum where you could see things
you really shouldn't see.
But before that, in the beginnings of the internet, there was rotten.com.
The internet only became mainstream a couple years prior with easy access being available to the public.
founded in 1996 by a developer only known as Soylent Communications, its ideology was heavily
inspired by the First Amendment. At a time when internet censorship was becoming a bigger worry,
rotten.com wanted to prove that censorship was unethical and wrong and serve as a haven for free
speech of a most controversial nature, in the developer's own words. It was the OG shock site.
Blood, gore, and extreme graphic violence were all too common on this site. It first gained
notoriety when an alleged picture of Princess Diana's fatal crash was posted on the site and
traffic spiked. It was later proven to be fake, but now the site was in the public's eye.
Tupac's autopsy was featured on the site, along with other high-profile crime scenes, such as
the murder of Nicole Simpson and Ron Goldman. It was one of the first media outlets, if it can
even be called that, to cover the 9-11 attacks and had the most videos on 9-11 jumpers. If you don't
know what a 9-11 jumper is, it's pretty horrifically.
self-explanatory.
Ron.com had the most footage of these jumpers as regular prints in digital media had
buried and or censored it out of fear that it was simply too much, too gory, or too harsh.
And by the accounts of some people, it may have been for the best.
I was a photo editor at Monthly Magazine in New York City on 9-11, 2001.
Later that week, I had to edit photos from Getty Images for usage in the magazine,
threw off footage that was only accessible to publications that paid for the service.
I have never forgotten the images of the jumpers.
The photos were clear and you could see their faces.
It was horrific, but even worse in every shot.
The woman jumped holding the hand of another woman.
The men were always alone when they jumped.
I remember crying at my computer as I'm typing this post.
Their faces were so clear that a family member could definitely recognize them.
The second day, I was so upset my editor-in-chief sent me home.
Those posts still exist in the Getty archives.
I have never forgotten those horrific photos.
this shot was a trigger that I had repressed.
I still remember the smell of the city as I walked home from Midtown to Brooklyn with millions of others in its days.
Soiland justified this gruesome content by saying that if you wanted to censor the site,
you have to censor medical texts, museums, and libraries.
Furthermore, he added that horrors are sprinkled throughout life,
and I see no problem with concentrating them.
If you want, we could go down to the bookstores and find pictures of cadavers for you.
It's very easy.
It's not possible to write a lot to make it impossible.
will display that stuff even for minors. It's too much of a slippery slope to take. In its peak,
it was seen roughly 200,000 visitors a day and was being investigated by the FBI for images
involving in and cannibalism. Those, thankfully, were proven to be fake. So, who is Soylent Communications?
There's a rumor that it is a programmer named Thomas E. Dell, who allegedly run Soylent
and wrote a bulletin board system named Waffle. Waffle was used by an early internet
service provider named MindVox, founded by the Legion of Doom Hacker Group, where it would cover
a vast array of topics from the evolution of cyberspace to drugs and a rank. MindVox may have been
the inspiration for Rotten.com, and there are many other similarities to the site. However,
rotten.com is no traditional forum site. It had a very minimal layout just consisting of users
submitted links with a morbid joke description below it and no thumbnails, which meant that you
could just see about anything if you click that link. It also spawned a little bit of the same. It also spawned
a host of other sites. The Daily Rotten, started by Thomas E. Dell, published stories based on
terrorism, murder, S-word, and abuse. It was driven entirely by user submissions, filtered by an editor,
posting extremely graphic images on entirely real gore. Another site was the gaping ma, which was a site for
commentary and satire written by cartoonist Tristan Farnan. This actually improved the site's image a little
bit as it was more of a discussion and contained intellectual arguments compared to the mindless
violence posted every day on the main site. The user base of rotten.com was obviously deeply disturbed,
and this would show clearly when a game called Rotten Deadpool was launched. In it, players would
pick 10 people who they believed would die over the next 10 months and would get a point for each
correct guess they made. I don't know about you, but this sounds pretty similar to something I've
seen in a movie. While the message of what this site is trying to achieve seems pretty
clear, the problems it poses greatly outweigh the principle at hand.
With there already been several rumors of what's hiding deep within the website, there's
no telling how long before it's revealed that the website is hosting videos of a very disgusting
nature.
The Shadowbrokers
The Dark Web isn't just a marketplace for drugs, stolen data, or Hitman for higher pages.
Hidden beneath the surface are places that have sparked chaos on a global scale.
leaks and entire events that changed the internet and government forever.
One of those events began with a mysterious hacker group who appeared out of nowhere
and claimed they'd stolen classified cyber weapons from one of the world's most powerful
intelligence agencies, introducing the shadowbrokers.
They weren't some small-time scammers.
No, they flipped the script.
Instead of the police chasing them, they attacked the police.
In August of 2016, they publicly announced on tour, which is the Dark Web,
that they had stolen hacking tools from the Equation Group,
one of the most sophisticated hacking groups in the world.
First identified by Casper Sky in 2015,
they revealed that the group had been active since at least 2001,
with more than 60 separate members.
They document more than 500 malware infections by the group,
affecting at least 42 countries,
but mainly targeting Iran, Russia, Pakistan, Afghanistan, India, Syria, and Mali.
Due to the extremely advanced techniques and intense level of secrecy,
it has been linked to the American NSA, specifically its tailored access operations unit.
For example, analysis of timestamps in the malware, distributed by the Equation Group,
indicated that its creations worked overwhelmingly Monday to Friday,
Friday in a timeframe that corresponded to 8 a.m. to 5 p.m. workday in eastern United States time.
Furthermore, the NSA code words, straight acid and straight shooter have been found in the malware.
In short, these guys were serious. So it was a big deal when a previously unknown group suddenly claimed to have access to a box full of NSA cyber bombs.
And they weren't lying either. They posted exploits first against major communication.
Asian companies like Cisco and Juniper.
According to a New York Times investigation, NSA staff were ordered to pull late-night shifts,
manually scanning thousands of their own internal respiratories in fear that more tools had escaped.
In fact, one insider described it as our own Snowden moment, except we didn't even know who did it.
In the months following, they ransomed the treasure trove of NSA cyberweapons.
Initially, the group asked for a mind-boggling
million Bitcoins worth over a $110 billion today and later reduced it to a modest sum of
10,000 Bitcoins, still worth over a billion dollars. Of course, back then, it was worth about 200 times
less than that, but still. Obviously, the government refused to pay, as is standard practice
for any ransom, so the group unleashed Pandora's box. They did try their hardest to get somebody
to pay. In fact, going through three different business models, auction, later crowdfunding to release
it, and then monthly subscriptions for leaks. Among the files was one of the most damaging exploits
ever discovered. Eternal Blue was a vulnerability in the Microsoft server message block protocol,
and within weeks, it was weaponized into the infamous Wanna Cry ransomware. It spread across
hospitals, banks, and factories all over the world.
demanding Bitcoin. It was a massive world pandemic with hundreds of thousands of machines
in 150 different countries being infected. Most famously, the exploit shut down the NHS,
United Kingdom's National Healthcare Service for a day. Another eternal exploit named Eternal
Romance would similarly enable the next major threat, the Not Petya ransomware, released in June 2017.
Not Petya was a continuation of a previous ransomware.
Petya, which was released a year prior and also used in a global cyber attack,
specifically targeting Ukraine.
It resulted in a $400 million loss in the country,
stopping a third of its economy for three days.
Basically, it harvest passwords,
then uses other techniques to spread to other computers on the same networks,
and uses those passwords to run code on them.
Although it claims to be ransomware,
it actually did not have any recovery system,
so if it infected your computer,
you might as well throw it away.
A White House assessment estimated the total damages
brought about by not pay you to be more than $10 billion.
In fact, it affected Ukraine so severely
that it shut down parts of a nuclear power plant,
as well as banks and a metro system.
It is widely considered the most destructive cyber attack ever.
Beyond Eternal Blue, the group revealed exploits that could hijack firewalls, routers, and PCs, and mass.
Tools used by elite government-employed geniuses were now in the hands of anybody with a working computer.
The world's vulnerabilities, once covertly used for espionage, were now turned inward, empowering criminals and hostile states alike.
alike. They kept on leaking for another year, sporadically releasing more allegedly classified data.
Thankfully, most of them either had already been patched or only affected older systems,
but it still left a permanent scar in the books of many companies.
Interestingly, Microsoft had patched some of the most important vulnerabilities just a month
before the exploits were released, suggesting an NSA tip-off.
So who were they?
and what was their motive?
Were they another Edward Snowden
intent on showing the world
the disturbing overreach of the U.S. government?
Or did they just want to get rich quick?
Of course, the first suspect was the U.S.'s biggest cyber threat, China.
Most evidence points otherwise, however.
When Barack Obama came to office,
he took a very strong stance against China,
threatening sanctions if any malicious Chinese threat,
were found. Furthermore, for the 18 months that the Shadowbrokers were posting, there was a
significant drop in Chinese hacking. One of the zero-day exploits released by the Shadow Brokers
was already in possession of a Chinese-affiliated hacking group, APT-31, four years before the leak,
so it wouldn't make sense for them to suddenly release it now. It would also make it completely
useless. Addressing the elephant in the room, money is probably not a motive either. China is
incredibly rich, and a negligible part of it comes from cybercriminal activities. It simply
wouldn't make sense for them to invest so much money into such an uncertain source of profit.
Next up, we have North Korea. North Korea does have the capabilities as shown in the infamous
Sony Pictures hack back in 2014.
A comedy movie was about to release where a major plot point was assassinating Kim John Oon,
which obviously angered the North Korean ministry, who promised to launch a merciless countermeasure.
A hacker group called the Guardians of Peace along with the Lazarus Group, then hacked Sony,
stole a huge amount of data, and shut down the servers for days.
If North Korea was capable of such an attack, they very well could have been behind the shadow brokers.
Wanna Cry, another ransomware that affected basically the entire globe,
was also created from the cash of exploits by the Shadowbrokers
and shows similarities to the Lazarus Group in its code.
Casper Sky and Symantec, two well-known and trusted security companies
actually showed the similarities which does provide some basis to this theory.
However, it falls apart when you look at some of the posts by the Shadowbrokers on Steemant,
a blockchain-based social media.
There were two posts that made fun of North Korea,
which, in such a brutal dictatorship,
makes it extremely unlikely that the group,
making fun of North Korea,
originated from or was affiliated to North Korea.
And then there's finally the insider theory.
We already talked about the similarities
between the equation group and the NSA unit, T-AO.
Linguistic analysis on the messages
that the shadow brokers posted
shows that all of them are written
in bad English,
though with entirely correct spelling,
and suspicious grammatical errors in idioms
that a low-skilled English speaker wouldn't know.
It does sound like a native speaker
trying to pretend to be a foreigner,
if that makes sense.
Furthermore, there are many comments on politics and events
that they wouldn't know unless they followed
American politics, specifically,
very closely.
Any Chinese-funded hacker group
probably wouldn't have known or cared this much
and definitely wouldn't have posted
that many American cultural references
found in their posts.
A former NSA employee
who wished to stay anonymous
claims that he and his colleagues
don't believe that there was actually a hack.
According to him,
the stolen files and scripts
were only accessible internally
connected to physical drives
not exposed to the internet at all.
Most importantly, the NSA themselves suspected that an insider was behind the leaks based on two arrests.
After the first post, the FBI received a warrant to search the home of Harold T. Martin III,
an NSA contractor and found terabytes of stolen material.
According to them, there is no evidence that Martin leaked anything from the stolen data.
Interestingly, gaming is popular among the TAO group, and the name Shadowbrokers could have come from the game Mass Effect.
Nevertheless, their identity still remains unknown, and we may never know who was behind this group that caused so much damage.
Whoever they were, their actions resulted in billions of dollars of damage across the world in some of the most devastating cyber attacks
in the world. After surprising the world, they went silent in July of 2017. No more posts,
no more leaks, and no more exploits. And it leaves us wondering, who was behind it, and what was
their motive? Want to cry? For this next story, we're talking about the Want to Cry Ransomware attacks.
Now, I've briefly covered this story before, but I think this story deserves its own spot in the video.
So here is a full rundown of one of the most devastating cyber attacks ever.
A group of people are slaving away on their computers, and they've been going for days.
Endless, monotonous days of typing, clicking, and scrolling.
They sleep for a little while, but once the sun is up, they're typing again.
A cup of coffee, a bite of some takeout, and a computer.
Rinse and repeat.
And they never stop.
Why?
Why? Because this group is composed of some of the most dangerous dark web hackers that have ever touched a computer.
Calculated, brilliant, malicious, and today they're stealing.
Not from a bank or a business.
They're robbing the United States of America.
Last week, the group discovered an exploit on a government system, an abandoned server, used for testing, with fragile security.
If they could crack into the server, it would allow them access to a sensitive series of files,
more powerful than anything money could buy.
And on August 14, 2016, after days spent trying to infiltrate the system, they finally broke in.
Virtually, they toured the server rooms, offices, research facilities, forgotten directories on form machines.
No one was supposed to have access, but now that they did, they looked for something valuable.
And after a bit of searching, they hit the jackpot.
Now, the story I just told you is completely speculative.
One of many theories on how this group accessed one of the most secure government agencies on planet Earth.
Some believe they were Russian hackers in pay from the Kremlin.
Others believe they were just a bunch of foreign computer techs looking for a payday.
And regardless of what theory you subscribe to, the facts remain the same.
We don't know who they were, what they looked like, or where they came from.
But we do know what they stole.
And their actions, with just a few days and a couple lines of computer code, nearly ended the world.
August 15, 2016, a group going by the name of the Shadowbrokers made it post a Tumblr.
And within a day, every news outlet in the nation was talking about it.
In Broken English, the group explained that they had acquired specialized surveillance tools,
stolen from the National Security Agency of the United States, the NSA.
These tools, they claimed, were more powerful than anything the public had ever seen.
In the post, they mentioned a program called Stuxnet, which was created by the United States and Israel
to sabotage the Iranian nuclear program in 2007.
famous amongst government and corporate hackers.
When it came to malicious computer viruses, Stuxnet was top of the line, the industry
golden child.
But the shadow brokers claimed it was nothing compared to what they had.
What they had was so incredibly powerful, with such potential for destruction, it made Stuxnet
look like a middle schooler's best code job, and they would be auctioning the code off,
with an intended goal of one million in Bitcoin.
The group included sample code as proof of their acquisition,
and that was that.
The plan was in motion.
The race was on.
Experts took the stage.
Many believed it was a hoax.
Others believed it was real, but trivial.
Quote, the data release so far appears to be relatively old.
Some of the programs have already been known for years,
said hacker and security researcher,
Claudio Guernelli, it's unlikely to cause any significant operational damage.
But between all of these news networks, constantly reaching out for information, the NSA never
commented because they'd seen the sample code. And they knew this was no lie. Someone had
somehow broken into their systems. And if they couldn't figure out what was stolen and fast,
there was no telling what terrors could be unleashed.
They hosted an internal assessment to quantify the possible damages,
but the shadow brokers were smart.
They left no trace they'd ever access to the servers.
So without any information on exactly what was stolen,
the NSA prepared for a worst case scenario.
Hunkered down and waited.
They tracked the auction over the coming year
because no one believed it was authentic.
It didn't have nearly enough Bitcoin.
A couple hundred at the most.
And behind the scenes, the shadow brokers were getting frustrated.
Clearly, no one wanted to buy what they were selling, so they made a decision.
In April of 2017, one year after the original Tumblr post, they revealed the files to the dark web.
So anyone, anywhere, could have free access to NSA surveillance technology.
And in those files were two pieces of critical.
software. Their names, Eternal Blue, and Double Pulsar. First, let's talk about Eternal Blue.
Now, on Windows computers, there's a background service called an SMB, or a server message
block. Essentially, the SMB lets computers share files, connect with printers, and so on.
The SMB only accepts messages, or attempts to connect to your computer in a very specific format.
Think of it like a receptionist.
If you file the right paperwork, the receptionist helps you.
That's the SMB.
Normally, the SMB has security that protects the computer from malicious or foreign devices
from connecting.
But on old Windows computers, there was a flaw.
Essentially, if you crafted the perfect message, it would override the security and let you
in without any trouble.
And Eternal Blue was that perfect message.
What does this mean in layman's terms?
terms. It means that with Eternal Blue, as long as you had a network connection, you had access to any and every Windows computer before a certain age.
And once you were in, you could control every process on the computer.
But once you're connected, how do you stay connected? And that's where Double Pulsar comes in.
Double Pulsar works like a back door, essentially.
Once Eternal Blue breaks into the system, double Pulsar plants itself in the computer code, allowing it,
future access from anywhere in the world at any given time.
And now, both pieces of software were public.
Granted, they'd only been released on the dark web.
Anywhere public was shut down due to national security, but on untraceable browsers
such as the dark web and private chat rooms, hackers across the world still had access
to these files.
The NSA was immediately aware of the leak, and once they found out what files have been
leaked, they were horrified. Eternal Blue and Double Pulsar were two of the strongest, most devastating
viruses the NSA had ever devised. And now that they were public, they had to act fast to protect not
just American citizens, but every country on Earth. They coordinated with Microsoft to patch
the issue in their older systems and sent out a worldwide update to every computer that was at
risk. Now, if every computer had accepted the update, we'd be in the clear. But once again,
there was a problem. But before we get into what that problem was, let's talk about another group.
One so demented and dangerous, it was willing to risk it all for a little taste of chaos.
Early May, 2017, somewhere in Asia, a group of hackers were laying in wait. This group was different
from the shadow brokers. All these shadow brokers were in it for the money. This group
hackers was in it for the politics. They belonged to a foreign nation, widely disliked, one with
lots of enemies, and this nation wasn't just interested in money, they wanted power,
and they were intent on getting it by any means necessary. This wasn't just a group of hackers,
they were internet mercenaries, a convoy of virtual militants on a mission to hostage the world
at gunpoint, and they knew exactly how to do it.
They had been working on a new project, one that had the potential to make them millions
of dollars overnight, handicapped for nations, and topple the global economy within
weeks.
They had developed the perfect ransomware.
Now, ransomware is a malicious virus that essentially holds your computer hostage.
Once it found its way onto a computer, it hijacks the system and in order to reach them.
gain control, you need to pay $300 in Bitcoin. If the user didn't pay within a specific time frame,
the program would begin randomly deleting files from the computer until it was inoperable.
Now the program would be devastating if it infected computers in mass, but how would they do that?
How do you infect every computer on Earth with a virus all at once before hackers figured out a way to shut you down?
How do you build the perfect delivery system?
Well, they didn't need to.
They had Eternal Blue and Double Pulsar, the twin insurgents that would infect the world
for them and allow their program to wreak worldwide havoc.
Once it entered a computer, the virus would self-propagate, spreading exponentially on its own
with no way to stop it.
They named the program, Want to Cry?
remember what I mentioned earlier.
If everyone just updated their computers, they'd all be fine.
Right?
Yes, that's correct.
They could have been all right.
But a lot of businesses and institutions have what we call legacy computers.
Legacy computers are often too old to run modern updates.
But more importantly, most of them are connected to vital infrastructure.
Corporations, banks, universities, public services, train systems.
most of these industries operated on older Microsoft systems, and if they updated to a newer version,
most of their software would stop working.
And because of this, for years and years, everyone in these industries chose to never update,
not even when it mattered most.
Which meant that on May 12, 2017, when the Wanna Cry Ransomware virus was released,
it didn't stop at one computer, or 100, or 1,000.
It didn't stop in one town or one nation.
It began to spread around the world.
The attack began in the United Kingdom.
In the first industry that got hit, hospitals.
Nurses and doctors opened computers across the UK to find a red ransomware screen.
Your computer is encrypted.
Your files will be corrupted.
Pay now or lose the computer.
Immediately, chaos swept through the UK.
Patients were left without critical sense.
systems. Medical records were inaccessible. Doctors, nurses, pediatricians, cancer patients,
people in active treatment, all held hostage behind a crimson webpage. Medical staff went back to
paper, doing what they could to service the public, and mitigate the threat on active care.
Quote, computer screens had gone blank. Messages had come up demanding a ransom for their computer
to be switched on again. It became apparent within 15 to 20 minutes that there was a very
significant cyber attack underway. They called the police, but law enforcement was having their own
issues. Government offices and emergency services were both experiencing the same attack. Directions for
ambulance workers were inaccessible. Police systems went red. Train stations scrambled to
realign their schedules as computers, ticket booths, and internal systems went red. Financial
institutions were working tirelessly to block the attack. Businesses instructed their departments,
plug the computers. The virus is spreading. University shut down. At the time, they believed it was
an attack on the UK alone. But within hours, it was clear. Most of Europe was infected.
In Spain, major telecommunication companies shut down. Cell phones went offline. The landlines
went cold. Communication went dark. In Germany, the public transportation system went
completely offline. Schedules were inaccessible. People couldn't buy tickets. 31 million rides
daily was reduced to nothing in an instant. In Russia, banks and institutions were scrambling
to stay afloat. Their IT systems couldn't prevent the attacks. So entire bank branches were locked
down out of their systems. Employees were reduced to using pen and paper to try and mitigate the
damage and keep debit and credit card services online.
Government offices were paralyzed, unable to provide basic services.
In China, production screeched to a halt.
Factories and manufacturing systems were all infected, especially in the electronic and auto sectors.
Production lines slowed or stopped completely.
Systems locked, computers froze.
In the U.S., major computer systems were affected.
The largest port in Los Angeles briefly.
shut down due to computer issues. Hospitals, government offices, and financial institutions scattered
to fix their systems before they shut down. Governments all over the world tried desperately to stop
the attacks, but it continued to propagate. Every second that passed, another dozen computers
were infected. Within 48 hours, over 150 countries were all infected. In estimated, 230,000 computers
were petrified by the red
Wanna Cry Ransom screen
and the threat of a global,
economic, and structural collapse
became a very real possibility.
Then, a miracle.
A 22-year-old cybersecurity researcher
named Marcus Hutchins
was analyzing the WannaCry ransomware
in a sandbox, a simulation,
to try and figure out how it ran.
He had taught himself coding from an early age
and was fascinated by malware.
When WannaCry began spreading,
he was fascinated and decided to try to analyze the code.
And while he was digging around, he found something strange.
Every time WannaCry spread to a new computer, it attempted to connect to a random domain,
made from a string of random letters and numbers, not randomly generated, a unique domain.
One single domain.
Marcus found this incredibly odd.
Why was it trying to connect to a website that didn't exist?
and just to see what would happen, he registered the domain.
And what happened next was nothing short of incredible.
WannaCry stopped spreading.
What Marcus had inadvertently discovered was the kill switch.
Every time WannaCry infected a new computer,
it checked that random domain to see if it was active.
If the domain was unregistered, it continued to spread.
But if it was registered, the virus stopped.
spreading and just like that for the low low price of 999 Marcus had accidentally
stopped the spread of the Wanna Cry ransomware single-handedly saving hundreds of
thousands of computers all over the world in total the damage caused by Wanna
Cry cost a terrifying four billion dollars worldwide and lost productivity and
repair costs and that was only after two days
If the kill switch had not been accidentally discovered, who knows what systems might have been infected and what catastrophic damage the virus might have caused.
A worldwide hunt for the creators of WannaCry began immediately.
Cybersecurity agencies collaborated to analyze the malware, traced payments of Bitcoin through the blockchain, and they discovered some similarities between WannaCry and a different ransomware.
Firstly, the payment amount was the same.
small amounts of money in the hundreds of dollars, always transferred by Bitcoin.
They recognize the writing style, in the fact certain portions of code have been recycled from previous attacks,
led them to confront their number one suspect.
North Korea.
In North Korea, there's an organization called the Lazarus Group.
Officially, they claim it doesn't exist, but in reality, it's a state-sponsored organization
whose sole purpose is to create ransomware.
Hack financial institutions and steal as much money for the North Korean government as humanly possible.
It's responsible for many high-profile attacks, especially against South Korea.
Using information from those previous attacks, it's safe to say, the Lazarus Group created the Wanna Cry ransomware.
The North Korean government has never accepted responsibility for the attacks, but no one has ever been charged.
But regardless of their official take, the Wanna Cry ransomware attack is one of the most horrifying
events in modern history. People could have died. Hundreds of thousands of industries would have been
set back decades, slowing to a snail's pace, sending the global economy on a downward trajectory
that could have left millions of people jobless and starving. Now, all we can do is speculate on
what might have happened. If Marcus hadn't accidentally found that kill switch,
What terrifying fate awaited us in the weeks or months, living in a world infected with Wanna Cry.
XSS.
Russia is known for their dodgy internet, and the amount of cybercrime that takes place there is absolutely unreal.
But there are several hidden Russian sites that have come to light recently, all of which were only accessible through the Tor network.
These sites specialize in ransomware, zero-day exploits, illegal product trade,
and a lot more.
One of the oldest sites is Exploit.
This website has been home to underground black hat hackers since 2005.
They help other users in social engineering,
finding and exploiting vulnerabilities, and much more.
If you don't know, social engineering, put simply,
is using information to manipulate and lie your way to defraud someone
into doing something.
Zero-day vulnerabilities are vulnerabilities in company's systems,
which is unknown to the company themselves.
People will use these exploits until eventually someone from the company finds out and they patch it.
That's when these hackers will find a new zero-day vulnerability and exploit that.
Seeing as this was one of the oldest hacking forums out there, to gain access, you either had to pay a $100 entry fee
or have a good reputation on other forums and have a good history.
This made it a closed forum, and this was done to ensure the security of the site, that not anyone
can simply come and go as they please.
except in 2021.
Exploit faced a breach when an intruder gained access to a server that protected the forum
from DDoS attacks.
This was a targeted attack that took down four other sites.
But this then links to Ramp, which we talked about earlier.
People flooded to Ramp after Exploit and another site was taken down.
As mentioned before, Ramp was shut down in 2017, but Ramp 2.0 came to life in 2021,
and the only way to gain entry, you had to be reputable user of XSS or Explo.
for over two months, which is now impossible considering both sites are shut down.
This turned Ramp 2.0 into a retroactive cybercriminal community for those who could prove they are
who they say they are, allowing only legitimate individuals into the site.
What is XSS?
Similar to Exploid, it's a closed forum which is more centered towards Russian cybercriminals
than being easily accessible for most cybercriminals,
which was unlike Ramp, which offered the site in Russian, Mandarin, and English.
To gain access to the site, you simply create a new account, answer a few questions, and
boom, you're done.
Sounds pretty easy, right?
This doesn't sound much like a close form until adding the fact that an admin from the site
approves your request to join.
Depending on your credentials and your answers to the questions they give, they can either
accept or reject you for any reason.
If you're granted access, though, you'd be able to take part in discussions involving
credential access, exploits, and valuable zero-day vulnerabilities lacking any security
patches. The site would go to extensive measures to protect their users, though. If you're allowed in,
IP address logging would be disabled, and you would have truly encrypted private messaging systems.
Until 2021, Ransomware topics ran rampant on the site. After all, most of these people wanted to
make a quick buck, or, well, in this case, a few thousand. But in 2021, these topics were banned
by the admin, likely due to the government cracking down on sites like these. And so they took this measure
to prevent their site from being put in the crosshairs.
A lot of these sites have turned to Telegram to conduct their business.
Famous for enforcing free speech,
Telgram lets almost anything and everything slide,
making it the number one place for criminals to communicate.
It also allows for a higher level of privacy,
as while you do have to link a phone number,
any spoofer can be used to link a fake number
and create an account hiding literally all your info.
Carter
As you all know, the United States and Russia
have been strong allies for 80 years.
And nothing has ever impacted their relations negatively.
If that joke wasn't obvious, here's the plain English.
Our governments have been at odds since before they invented slice spread.
And when it comes to issues online, including the dark web,
neither nation sees eye to eye.
And the story we're about to cover takes this conflict to a whole other level.
We're talking about Roman Selsnev.
Now, I wasn't familiar with this man,
or his website, Carter.
Before researching this video, so let's discuss this man's timeline, and I'll try to fill you in as best as possible.
Roman Selzenev was born in 1984, the fourth son of Valerie Selzenev, a member of Russia's Duma.
Now, the Russian Duma is essentially the country's parliament, established in 1993.
For our U.S. listeners, it's like the House of Representatives.
The Duma is responsible for debating and passing legislation that goes into law.
So Valerie was a big deal and still is.
Not much else is known about his early life, but being the son of a powerful figure,
we can imagine he had a pretty all right childhood, and he really liked computers.
Like, a lot.
There are no official records of him until 2003, when at the young age of 19, he began his career as a multinational.
Hacker. At one point in time, there was a dark web website called Carter Planet, a form for selling
and trading stolen information. Today we hear about this type of crime all the time. Servers are
infiltrated, Facebook gets a data hack, and suddenly people are getting charged $10 for a drink
they never bought. In a country, they've never visited. Now, Roman was an expert at stealing
people's information. He would hack background check websites and retrieve their data.
stuff like social security numbers and criminal histories and he would then sell them on
card planet he was making so much money in fact he hired an employee but there
wasn't a lot of business in social security numbers no the real money wasn't the plastic
credit card numbers Roman worked with his employee to develop a software that would
scan the internet for something called MSRDP open ports a
Essentially, he was looking for weak security on administrative networks.
Think of it like trying to break into a house.
The front door has a state-of-the-art security system,
but the back door has a cheap padlock.
That cheap padlock was the MSRDP open port.
He could connect to it remotely, break the lock, so to speak,
and retrieve all the data without ever getting found out.
And these networks had financial information,
specifically credit card numbers.
But there were a lot of networks to cover.
Lots and lots of houses, and most of them only had a couple of numbers.
Roman needed a way to sift through the worthless ones and find the money.
Large businesses with lots of recorded numbers.
So we contacted another hacker, Bad B,
and paid him to write an automated program
that would look for credit card numbers across multiple networks.
With this program, Roman and his employee scoured the internet.
And after a couple of days, they received their first credit card dump, and he sold it to Bad B for thousands.
They operated successfully for a year, stealing thousands of credit card numbers across multiple nations.
Their target?
Businesses, banks, financial institutions, eventually they developed malware that could crack even more sophisticated security.
and they were raking in hundreds of thousands of dollars by the end of the year.
But in 2004, the waters were getting choppy for Roman and Bad B.
The operators of Carter Planet realized that law enforcement had caught their scent
and they shut down the website.
Left without a way to make money, Roman looked for another home to sell his stolen goods.
That's when he discovered Carter.
Carter was the functional successor to Carter Planet, but now knew and improved.
It operated like the eBay of credit card theft, with hundreds of vendors and thousands of buyers,
selling millions of dollars worth of stolen credit cards.
If you ever watched the news and wondered where all those stolen credit card numbers were going,
this was where?
A dark web criminal syndicate orchestrating multiple million dollar heists across every nation on planet Earth,
operating on Carter.
And Roman was a big player.
He posted ads across the website,
specifically on the card dump forum.
He had a lot of money by this point
and was considered one of the most trusted thieves on the site.
But he had a problem.
Hacker Bad B, his longtime partner and friend,
was getting jealous.
Roman was making a ludicrous amount of money
using a program Bad B had devised, and before long, their relationship began to sour.
Friendship curdled into bitter hate, and an all-out war began.
Anywhere Roman posted his ads, Bad B posted more.
They wrestled over the sale of stolen credit cards and tried to screw the other at every opportunity.
Talking bad about the other and their credibility, it was a nasty, drawn-out bad.
battle between the two thieves, and before long, they were the only real players on Carter,
the two master thieves fighting for the throne. Then in 2010, Roman caught a lucky break. Bad B. was
arrested on a U.S. warrants in France, and was extradited on charges of fraud. The battle was won,
the war was over. And Roman, left with no competition, was the crown prince of credit card fraud.
And for four years, Roman reaped the rewards.
He traveled the world, hired more employees, and was richer than ever.
The smallest estimate for how much money he made is $17 million.
He stole over 2.9 million credit card numbers for a total cumulative theft of over $169 million,
plucked from the pockets of every day's event.
That's right, he was single-handedly responsible for the theft of over $169 million, making him one of the most
devastating thieves in modern history until 2014.
You see, the United States were made aware of Carter about two years before Badby was arrested,
and this time, they weren't watching from the backlines.
They had a front row seat.
The Secret Service had infiltrated Carter and spent years following breadcrumbs to catch these criminals.
They went undercover, buying credit card dumps, both from Bad B and from Roman.
Eventually, they were able to track down Bad B.
But Roman was more difficult.
Roman was smart.
He used multiple usernames to disguise his identity.
Online he wasn't Roman, Selzenev.
He was N-C-U-X, Track 2.
Bulba. One name was literally just Tupac. By hiding his title, it made it much more difficult to
pin him down. In fact, initially, they believed Roman was actually multiple people. But Roman
made some mistakes along the way. Firstly, across all of his aliases, the pricing never changed.
This was odd. Most vendors had different pricing to compete with the competition. Roman and Bad B
had different pricing.
Think of it like McDonald's and Burger King.
They were trying to outdo one another to sell the most of their product, but these
aliases always had the same pricing.
In over the years, the Secret Service tracked his writing style in communications with
each of the four personas.
All of this made it abundantly clear.
These weren't four separate hackers.
It was one man.
operating a multi-million dollar business with very little help.
So how did they catch him?
Well, after they'd buy a credit card dump,
they'd collect all of the institutions that had the cards saved online.
When they did this, over the tens of thousands of instances,
they were able to narrow it down to a couple of institutions.
From there, it was clear this wasn't a team effort,
again, reinforcing the theory that this was one man.
And remember when I was talking about MSRDP open ports?
The cheap padlocks that Roman used to infiltrate these institutions?
Well, Roman was remotely connecting to the networks from his personal computer.
And in doing so, he left behind key information, the digital version of a physical footprint.
He left behind his IP address.
Even when he used VPN's systems for obscuring his IP address, he would reuse the same systems,
hosting companies and domains all under the same aliases.
And with this information, the Secret Service was able to get a name and a location.
Roman Selzenev.
The Maldives.
In 2014, in coordination with the Maldives government, he was arrested by local Maldivian authorities
and extradited to the United States.
The dark web mecca of credit card fraud,
Carter was finally shut down.
And the crown prince of credit card fraud
was finally in custody.
But the story isn't over yet.
So far we've talked about the U.S. interest in catching Roman,
but what about its home country?
Russia.
Well, although the war between the two thieves was long since over,
the war between the nations was just beginning.
News broke all over the world.
The United States made another arrest on a dark web kingpin and another website shut down.
The people were safe once again.
But when Russia got word, they had a different story to tell.
They called it an illegal kidnapping by the United States.
According to them, Roman was their concern and their citizen.
So the United States had no right to imprison him without Russian due process.
They asked where Roman was being held or where he had even been arrested.
And the U.S. refused to give up the information.
The Russian government was pissed.
To them, this was an incredible disrespect.
Eventually, through the American legal system,
the Department of Justice eventually revealed that Roman had been arrested in the Maldives,
and this continued to exacerbate the national conflict.
You see, the Maldives doesn't have an extradition treaty,
with the U.S.
And still doesn't to this day.
The government of the United States negotiated with them specifically to arrest Roman and shut down his dark web enterprise.
But the Russians considered this a departure from international legal norms.
However, the U.S. was prepared to defend itself.
Back in 2009, when they discovered Carter, they believed Russian citizens might be involved.
So they reached out to the FSB, which is essentially,
Russia's FBI and requested assistance in capturing the criminal who would later steal hundreds of
millions of dollars from basically every nation on the planet. Roman Selsenov. But Russia denied the request.
They refused to help. In light of this, the U.S. stated we had no other option. You didn't want to
arrest him, so we did. So for years, he was held in the United States awaiting trial until 2016.
when Roman was found guilty of wire fraud, device fraud, credit card fraud,
illegal access to protected computers in the compromise of over 2 million credit cards.
He was charged with 27 years in federal prison.
But he didn't spend 27 years in prison.
Don't forget, Roman's father was a Russian politician.
This wasn't some random kid.
this was the Russian equivalent of a senator's son, and they wanted them back.
Over the years, the Russian government continued to make a stink about the arrest,
calling it politically motivated and unjust.
But Russia knew they had an ace in the hole.
Russia had a couple of prisoners we wanted back,
among them two journalists, a handful of activists,
and a U.S. Marine named Paul Wellen.
Wellen was arrested in 2018 in Moscow and charged with
espionage, a charge the United States vehemently denied. In fact, Paul was initially told upon
its arrest in Russia that he was being detained for the express purpose of a prisoner exchange.
In exchange for these prisoners, Russia wanted a couple of people, including Roman, a business
fraudster, a couple of spies, and the famous Russian assassin Vadim Krasikov. In 2024, the 24, the
exchange was agreed upon and Roman was released to Russia. When he arrived by plane in Moscow,
he was met by Vladimir Putin himself. And to our knowledge, he now walks free.
