📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

⚠️ Как Пробить Любого? Секретные способы профессионалов

Люди PRO1:28:57

Transcription

How does, for example, a Telegram admin's de-anonymization look today? Full identification in 70% of cases. And restoring your content, your correspondence is not difficult at all. >> Regular drug shops on platforms. Did you figure them out or not? >> This famous St. Petersburg case with eighteen tons of salt was investigated. >> Do you really believe that it will be blocked soon to please this state messenger, Max? >> The existence of even conditionally independent services is unacceptable today in the world. Internet access with a passport is generally possible. And how many bots, in your opinion, are there in Telegram? >> Durov, uh, for a long time told everyone that he doesn't transfer user data to anyone. We have a main resource where everyone is checked. Friends, hello, People Pro. Glad to see you. And we have Igor Bedyrov as a guest. Yes, the creator, I'll read it, the creator of the company, developer of algorithms for internet investigation of offenders, expert in business security, former special services employee, it's interesting which ones, and an expert in internet intelligence. Now he will say himself what corresponds to reality, or maybe everything at once. And we will talk, in general, about what kind of offenders are searched for on the internet, and not just about drug shops and the like. In short, about the Eye of God, Sherlock, and all the others. How not to get caught, or rather, not to commit crimes, so that such uncles in uniform and like Igor never look for you in your life, preferably? Yes, Igor, please tell us how you got into this field, where you studied, from where, and what you did before the internet, let's say, before internet investigation. Thank you, Sergey, for the invitation. It was very interesting to meet. How I entered the world of investigations was when I was little, I read a lot of detective stories, I was interested. And the first investigation, probably, that I encountered, it happened in the nursery. A small family secret. Indeed, I, uh, being a very, very small child, was in the nursery. And my first case was that I caught one of the caregivers stealing cutlets from the nursery canteen. And I followed her, walked around the corridors. I was, of course, caught, complained to my parents at the time, and I was taken away from the nursery. Well, the vector was set, and since then I have been interested in all this topic, connected to various wires, was involved in listening to the school director, connecting to the school radio broadcast, and other things, which, in fact, predetermined all my further interests. I probably came to this consciously and from the earliest childhood understood what would be interesting for me to do. Tired of unscrupulous sellers and wasted time? Continental offers a fundamentally new level of interaction in a certain interesting business. Only top sellers gather in this chat. Ranchat carries out strict control of each transaction, ensuring full protection of your interests. Join via the link in the description and forget about risks and disappointments. [music] Where did internet investigation come from? Well, we all know what competitive intelligence is, what OSINT is. For a long time, we looked at all this, well, some searches for pictures on the internet, uh, location by these pictures, googling something. Then came the realization that all these methods can be applied for various purposes. And today, when we face the question of professionalizing this entire direction, standardizing its work, we must identify the areas where OSINT can be applied. And for myself, I chose law enforcement and security activities. Thus, internet investigation is methods and techniques of work, as well as products that are created in this conditional OSINT and are intended for security purposes, for law enforcement purposes, for identifying, preventing, and investigating various crimes. >> How old were you then, >> when you started creating all this? It was, God willing, it was the end of the sixteenth year. >> And how, for example, did what you do differ from software complexes created by Kaspersky, the same Group IB, and so on? Firstly, a narrow focus, specialization specifically on investigation. Kaspersky Lab had its own internal solutions. Group IB had Behemoth, if we take the processing of various data leaks. They tried to make market products out of it. Since I was involved in and fascinated by investigation, I conducted investigations, created tools for myself. That is, even if you look at what they write about me on the internet, all the developments that were made were specifically to ensure the activities that I conducted. Thus, I developed a service for researching cryptocurrency, the second service in the world that dealt with Telegram data, and a number of others. I wrote one of the neural networks, which today is included in a large software complex and, uh, is used for, for example, counterparty assessment and identification of Telegram channels. In total, about 10 developments were made. Despite the fact that I absolutely cannot program, except, perhaps, for BASIC, which I managed to learn in school. >> How does, for example, the Dianon Telegram admin, that is, a channel admin, look today? What would you do? Actually, if we take the base, we have a Telegram channel, the Telegram channel has a description. It may already contain a reference to the administrator's profile. If not, we can delve into the archive of these descriptions, which are contained on a number of portals, from the web archive to specialized portals that aggregate Telegram history, >> like TGStat, and others, right? >> TGStat, Telemetr, My Telemetr IO, a number of others. In addition, we have, uh, content that is published. There are posts, some posts may be signed with the administrator's name. We can identify him by this name. There are built-in chats. The chat is embedded by the channel owner. Accordingly, the chat owner is the channel owner. We can also know him. If the administrator lists for the embedded chat are hidden, we can again raise the archive and see what is contained in it. We can, uh, download all messages that are in the chat and in the channel, including even in a private chat embedded in the channel, where you can comment on individual posts only. And we will analyze all this, extract named entities, phone numbers, emails, all hyperlinks. Even in old, old software like Archivist, we will analyze all this and understand that there is a certain frequency of use of a phone number or email, or there are often many shortened links clicked via the VKontakte link shortener. Well, we assume that any shortened link from the VKontakte shortener is immediately a full de-anonymization, because, firstly, you cannot create this link without authorizing yourself on VKontakte. That's one. Secondly, any transition through this link fixes your authorized profile in the browser. And files with metadata are downloaded, analyzed, all attempts to advertise this channel are analyzed. That is, even if there is nothing there, someone was promoting this channel, someone mentioned it, uh, published links to it in various chats. We will extract all this from the history, look at it, and check the version that the person who promoted it is likely its owner. Who else benefits from this? Channel connections. We will try to contact him. Well, in total, I calculated it, about 170 methods are used to, uh, achieve this. I even automated it a bit, created a Google spreadsheet where I put all these methods. So then, when I gave it to employees, they could go according to the methodology provided by this spreadsheet, click on buttons, and immediately go to the required sections, use dorks, dive into the channel archive, into its deleted messages. By the way, deleted messages are a cool story. Many people make mistakes. We have Telegram and channels in it jump together with chats. You can regularly miss. I, for example, miss a chat about once every six months. I write somewhere, but not there. It ends with channel administrators also making mistakes, also with approximately the same regularity. And we suddenly find private correspondence in the channel's deleted messages: "Greetings to various Ivan Ivanoviches, owners, beneficiaries of channels, complaints that they haven't paid money for certain compromising material that they are leaking." There were cases when we analyze links, down to the most curious ones, and a person leaves a hyperlink instead of the one they should have for the content they are commenting on, they leave a personal link to their journalist's account in Rossiyskaya Gazeta. A real case. The author of Rossiyskaya Gazeta writes for some clearly hostile opposition channel. There was a case, we investigated the Washington Obkom. There was such a channel some time ago. Also funny. It was personally, even solely, run by the then mayor of one of the Russian cities. >> But do such investigations happen more often by order of the authorities, or competitors, or whom? >> Literally everyone. We work either with government agencies or with private companies. We practically do not work with individuals, unless they are representatives of some business elite or officials. Friends, how are things on Instagram? How is Ms. Mizulina doing? Not all VPNs are blocked yet. In fact, these are not jokes, unfortunately, because the other day a law came into force that prohibits other sites from advertising VPN services. Therefore, listen carefully to what I am about to say. I think you all know what a VPN is, so we won't dwell on it. But if you are suddenly unaware, then know that a VPN service allows you to: A) gain access to any blocked sites and applications in your country, B) substitute your IP address so that Comrade Major, if anything, follows the wrong trail, C) encrypts traffic, which is especially important when connecting to public Wi-Fi networks. And before they block us all, I hasten to inform you about the UFAST VPN service, which all of us use, me, the People Pro team, our relatives and friends. Of course, it is paid, but a free trial access will allow you to feel all its advantages, and not the major's baton in your backside. Of course, it does not keep logs, so any request from law enforcement agencies will remain unanswered. Of course, it is fast, like Mike Tyson's punch, but besides that, it allows you to check your IP for cleanliness, RIS Score, Frcore, and how other sites and servers see you. Also, UFAST VPN uses Telegram for VPN distribution, so it cannot be blocked or removed from App Stores. Ufast VPN is with you everywhere there is Telegram. And finally. Roskomnadzor has been creating too many problems for services in the last year, but Fast is always one step ahead, or even two. You can pay with crypto and not worry about your security, anonymity, and access to Instagram and any other blocked resources. You will find the link to Fast VPN in the description. Get it quickly before it's deleted. And even if you don't need it right now, still go to the bot to save it for the future. [music] >> And in what percentage of cases, if we take, say, 100 requests, is it possible to establish the identity of an anonymous administrator, let's say, of a Telegram channel until a certain day? >> So, I named it very cautiously so as not to make a mistake. Full identification in 70% of cases. About 20% is partial identification. >> Well, that's quite a lot. >> It is, but we also have a lot of practice. I've lost count, but somewhere in mid-2023, it exceeded 1,000 channels in Telegram alone. And there are also YouTubes, Twitters, simple websites, bots, various services. >> I like it when you go in, look for someone, check them on Telegram. Yes, well, the Eye of God was there, of course, the initial search. By the way, it was very cool, it saved time, and how many law enforcement officers were connected there. Well, it's clear that practically everything that was in the Eye, well, you can find it yourself. Yes, only here you find it in 2 minutes, and yourself, well, sometimes I just found things for myself that the Eye sees. I searched manually for 2-3 hours. And, by the way, an interesting fact. The Eye sometimes found such things. I mean, not from hacked databases, that the info was there, but, well, just about me somewhere on the internet, right? Well, I found it difficult to find manually, frankly, I couldn't find what it generally found. Then you take, for example, the passenger of interest, throw it into Insight, and the same, for example, is familiar with the owners and look, for example, in the Eye, there wasn't a large history of name changes for a long time, say, for 5, 10 years, for example, or when Telegram appeared, right? Well, in Insight, for example, it exists, it pulls out, for example, links that you shared in some chats. Also an interesting moment to look at the interests of the passenger, right? Moreover, it's interesting, the same Insight, just about it, for example, few people know. And it shows, uh, on what, in which chats you are. And most people, well, probably 70 percent, I would say, whom I have searched for at some point, they are in chats of their residential complexes. You sometimes look there, like residential complex Omsk, then you look at Moscow, well, you understand that you've moved, right? And the same is interesting, curious with the sphere of interests, for example, uh, Insight, it gives, for example, what [ __ ] are interested in, drugs, mountain skiing, something else, you know, and you look, aha, well, you already roughly understand the psychological portrait of whom you are looking for. And another interesting moment, it showed from what time you are interested in a particular topic. That is, you can roughly understand when a person started using drugs. Well, I'm speaking figuratively. I'm just telling you this as a joke. But, uh, for an operative who is looking for where to catch you, right, in which Krasnaya Polyana or in Arkhyz or somewhere else, because you started being interested in mountain skiing two weeks ago and subscribed to Rozahutor, to Krasnaya Polyana, and so on. This will give, well, a significant starting point for finding and catching you, possibly. And it seems that Telegram, anonymously and so on, right? This is generally, I think, the biggest dust collector, right, of all the info about us that exists now. Or do you know any more exhaustive sources of information? >> Sergey, actually, there are very many resources, and today, for example, we are collecting. There are also several services that aggregate all public chats and messages from them. They re-upload daily. These are over 23 million chats that are being vacuumed daily, and you can search for specific users' messages in them. This is where the data for Insight, Beholder, and other services that evaluate your interests comes from. It's not just groups anymore, it's also messages that users write. Their approximate age, social circle, who they are with, who often mentions them, whom they mention, approximate age, interests, and so on. Everything is reflected in their messages in what third-party services collect. The legend about Telegram's anonymity, of course, existed, it was actually built around two main postulates. The first postulate is that Telegram does not display the phone number in its database, it is impossible to see it when you communicate with someone using simple methods. And the second is that Durov for a long time told everyone that he does not transfer user data to anyone, as we found out later, and he transfers it, and quite a long time ago. Maybe not everything, and not in full, and not to Russia, but he transfers it. Well, and he, remember, lied about that. It's just that my wife has some heroic image of Durov. We even argue. For me, well, no, as it were, because he lied many times. And, firstly, he suppressed some opposition chats very quickly, right? And then he was in Russia many times when he claimed that there were about fifty border crossings, well, and so on. There, his games with Ton, for example, like now, right, they announced that, well, I think you saw it three days ago, that like Holder, staker of Ton, a golden visa to the Emirates for 10 years? Well, there were also expenses to pay commissions, like for processing $35k, but nevertheless, the next day the Emirati authorities officially denied it, but nevertheless, the Ton course went up by 10%, right? And if you, for example, are sitting on long positions with some kind of fiftieth leverage, well, you understand how much money you could have earned. Ah, well, plus to this, you can buy press. I, for example, have some money in my channel. I discovered some Stars yesterday, literally, well, there aren't many, like 1,000, right, and I have 200, there are 50 Tons accumulated, these, well, $3 each, well, let's say $750 for advertising. And I can't even withdraw them, because I need to have few Russians, few Germans, few Israelis, few Ukrainians for some reason. And, in short, in my opinion, these are completely incomprehensible movements. And Durov himself, well, as it were, discredited himself. That is, the halo of a great martyr for your rights and freedoms. Well, in my eyes, it has definitely fallen off. What do you say about this? >> Well, look, first of all, 2 days before Durov was detained in France, there was another meeting of the ONE. ONE is such an American intelligence community that coordinates, among other things, OSINT work and interaction with external services. One of the issues that was raised there at the time was that the existence of even conditionally independent services is unacceptable in the world today. After that, Durov is detained 2 days later. You can speculate as much as you want about whether he is good or bad, it doesn't matter. The point is that he, uh, one way or another, broke. He left France, and Telegram began to change for the better, probably, in the understanding in which we live in this world, in which all social media exist. As for cryptocurrency, the KYC procedure has begun for the internal wallet, for the wallet within Telegram itself. The possibility of making requests for law enforcement agencies has appeared. Interaction with Roskomnadzor at the end of last year appeared, quite good, strong, with Telegram, with the possibility of deleting, blocking content, deleting channels. And all this works further and further. Further, of course, the question will arise about user identification, requests for users, blocking them, transferring their user data. All this, undoubtedly, will happen, and we will come to it. But on the other hand, Durov, as a good player, apparently, he, in my personal opinion, positioned Telegram as a kind of ecosystem in which, if you want, you can, in principle, collect all the data you need for an investigation. You can collect logs, user messages, archive of his profile changes. That is, it is no longer 2017, when we started this whole story, started this work with identifications. This is already a time when there is a huge number of external services, micro-applications, authorized bots, behind each of which is an entrepreneurial entity. Some of them are Russian entrepreneurial entities, from which you can get, request information. A lot of archived messages, channels, bots, user data. Many leaks have occurred. And most importantly, Durov, of course, earning money, launched Telegram ADS. Given the capabilities of modern mailing, Telegram ADS, given that we have the possibility of precise targeting in advertising, what kind of anonymity can be talked about in principle? We take the target, we create a specialized trap in the form of a bot, in the form of some external website, application, and bomb that group of users that is of particular interest to us. At the same time, targeting is possible for specific users, including just a list of IDs. >> I just haven't played with it, as there was no need for settings. How can you target there >> just by a list of IDs, if you take, for example, marketing platforms, Russian telecom operators, everything is quite interesting there. Before, when there was no ESA, we did the same through bots. We took some bots that are constructors, uh, and feedback bot constructors, and through them we also entered a list of IDs and sent mailings to them. Naturally, through one or two iterations, everything was blocked, but, uh, it was enough for us. In short, Telegram, can we say, gives the most information about a Russian person now? Well, about an CIS person. I think only in large cities. The thing is, since I am also an advisor to several governors, we work with the information agenda in the regions. And Telegram is especially relevant for Moscow, St. Petersburg, Moscow region, maybe a little bit for Leningrad region, as an aggregator of various opposition information, an aggregator of criminal actions, a distributor of fakes, and so on. In the regions, the majority of political information is still concentrated on VKontakte, surprisingly. There are more influencers there, there is more audience, more views of regional materials. So not yet. As for large cities, mostly yes, but in the regions, VKontakte rules. And how many bots, in your opinion, are there in Telegram? He claims to have a billion users, but in my subjective opinion, probably 60 percent are bots. >> Yes, indeed, it gives that impression. I once looked into VKontakte, they also write something around 400 million, if I remember correctly. According to external estimates, well, 40 percent for sure. So I think that approximately the same figures may apply to Telegram, given the need for these bots for parsing, for extracting data of any kind, for collecting technical information, for collecting donations, collecting gifts distributed through communities, premiums, information dissemination. I think 40 percent for sure. >> And these anonymous numbers, I was looking at Fragment yesterday for my other business, and there they sell these anonymous Telegram numbers, like +888, I think. How much security does that give? In my opinion, it's just an illusion. And buying, but I saw two numbers yesterday, for 15-20 thousand dollars, in my opinion, there is no point in buying these anonymous Telegram numbers. >> Look, let's go back a bit in history. When we started investigating in Telegram, the main question all law enforcement officers asked was, we can't investigate. Give us a phone number, we'll beat everyone. Then, however, it turned out that we wouldn't quite beat them, because phones can be disposable, virtual, gray, and this has not been fully overcome, even despite the changes introduced by the State Duma. Given the possibility of buying these virtual numbers with cryptocurrency, given that they are sold through Telegram, although, as I understand it, even at a minimum cost they are 3 times more expensive than we would buy them somewhere on an online platform, this is just earning money. The thing is, the problem with these virtual numbers for investigating crimes is often that we don't know on which platform this number was purchased. If we knew, we would request user logs from that platform, about how the purchase of this phone number was paid for. In the case of Telegram, we know what platform it is. And we know that it was most likely purchased with Ton. It was probably paid for through the wallet located inside Telegram. And, accordingly, the Wallet raised its hands and said that it is ready to cooperate on all requests with law enforcement agencies worldwide. >> I didn't pass KYC. I don't have a Russian passport or a Belarusian one. I still didn't pass KYC. So you mean services like SMS Activate, onSIM, and so on? >> Yes, yes, yes. Those that are in Russia are generally known, and they can be requested. And mainly in such cases, when a virtual number appears, Russian aggregators of virtual numbers are requested. Maybe the user will appear there, of course, but the probability is somewhere around 20-25%. >> Well, that's still a lot. So you just send it to everyone on the list, right, and that's it? >> Modern crime investigation has now come down to sending a million requests and waiting for a response, and hoping that you will get a correct answer. This is where we strongly differ from Western countries, where such information has long been aggregated centrally, cross-analytics is applied to it, and then employees of analytical departments sit with it and see everything themselves, they don't wait a month, two months, maybe someone will answer me, but work directly with the information immediately, having it in front of their eyes. >> To finalize about Telegram, what, uh, security methods would you call the most obvious? Well, in my opinion, it's to remove the username, for example, to prohibit showing the phone number, to prohibit even showing your avatar, right, then what else? Configure privacy so that your messages cannot be forwarded. Well, that's probably the most basic. And also not to engage in activities that are displeasing to the authorities, so that there is no reason to search for you, especially to search deeply. Here you can engage in what is pleasing to the authorities, but there will always be people who suddenly become interested in where you got the money for this pleasing activity. And don't you want to share this money? This is also a small secret. But you can really advise, yes, those measures you noted absolutely correctly, they take place, because you can also disable pre-loading of video and, >> uh, photo content. There were vulnerabilities in Telegram for some time, it was possible to embed, uh, capabilities, including session interception. This was, for example, during the start of the special military operation. I know guys who hijacked a number of channels from that side. It's better, of course, to check all hyperlinks. Well, as always, hyperlinks, files for the presence of various malicious software.

If not through the application, then through the web version, through the desktop version, one can try to hijack the connection. Then, of course, cloud password and two-factor authentication. Cloud password is already like, well, a must-have for today, because without it, uh, restoring your, uh, content, your correspondence is not difficult at all. As far as I know, to this day, unlike WhatsApp, Telegram stores correspondence on its server. Moreover, it even stores the last message in secret chats, which you can restore. I encountered this completely unexpectedly. I change my phone maybe once a year, once every 2 years. And suddenly I noticed that I had changed my phone three times. And after 6 years, those secret chats that I had 6 years ago were restored. The messages that were sent last there, pop up in these chats. Accordingly, we conclude >> Yes, yes, yes. Accordingly, we conclude that at least the last message, while it is accepted or not accepted, it hangs somewhere in Telegram. >> I just talked to guys who went through various criminal cases. Well, in general, all the info that was in regular chats, it was in their criminal cases, but the one in secret chats, it never, in principle, plus or minus, if you didn't give it yourself, it didn't get there. And you say, in short, the last message somewhere due to some glitches, possibly technical or features, it shows up. Well, probably, it hangs somewhere on Telegram servers, specifically the last message. Maybe it's considered undelivered, I don't know, it's difficult. Forensic tools don't really pull it out. I saw that. It doesn't pull out the message. Neither mobile forensics, nor, uh, Avila Forensic, nothing. >> Well, and now this fight with Telegram, right? Do you believe that it will be blocked soon in favor of this state messenger? Max? I don't think so. I don't think they will block it. Firstly, it is cooperating quite closely with Roskomnadzor now, there is no point in blocking it. Secondly, well, Antipov's "Eye of God" has already been blocked for us, unfortunately. From this, there were more minuses, in my opinion, and in the opinion of a large number of the same security forces, because, well, let's be frank, we have a main resource where everyone is checked, even against those against whom they plan to commit a crime. Murder, God forbid, or something else. And the first task of the security forces, knowing that this is the main resource, they go to the "Eye of God" and say: "Who checked that person?" >> Yes, yes, yes, of course. >> The simplest thing: look where you can catch this fish, control the environment. Now the possibility of controlling this environment has significantly decreased due to the fact that, uh, "Eye of God" is gone. >> Well, analogues have appeared, the Belarusian Tambox, Sherlock is a strong player, I think. But the point is that the example was indicative, yes, indeed. That's how they dealt with him, and considering that he helped both ours and yours with PM with dancing there, and he has diplomas from the FSB and award knives from the FSB and so on, and so on, and simply, well, they took him and destroyed him. I don't remember how many, but probably thousands, maybe more security forces were involved for free. Journalists also used all this, by the way, with the start of the war and so on. and simply cut off this possibility. And others already think: "Well, why should we cooperate with you, help, and so on? And indeed, well, everything has gone into the shadows." Correct. All correct. All correct. Here, the phrase from the nineties is usually remembered: "You can't make a deal with a cop." Well, there's no point. The cop always has a boss. A boss. The boss has another boss. How will it go further in their hierarchy? Who will tell whom? For the sake of staying in place, getting another star. There is no point in making a deal. They fought for "Eye of God" a lot and seriously. >> Yes, and higher than the Ministry of Internal Affairs. I was curious, you know, figures standing much higher than the Ministry of Internal Affairs, well, they couldn't resolve this issue. That is, the Ministry of Internal Affairs simply opened a case and that's it. And when I talked about this topic, I said: "Well, why did this happen to him?" And they simply told me: "Listen, well, it's impossible to protect a person who is in plain sight of all deputies, senators, and lives in the Russian Federation, as it were, and everyone points a finger and knows, in principle, who he is, right? That is, even with Chimera, there was DAnon of the owner and so on. Well, like, well, there was DAnon, he left and left. Here DAnon, not DAnon, but here, well, everyone knows that he is a public figure and specifically the creator, author, and sole owner of "Eye of God". That is, this corresponds to reality in many ways. I, as far as I remember, was one of the first to find him then. This was the very, very beginning of his work. "Eye of God" had just appeared, and I had requests from a number of departments to find the developer. And only then did we meet and communicate with him. >> But he is a really serious programmer, >> isn't he? He's cool. The most curious thing is that he writes code himself. If I knew how to program, all my projects would move 10 times faster. And so I have a hundred percent dependence on developers and it just slows me down. In his case, of course, it was good that he is also an entrepreneur, well, he himself is also a coder. Well, okay, let's wish him luck. And now Sherlock Holmes, right, Sherlock has appeared. I have a question. Do you call yourself Sherlock Holmes of the digital age? And what then falls into your circle of tasks, responsibilities? >> The phrase appeared, God grant me memory, I think in 2018. and belongs to Mikhail Deneev. He is the editor-in-chief of Rubezh magazine. He interviewed me about the prospects for the development of services for security structures for the year ahead. That is, I made a certain forecast of how everything would move, what risks would arise. And then he put it in the headline of the article "Sherlock Holmes of the Digital Age". And since then, it has gradually spread. For the most part, I don't call myself that. I used it, I think, only on social networks. For me, Sherlock Holmes is a bright image of a classic honest detective, working. Well, qualitatively, effectively. And what kind of crimes do you investigate? Well, do you work for yourself, in the form of some company or as part of some holding, special services, etc.? These are companies for the most part. And, well, again, let's dispel a popular myth. As for OSINT, and indeed the entire field of investigations - these are low-profit industries. I constantly tell students this, including those we work with. There is no such special market in the country for either OSINT or investigations. It all happens from case to case. It's a very image-driven story. That is, when you can do something that others cannot, you get into the media, newspapers, you become known, you are invited. But for the most part, earnings are not built on this. It does not bring any crazy, fabulous money, or even, say, just large sums of money. Mostly all earnings in this sphere are indirect. They are related to the sale of hardware, to AVT, to providing information security services, which is in demand today, to ensuring reputational security for VIPs, for officials on the internet. Regularly they drown each other, humiliate themselves, try to remove them from office by publishing information. New methods of working with information appear, spreading unreliable information, political or economic fakes. This is what is investigated. That is, what can really be touched in terms of finances. Reputation is now a very important financial asset that hits companies, often hits them right in the gut. Well, >> we saw those official wars, right, when they wrote about Chemezov and so on on Sobchak's channel. As a result, several administrators were imprisoned for such long terms. Well, Sobchak, of course, is like water off a duck's back, as always. And is it a common story, right, that compromising material is leaked to each other through anonymous platforms? >> Practically constant, especially when elections are being prepared, especially when we are now living in conditions of a shrinking food base, a shrinking market, Yush Uralzoloto and so on. We see everything, we follow the news too, >> yes. Plus, we have already reached the ceiling in many industries that could be reached within the country. The same information security. We have, in principle, already reached this ceiling. Further, in theory, companies should eat other companies. Although at the PMEF, certain words were spoken unofficially, which I paid attention to, and they, uh, led me to think that, most likely, information security will now be imposed on small businesses and individual entrepreneurs in the form of a subscription history. >> Well, again, that is, only a few companies affiliated with the state will get there, right, and that's it, >> undoubtedly. But this will stimulate another round of development. Although, looking at these unfortunate SMEs, you can't look at them without tears. >> Well, how much, for example, does a service cost? I understand you say you can't earn big money, and I, well, I rather agree with that. How much does a service cost not out of friendship, but on a commercial basis to deanonymize a bothersome administrator of a Telegram channel, for example? >> Very conditionally, very superficially, from 300,000 to about one and a half million. Further, you need to know the nuances. understand the work methodology. We try to be very transparent here, we write and discuss with the customer what exactly we will do, so that there are no misunderstandings later. The customer is always a very complex being, often living in a fantasy world of dragons, satellites, spies, hacker organizations, killer corporations, like in the nineties, and similar things. Therefore, he needs to be grown as a customer in this regard, explaining what will be done. And what will definitely not be done, what violates the law, and we will definitely not take on that. >> Well, for example, what won't be done? >> Well, of course, there will be no attempts to hack. We will not commit crimes. And if we are talking about an investigation that is intended for his personal, for his personal eyes, then we can provide not much information, for example, non-obvious information, information that was obtained, say, from not entirely correct sources, let's be honest. If we are talking about preparing a conclusion that goes to court, then we, of course, simply cannot do that. Technically, the judge will give me very surprised eyes and say: "Igor Sergeevich, you have written four scientific papers on this topic. What have you actually brought here? This is at least wrong, incorrect, and it will not be accepted in court. Rather, I will be accepted in this court. Darknet platforms. They convicted the administrator, let's say, of Hydra, right, then who held their servers, then some freelancer who helped was separated from his case. I recently read this whole big story. Well, again, Germans and Americans were all involved, and St. Petersburg cops or FSB officers, everyone was involved in this. Somehow, with the help of the world, all these servers and so on, they managed to find a person, right? Well, of course, not the main owners. I still don't believe that this sysadmin, figuratively speaking, was the main owner. Now they recently detained guys from a hosting company. They are accused of administering servers for the Octopus, well, all these, you know, servers and so on. How difficult is it and by what methods can users be identified and deanonymized, for example, users are clear, phishing sites, like Hydra, and other platforms, administrators, sysadmins, owners of Darknet platforms, especially those in the Tor zone? Well, let's start with the Germans and Hydra. The fact is that Interpol was very concerned about the story published on Three-Headed about the fact that a platform operating in Western Europe would appear. As usual, they are actively fighting it. They have relevant regulations that allow this. They have an obligation for hosting providers to identify and report such actions. By the way, in this regard, the legislation of the Russian Federation in this regard looks very liberal. Probably for the simple reason that they haven't figured out how to do it yet. Therefore, the issue of identifying Hydra's server equipment, I think, was not particularly pressing. They found it in a year, blocked it, collected evidence, destroying the prerequisites for the development of Ternos. Moreover, they probably didn't even find the main platform developer. He is a guy from St. Petersburg, we know him a little. We have resolved this problem for ourselves personally. Well, and then the general trend emerged, which we observe today, when Europeans, when Americans publish the results of a particular investigation, they publish court materials, then our security forces look at this and, wow, why not work on a case that's already done? It seems like everything is revealed. Here are the legal entities that participated in all this, the personnel. And let's also make some money on this. I think it could have looked something like this. And then we have this story with Pavlov, who was a hosting provider for Three-Headed. And I had a case, I talked to his wife, we discussed the issue of conducting an independent examination in this case. I'm afraid that all we can say here is that the issue of the necessity of bringing someone to justice was already political, so no expertise would have helped. In principle, someone had to be detained, someone had to report. We have a small secret, very many, uh, cases of terrorist acts when, well, it needs to be solved and all efforts are thrown to find, prove, solve. And sometimes it raises questions, sometimes it doesn't. >> Well, with Hydra, it's clear, right, essentially, the Germans, right, at Hetzner or where there, at Hetzner, I think, did all the work. By the way, what do you think? Antipov had such a step. He stored all his infrastructure at Hetzner. Then the war came, and he, as it were, transferred all the databases to Russian data centers, well, allegedly from unfriendly countries and so on. And probably, in wartime, this step was justified, right? At the same time, it created some vulnerability. So, if I were in his place, I would still keep some copies somewhere, maybe not in Germany, not in the USA, but in some Africa, figuratively speaking, on some alternative servers, but it turned out that he didn't even have backups, that everything was on Russian servers. So it did a disservice. So he wanted to be a good patriot, so that the bourgeoisie wouldn't have access to RF information, but it turned out like this. Well, let's say, from what the bourgeoisie had access to, even in the years when the special military operation had not yet begun, they had enormous data. Here, the specifics of their legislation regarding leaks for special services are reflected, I mean, not for ordinary citizens, not for organizations. I'll give you just one example. We had a client, a TV channel. And the TV channel was serviced by one of our infosecurity companies in terms of this security. Suddenly, the email of the TV channel's head of security is hacked. We investigate all this, and the story emerges that the IP address is live, but located in Cloudflare. Oh, I'm wrong, in DigitalOcean, that is, a conditionally anonymous IP address. At that time, I had a debtor, an FBI agent from the old days. I call him and ask: "Can you?" He says: "I can." Five minutes later, a call rings, he says: "Behind this is number 2, and he is in this building right now. The building is of one of the well-known infosecurity companies, which no longer exists, having changed its name several times. So the possibilities are there, and the possibilities are quite good. How much did they need domestic databases? Well, I don't know, maybe they did. There, I understand, the special services are not entirely homogeneous. But the fact that Antipov lost a promising market, well, perhaps it's worth worrying about. He could have left and continued this activity, but now, having nothing for this work, it would be difficult to continue. At least, one could come up with some kind of offline story. For example, how I, for example, for researching data leaks, I accumulate them all on a hard drive. They are indexed there on this hard drive if I need them. This is a completely offline story. I plug it into a computer, search for everything I need in a non-relational database. It's convenient, quite fast, and doesn't attract any attention. >> In Mac, the standard search Spotligh, it also indexes everything that is in your Mac. And you can find any info very quickly. It's already indexed there in literally seconds. So you're talking about something like that, right? Well, for the most part about Windows. There are also various offline DBMS, Chronos, Archivvarius 3000, Docfure, which work with text leaks. What is needed for work? I can index different options. I can index a relational database in Chronos to have the ability for global search. Approximately the same way "Eye of God" did it, so that it is exported in standardized report forms. I can use Archivvarius. In that case, I will essentially have a non-relational database in my hands, which will search by partial data, for example, by a piece of an email address, by a partial phone number from the access recovery system, it will find all similar options. And what bots and relational databases couldn't do, in principle, everything is strictly divided there, and an incomplete identifier cannot be checked and data cannot be obtained from it. What is a time attack? >> A time attack is probably more of an analytical method that allows you to test a hypothesis. Example number one. We have Darknet. We have some villain who regularly goes to Darknet. We track his presence on a particular platform by his nickname and record the time of his presence. After that, we turn, conditionally, we don't have such databases created today, but if they were created, we would turn to this data array to operators, to telecom operators, since their traffic is different, we would ask: "Dear operators, who went to Darknet at a certain time?" They would tell me: "Well, 100,000 people." Okay, let's look at the next online access. Who went this time? Another 100,000 people. And who went the first and second time? Repeating 30,000 people. And the third? And the fourth? Thus, a certain small capacity of those who could be involved in this profile is achieved. Another example. We have a Telegram channel, posts are published on it, and we have users who are suspected administrators. We put them under control, we record their online access to Telegram and simultaneously record the publication of changes or posts on the Telegram channel. After some time, they start to coincide. Our hypothesis is confirmed, that most likely this person is an administrator. >> Yes, but this is complicated if you turn on VPN and do all actions in it, whether it's further access to Tor, or actions with your Telegram channel, and so on. >> Yes. Yes. Plus, you can also hide your online access from an external observer. This all limits, but does not cancel the methodology itself. By the way, there are so many VPNs now. I look at targeting, somewhere on, well, you read some channels, and there's Telegram advertising targeted. I just collected, probably, about 40 of them, specifically in Telegram, specifically all sorts of VPN bots. And I see that many of those that I collected a year ago are no longer working. And in principle, the reason is quite simple. I was surprised, well, okay, I can start any business tomorrow, right, VPN is, well, a low-margin product. And it's okay when it costs 5-10 dollars, well, five, let's say, per month, and you have your own traffic, then okay, your economics add up. But when you have a VPN, there are certain costs and so on, you sell monthly access for 100 rubles, and you also pour into Telegram, well, this Telegram MS, well, somehow the economics don't add up, but there have become many more of them, of course. And in this regard, what is the next step? Well, they immediately blocked Insta, Facebook, Twitter, what else? LinkedIn, right, harmlessly, it's been blocked for 100 years, and YouTube is blocked. The next step is this, figuratively speaking, Cheburnet, what we see, for example, with Telegram and so on. And most likely, the next thing, I think, it would have taken several years, but these white lists of IP addresses, because, well, for example, everyone needs to be switched, all banks, all websites, all media, and so on, to some Russian pool of IP addresses, right, and if I were doing this, I would probably create some Russian analogue of Cloud Flare. Well, if you are given an IP address from this Russian analogue of Cloud Flare, then it is a priori in the white lists. But it seems to me that this process is very slow and would have taken, in any case, given the size of the country, the network infrastructure, probably 2-3 years. And what do you say about the complete blocking of YouTube, Telegram, and everything else, and when our Cheburnet arrives and entry or exit, rather, to the internet by white addresses. I can also say here that I lived in Belarus for a considerable time and I know that internet access by passport is possible, in principle, if the authorities wish, to a certain extent. Of course, one can somehow bypass this, and it was even possible to do it, but for the most part, for a significant mass of the population, and we are talking about such issues precisely about a significant part of the population, because everyone understands that individual enthusiasts and smart people will always be found, but the main mass, the main core of the population still needs to be controlled. Personally, I doubt that, in principle, this sovereign internet is achievable. The Russian Federation is too much of a European country. We are part of European culture, part of European business. In general, in principle, part of Europe, part of the civilizational path is directly connected with Europe. The larger part, the more modern part, than with Asia. Therefore, I believe that it will still be impossible to do this completely. It may be possible to try to restrict certain resources. And this path is probably what is happening now. Perhaps it is necessary in connection with the conduct of the SVO, with risks, with drones, with these, like in StarCraft, trucks are already driving, equipped with drones. Soon ships and planes will fly with drones, so the risks are high. People with backpacks, famous drones, will probably appear. Yes, it is necessary to fight this. Blocking of individual GSM connections is happening. What we saw, I came across this, in St. Petersburg, connections were blocked. I couldn't call my child, or pick him up, or order a taxi. This is a problem, this problem is temporary, probably, it will have to be solved. I want to wish that the special military operation is completed as quickly and successfully as possible. >> This is terribly annoying. I remember arriving in Sochi, and there, well, Putin was there, the whole government was there. And I was in Sochi, okay. I arrive at Kadler, there's the airport and all that stuff. And it's there, and you have no internet for a day. Until 8 PM, you have no mobile internet. And this is, well, nonsense, actually. That is, and it started with officials, then drones and so on. And this I, well, this, in short, is a huge inconvenience for people. Moreover, I read that at PMIF, right, you can't call a taxi, nothing. In short, a whole bunch of problems. So, you don't think that sovereign internet, right, and white lists of IP addresses, and so on, will appear in the coming years? >> In full, I think not. We are too dependent on foreign resources. Therefore, they will restrict something, maybe gradually replace it. You are talking about 2-3 years? Yes, this process may take 2-3 years, but, I think, by its expiration, even earlier, the prerequisites for carrying out this process will disappear. And if they disappear, then what's the point of doing this? >> Online drug shops, that is, large platforms, it's clear, there, coordination of special services of different states is usually needed. somewhere the human factor, someone makes a mistake, and so on. But these ordinary drug shops on platforms, have you identified them or not? And if so, how? I had a friend, a comrade, who was purposefully involved in this. We cooperated with him in this direction. For the most part, despite the fact that I gave many comments, appeared on broadcasts about these drug shops, I didn't really deal with them. maybe I provided partial informational support, suggested something, had an agreement with the GUNK and other departments dealing with these issues, trained them. What was it built on? Firstly, on the fact that a huge number of administrators, users were recruited by similar guys, similar investigators. Recruitment, identification was built

Completely differently. Somewhere they caught a stasher, took his phone away, conducted analytics of all these tags, all the points that were used to distribute prohibited substances. For example, the famous St. Petersburg case with eighteen tons of salt was investigated like this. >> I don't >> they really took a guy, a few years ago he was a stasher. They watched him for a long time, controlled him, he reported on all the stashes. But they only really got results after they broke into the account of an administrator of a different platform, moreover. And that platform, which they broke into, had relations with, uh, precisely the factory that produced the salt. And they ordered a wholesale batch. And the wholesale batch was brought to a completely different place. They tracked it and heroically led it to a small warehouse located in a forest belt. And then it took about, as far as I remember, two months to convince law enforcement agencies to visit this warehouse and, at the same time, not to reveal, of course, the people who conducted the investigation. After some time, a heroic figure of a local policeman appeared, who had 5 days left until retirement, and he decided to direct his steps to this warehouse. He went there, epically scared away three drug addicts who dropped everything. One returned later, and he was actually blamed for this warehouse. All further materials, developments, the development of the group, all its network infrastructure, were simply uninteresting. 18 tons of salt were epically seized. The guy who returned to this warehouse, who said he was from another region and had nowhere to go, was epically caught. The whole case is closed. A month later, the same group continued to operate under a different name. And did you have to investigate ordered murders using internet methods? >> Yes, even the most famous murder of Yevgeny Shishkina on October 10th, if I remember correctly, in 2018. >> Who is that? I don't remember. >> She is a police investigator, a police lieutenant colonel. She was investigating the ticket case of Yaroslav Sumbaev. According to the investigation, he ordered her. We were involved in this case when Telegram just emerged. At that time, we were building Telegram Dнимаimer, one of the software products for investigations in Telegram. It was known that Shishkina was threatened before her murder from an anonymous account. This account had the same nickname as her residential address, Arkhangelskaya, house number, apartment address. A phone number was needed to try to figure out who it was. That's when we extracted this phone number, traced this whole story with the user to St. Petersburg. This happened on October 12th. And after another 6 months, the official investigation also came to St. Petersburg to detain Abdulazizov, who committed this murder. >> Well, and it was him, yes, who threatened her on Telegram. >> And this, by the way, remained in the investigation materials. I don't know for sure. Most likely, the phone number was obtained somewhere in Russia. Sumbaev himself could have threatened her, presumably. Then this story had a continuation. The Loszeta was investigated, not a hacker, but a drug trafficking shop of the same Sumbaev in the darknet. He was extradited from Georgia to Russia. There were already a whole bunch of adventures. >> Is it easy to get any information from Russian services like taxi, delivery, and others, unofficially? Well, officially and unofficially is clear. That is, an FSB or Ministry of Internal Affairs unit writes requests, waits, calls the necessary acquaintances to speed things up, but unofficially. It all depends on the top. If there are agreements, if there is consent, if there is an opportunity to pressure, it all happens quickly and easily. Even law enforcement officers have completely different situations. Law enforcement officers in the regions, the same specialized units that deal with cybercrime, internet fraud, they can wait for a response to a request for 4 months, as if from scratch. from the same unfortunate VKontakte. Therefore, there is no single system. Plus, there are methodological recommendations, and I wrote them, among other things. What exactly to request and what the service should provide you. Do you think anyone provided complete information from what they contain? No. They can write back what they considered necessary. They can even write that they do not have the technical capability to provide this information. Therefore, until this work is systematized or a centralized database appears, where, for example, user logs, their registration data are entered, as it exists in Ab, for example, we will continue to live in the paradigm of needing to send hundreds of requests and then wait for months for answers, hoping that something adequate will be sent back. It is very sad from the perspective of us, those who work with identifying digital traces, which are most often used to make requests, and there can be interesting nuances here. I really liked the story at one time. We also investigate owners, developers, administrators of websites. Many of them use Yandex.Metrica. You can write to Yandex.Metrica support, and it will tell you which email belongs to this Yandex.Metrica by identifier. This is a small life hack. Yuri Drugach described it in his book at one time. I checked it later, it really works, support provides the email address. A similar story exists in Odnoklassniki. >> Well, you can also take Google Analytics there, and then that service, not Metrica, but what is theirs? Yandex Webmaster, then Google Search Console. Well, Google, it's clear, will send you away now, but Webmaster, yes, and Metrica, that's two things. Then you look, for example, analyze the main page, look at what scripts are installed in the header or body, what pop-up windows, and so on. You can also request from them, and so on and so forth. In principle, I understood the direction of thought. Yes, yes. Yes, depending on the technology on the web resource, the most important thing is to understand what you can request from them. That is, that they are friendly countries, Russian services, because, well, Americans will clearly not give us an adequate answer now. So yes, in general, the methodology is like this. But again, speaking about law enforcement officers and what we could use within the framework of conditional asint, this whole story of mine about investigation is a long story about collecting something that works and has the ability to replace existing operational-search activities. such products made from sticks, branches, and duct tape. Here, for example, we can recall 2018. I had developed the LPOisk service, and it was the only service that publicly provided the exact geolocation of a mobile phone at that time. At that time, detectives sold it for 10, 20 thousand rubles. It was called Vspyshka. Information about the current position of a mobile phone via a base station. And we got it simply from SMS centers. For a long time, SMS centers directly transmitted information about the base station, that is, the identifiers of the base station where the mobile phone is located. Then they started to mask this information, they issued a unique code for a group of base stations, but this was also circumvented. We could drive around the city for half a day to collect. You understand where you were, that is, and what the code of this station is? >> Yes. We continued to provide this information, and then they finally stopped publishing it in April 2018, and the game was up. But it was fun, it was interesting. >> How much has this market shrunk now, right? Well, besides the fact that prices have increased, how much harder is it to get information now, because, well, I needed certain information that I used to get for, say, 20 thousand, now probably for 50 I paid for it. And it turned out to be much harder to find. Well, it was information about me specifically. It didn't go anywhere else. And the person knew that I was looking specifically about myself. Maybe that's why they met me halfway. Well, how has the market changed >> here immediately? The story is also like this, uh, from several components. Firstly, the information retrieval market itself has, of course, fallen significantly. And the supply that existed some time ago, it still existed, say, in 2023, already during the SMO, when there were various publications on Ukrainian hacker chats where my personal data was published, Pasha Sitnikov's, Slipari Fox's personal data, they shouted that we are bad people. Moreover, guys from Ukraine were asking: "What exactly did they do?" Trying to mumble something. And what did they do? They speak ill of Ukrainians. Ah, well, that's it, they're done. >> In my opinion, Sitnikov is a slightly strange character. I still haven't figured him out. In short, he constantly talks a lot, throws some kind of aura around himself. I'm a super hacker of the whole world, something like that. Well, guys who have real knowledge and skills, well, I know many historically, well, they behave much more modestly. Therefore, Sitnikov remains a dark horse for me, this Fox. Here, everything depends on how you sell yourself. He positions himself. So, I am inclined to think that a person with knowledge, a person with high intelligence, as a rule, strives to constantly doubt something, to look for additional options. Why don't they take people with an IQ above a certain level as astronauts? Because in a critical situation, instead of following instructions, they try to invent new methods and techniques of work. In my opinion, an IQ above 130 is not allowed. As for this story, then our data, the form from the passport office and so on, was indeed published, and an investigation was conducted. As a result, the MoscowCAO burned down, in the central apparatus, oh, not in the central apparatus, but in the central autonomous district, right? Here is such a whole department, a subdivision, I think seven or eight people were fired, who purposefully, for a long time, sold personal data, including with full awareness that they were selling it to the enemy in the context of a special military operation, that is, they were essentially committing treason. And it was, well, so unscrupulous, so blatant, that it becomes creepy. People are used to working the way they are used to. They are used to earning the same money as they are used to. They have built an industry out of this from my perspective. My work with illegally obtained information is practically absent. We transfer 80% of cases to court, civil, administrative, criminal, it doesn't matter. But we are obliged to record only legally obtained information. Therefore, our task is precisely to identify what the court or law enforcement agency or investigative body will use for its official requests. To identify precisely those signs by which they will obtain the person. Or if it is possible to identify the person himself, because the main task now in information and telecommunication crimes is precisely to obtain the person. Earlier, when crimes occurred mainly in the physical world, well, it was clear, there were certain suspects. Someone stabbed someone. I am from St. Petersburg, from the former Leningrad. This is a popular story, yes, a girl changed, I sit, I saw, therefore we are used to it. There was always some suspect, there were fingerprints, there were witnesses, grandmothers at the entrance who saw a young man coming out with four bags, something always caught the eye. With the advent of the internet, a lot has changed. Naturally, a new system of criminal accounting and identification is also needed today. Instead of meticulously digging something out of a website, from a Telegram channel, the approach to the work of forensic experts and investigators needs to be fundamentally changed. Therefore, most of our work is purely legal, and we are engaged in digging out these identifying signs by which a person's identity could be further extracted. And how would you assess the professional level of our, let's say, cyber detectives? Well, let's not take private firms, like yours, IB, and others, but police officers who are involved in investigating computer crimes. Just the Belarusian ones, I can assess as very, very good. So, I think you interact with law enforcement, well, plus or minus privately with other countries, and so on and so forth. And to sketch a rough hierarchy table. That is, do their hands grow from the right place or not at all yet. As for the Belarusians, Gomel, Brest, a solid five points for the department for technological crimes. In Russia, based on interaction experience in 2022, when we were investigating mass cases of virtual mining, we interacted with Belarusians, Kazakhs, and Russians. In Russia, everything is very difficult. In Russia, information is difficult to share. In Russia, information exchange is difficult to organize not only between countries, but even between cities, so everything gets stuck. That is, when we were investigating mass swatting in 2022, just before the special operation, January, February, March, we, in essence, coordinated all the work and information transfer between Russia and different regions of our country, between Belarus, and other countries. Then, successfully, from January 4th to 17th, we identified, probably, the majority of the organizers. And all the remaining time they were just being detained. In February, 14 people were detained, in March, 10 were detained in Belarus. Ukrainians, for obvious reasons, were not detained and continued their activities. >> So, were these organized groups doing this? >> There was organized coordination. Most importantly. This coordination began with the activities of the Vex miner, if you remember, 2019, 2020, 2021. A guy who said that he was burned on the Vex crypto exchange, that his 120 bitcoins were stolen, and therefore Konstantin Malofeev personally owed him, and until he returned his 120 bitcoins, he would mine airports, kindergartens, schools, public institutions, and so on. And he did this for 2 years. When we conducted the investigation, this was later also used by the Ukrainian SSU to refute our investigation, we proved that the Vex miner was an employee of the 83rd Center for Information and Psychological Operations. They even published his personal data. This was in an RT report at the time. This is where the new wave started. From professional virtual mining. They decided to involve a large audience, they prepared for it. Legends were spread among the youth that there are groups of swatters, that they are paid money for this, and this desire was ignited in them. They all wanted power. The children with whom we communicated during detentions, psychologists talked to them. And what did you want? You suspected that you would be found, you would be brought to justice. They all wanted power. Power over the state, power over the school that opposed them, power over the institute, simply power over the teacher who bullies them, and because of this, we mined the school. Someone wanted to get money, someone was really told this legend. Then the most interesting thing came out when we combined, we built the "Okhotnik" software complex for this time, which investigates technological crimes in general, a Russian hunter, in short, when we put different investigations into it, including investigations into swatting, investigations into destructive communities existing in Russia, and investigations into, uh, suicidal groups, it turned out that they could all be coordinated from one place. And this place appeared in the darknet, because we found threads and found crypto wallets that coincided in all three topics, in all different investigations. And then they led to the understandable guise of foreign special services. So, information-psychological operations and work on criminal training in general have been going on for quite a long time. >> And we've already touched on cryptocurrencies. I sometimes read on Twitter, well, it's not blocked for me, thank God, I read the investigations of Zak Zag BT. This is, you know, a guy who investigates all sorts of things, like exchange hacks and so on. In short, he writes very interestingly. Well, in short, he studies the blockchain and shows what connections there are, affiliations, who withdrew where earlier, and so on. And what do you do in crypto? >> Yes, practically the same. It is important to understand what we can legally do. As data analysis specialists, it is important to observe this legal boundary. We, law enforcement agencies, courts, customers for the court, they formulate a list of questions. We, as specialists, can only answer these questions. At most, we can explain to the customer what should be included in these questions. The professional level of customers is also quite varied. And they do not always understand, they often ask questions that we are not competent to answer and cannot provide to the court. We have to train them in this regard. What have we encountered? There have been many investigations, including the investigation of this Vex miner, which was published by RT. At that time, cryptocurrency transactions were tracked. Mendeleev, by the way, Alexander also tracked these transactions in parallel, and they were withdrawn through Binance. That is, it was clear that the Vex miner received part of the sum he needed, and about 400,000 in rubles at that time, and got greedy, decided to withdraw this money, withdrew it through Binance. In parallel, here comes the most interesting story, that in parallel, cryptocurrency obtained from the activities of Vex miner distributors of ransomware, who were actively operating in Russia, China, and the European Union at that time, entered the withdrawal chain. And from them, when the special military operation began, leaks from Bereginya, from other organizations were planned, we gathered some information, and it was possible to find out that the same email addresses that were used by the ransomware for communication were later used, again, human factor, they were used to register accounts on Medium, on Kont, which then spread fakes regarding the Russian Federation. And from there, information was obtained that this is all part of the work of the 83rd Center for IPO. So the investigation was deep and interesting. We can also mention Alexander Mendeleev, who also conducted his investigation in parallel. Sergey, >> yes, I'm wrong, yes, Sergey Mendeleev, I apologize. I hope he won't be offended. >> I think he definitely won't be offended, especially if we show and talk about his channel. Recently, criminal liability was introduced for droppers. Yes, well, for me, it's a funny word, of course. Droppers were invented. For us, they have always been, are, and will be. And they did it, well, basically, according to the Belarusian scenario, because in the Belarusian Criminal Code, there is an article for providing one's card to another person. It has been there for 1000 years, probably since the existence of the new Belarusian updated Criminal Code in 2000. But I haven't seen it applied to anyone in Belarus, if I'm honest. And in Russia now, it, well, it seems to be starting to be applied. And there are already problems with requisites. I also have payment systems in some businesses, like PSBPs, and so on. And what used to be, say, 6-8%, now it's 12-14%, there are constantly no requisites, it's a whole problem. Yes. Mendeleev posts that often a person who simply helped to cash out some amount, a completely harmless person, not from the criminal world at all, and simply through their account on a crypto exchange or somewhere else or through their card passed money, and they are considered one of the main suspects, and later accused of a rather serious crime, right? What danger do these drops pose to the state and society? Well, let's be frank, of course, from the state's point of view, this is all absolutely wrong activity, because, uh, it hits the budget very hard. That is, these are taxes that did not go into the budget, that were not calculated correctly, that were not transferred, that the state did not receive and, consequently, cannot count on them. Therefore, from the state's point of view, this is, of course, a terrible thing. >> Like money in the shadows, right? >> Yes, yes. I was very, we were just discussing recently with guys from the nineties who survived all this, all that time. What was the peculiarity and difference of the nineties? The difference was that the country survived at that time because there was a huge, uncontrolled cash money supply. The state, yes, had some budget, it trembled over it, fought for it, but it was very small. But a huge cash money supply existed outside the state. And it was through this that various careers, palaces were built, criminal groups worked, all business worked thanks to this shadow cash. >> So the same thing is happening now, because, well, many are forced to even do crypto exchanges, right? Like, I need to deal with some salary issues, or something else. So, if before I would have withdrawn from an exchange to a card and distributed it to employees, now I don't do that, because, well, banks just don't let me do that. Accordingly, the second wave has started, cash has come, for example, cash, which I withdraw in the city and deposit, for example, to a card. But now, even this is not allowed from this month, well, from last month, to be precise, I can no longer deposit cash to a card, well, as a reliable source of money. And I simply have to pay everyone in crypto or distribute cash. The state, well, loses even more money turnover, it goes even more. This is like a fight between armor and a projectile, right? The more they tighten with this 115 and what is it, 162 or 152, the more money goes into cash. It seems to me that the nineties have almost returned in this regard, or not yet? >> Well, I don't think they have returned. The grounds are fundamentally different. We will not compare a person with your experience, with competencies, knowledge in business and in working with money here. And the majority of the population, the state counts on large masses of the population that it must control. It does not set itself the task of controlling 2%. It wants to control 98%. This is important to consider. And these 98 are subjected to this control. Most of these measures are introduced against them. That 2% will bypass them is clear. They will find methods and techniques. But controlling 98 is necessary. Therefore, sooner or later, we will come to the point, well, already now, how many cashless transactions are currently being carried out. The last time I was interested, about a month ago, it was 17%. It is considered that 17% of settlements are carried out in cash. Previously, it was 70%, not so long ago, say, 10 years ago. But when I lived in Moscow, I basically, well, here, in Thailand, I sometimes need cash, to pay in restaurants and so on. But in Moscow, the QR code service for paying tips, yes, I don't remember what it was called. There were periods in my life in Moscow when I didn't hold cash in my hands for 2-3 years at all. Well, absolutely. So even tips via this QR code. And you say, in short, 17% now are cash operations, right? It was 70%, >> yes, and the share is decreasing. Employers arrange salary projects, arrange cards for employees. Very developed involvement. Practically like drugs, they attract people with these credit cards, they almost forcibly shove them. >> Yes. The funniest thing is when Russian Standard called me about once a month and offered me a credit card, I tell them: "Well, you've probably already noted that I'm a Belarusian citizen and, well, I couldn't get a loan, at least, at that time, in the Russian Federation." I say: "Just, you know, don't call, don't waste my and your time." And, probably, plus or minus the last questions. And many law enforcement representatives with whom I have communicated before, yes, they, you know, say that the level, well, some say it's high, but I understand that for investigating phone fraud, these call centers and so on, it's negligibly small. How would you investigate a similar case, and have you had them in your practice at all? >> Well, for starters, statistics. We are told that, well, on average, crimes committed in the country per year are 2 million. >> Is that a lot or a little? >> That's a stable figure. They even try to reduce it slightly every year. Long, meticulous work of staff departments on statistics, nothing more. The share of crimes committed using modern technologies is growing. We are talking about crimes, that is, acts that caused damage from 5,000 rubles, which can be qualified as a crime. Their number exceeds 650,000, I think, committed crimes. That is, according to various estimates, today up to 40% of crimes are committed one way or another using modern technologies. That's one point, that's official statistics. Now about the factual side of the matter. Let's take any of the top Russian banks, for example, the largest one, we won't advertise it. It claims that it has over 10,000 unauthorized debits from citizen accounts per year, that is, which should fall under criminal liability, exceeds a million. This is one bank, even if it's the largest. There are many other banks, and there are many other types of fraud. Who is right? Official statistics of the Ministry of Internal Affairs, official statistics of a state-owned bank, or some speculative conclusion from an external specialist, given that all these external specialists tend to believe that the actual number of crimes is likely about five times greater than what is officially declared by law enforcement agencies. >> Well, the answer is simple. Computer crimes are not only in the Russian Federation and so on, they are, well, they have a latent character. That is, neither victims nor organizations that have had a leak and some unsightly action are, as a rule, interested in excessive fuss. And therefore, I think that, probably, the bank's statistics, yes, collected plus or minus from other banks and so on, probably, yes. Then maybe three million, probably, five, well, five, probably not, 1-2 million computer crimes alone, yes, and

Not 600,000. >> This is a crime. And now let's move to the category of administrative offenses, which, uh, by law, cause damage up to 2,500 rubles, but in fact, considering the difference between 2.5 and up to five, that is, everything that is from 2.5 to five, it is interpreted in the direction of reduction, in the direction of an administrative offense. Their number has never been counted at all. How are they investigated? Are they investigated at all, considering that a large number of operational-search activities cannot be applied to administrative offenses to ensure their investigation, most likely, they just get rid of them with written responses. And, unfortunately, that's where it all ends. >> Well, how would you investigate, for example, or or have there been cases in practice with these call centers? >> Have there been cases in practice? First, if I'm a security officer, I have SORM, and we've already discussed with colleagues the issue of using SORM for end-to-end analytics to determine the location of call centers. This is quite feasible. The second story is private investigations. And by interacting with those individuals who came out of these call centers, sending them various, let's say, not very good content, as a result of which their, uh, infrastructure was revealed to us in the end. They are also ordinary people, they mess around, they open all sorts of bad links, >> like a phishing link is thrown at them. Well, I know such services. There, you either create a picture, which then allows you to trace, or a link, and that's it, their IP address is recorded, if they are without a VPN, >> a picture, a link, a check, a payment receipt, >> anything. A transition to something from the Russian ecosystem of services, to a Russian file-sharing service. There are many options here with conditional phishing, with obtaining a digital fingerprint, with obtaining computer data. for attackers. Well, many, not infinite, but quite a lot. How often is fingerprinting used in investigations? In my businesses, for example, I save it. That is, if, well, I save logs of all IP addresses, for example, in e-commerce businesses, well, where money is involved, where they can be hacked or there are fraudulent transactions, I save the IP address of registration, for example, and logins and all significant financial actions. For example, a payout was made, and so on. But I also save the fingerprint for this. I've never had to compare it under a microscope. Because people, if they get caught on multi-accounts or something else, well, on some kind of burden, then, as a rule, they are caught either on IP, or on a range of very, very similar IPs. Well, as it were, it's clear from the outside that the same organization acted, but I've never used fingerprinting, but I collect it. Do you use it in any way? >> We use it constantly. It comes up in investigations. Now there have been a lot of investigations related to vulnerabilities in Bitrix, other automation systems, banal things. All Bitrix sites were hacked, the largest ones were taken down. >> Yes, but we are investigating financial damage for the most part. That is, a hacked Bitrix, someone, well, there's the same basic vulnerability, you can duplicate, for example, an order. Well, you have some kind of service, you sell something, and using a robot, you can create 10 orders instead of one at the same time. This was a recent investigation. There we calculated the attacker's infrastructure using digital fingerprints. We found out that he has been doing this entire activity for a year and a half successfully in the company, gradually milking it a little, then he decided to overdo it and got exposed. >> Is MAC address something like an analog of fingerprinting, perhaps at the hardware level? I just remember, well, I first heard about MAC addresses when Webmoney Keeper was installed by security specialists, there was no such thing yet. This was in the mid-nineties, there were no Habr or anything. But Webmoney already existed. And we thoroughly researched and investigated how they get the MAC address of the hardware, this Keeper for Windows. And theoretically, a MAC address, well, it's like an identifier, right, undeniable for a device. You won't dispute in any court that it's not your computer anymore. You won't say that, like, no, the computer isn't mine, here's the MAC address. And I remember there was such, well, not a legend, most likely it's true. We just never tried it, that if you change some important component in the computer, like a hard drive or a video card, then the MAC address and you reinstall Windows on top, the MAC address changes. Or is that not the case? >> No, the MAC address does not change. The MAC address can now be randomized. It is, at least, randomized in Android. >> Network card. That's what I'm confusing. If you change the network card, >> yes, the network card. The network card, yes, it essentially is this MAC address. It is now randomized on most operating systems, but randomization occurs within a given list. That is, the list of these random MACs on one device is still limited, so that the manufacturer can understand what kind of device it is. And the second point related to MAC addresses, which interests us a lot. At the University of Washington in 2017, there was a study that presented a new tracking technology called One. We repeated all this in 2019 here, in our educational institutions, and came to the conclusion that this is a very promising area. That is, you have a phone number, an email address as input, which may not belong to this person anymore, even today. At the same time, we proceed from the fact that all search engines continue to stitch together your digital portrait. At least, this is their self-goal. Even if you throw away your phone, change your phone number, they will still strive to collect your unified digital identifier, to bring it to a single one. And the MAC address of the device, the Google Android identifier, the iOS identifier also fall into this. And these five input parameters can be used for One. What does this allow? It allows, at least according to the 2017 study, to run targeting in the form of banner advertising and, based on banner advertising, to obtain the social graph of users using these devices, to track their movements through banners, through applications. In 2019, in Israel, the Echo development appears, which no longer runs banner advertising, but simply buys this information from the largest holders of this data from Google, from Meta, quite legally. I even have a presentation in my channel. They write that they receive, for example, geotags from Facebook, geotags, analysis of user communication from Mail, from WhatsApp. Then, also in Israel, the Lavander development appears, which uses these same technologies to detect terrorists and their connections and to guide warheads. Here, the fair question immediately arises: "Why does the Facebook application request geolocation data every 5 seconds?" In the same 2019, we conduct our own research here, thus giving birth to a third approach to One. It states that we can use this same data, since it has already been accumulated by the largest holders, by Yandex, Sber, and other companies, for our own purposes. And these purposes are closely correlated with surveillance. Let's take an example. We have this MAC address. We can use it in the Yandex.Audience service as a mobile device identifier and, based on it, obtain data about the user using this MAC. Gender, age, city of residence, search interests. Yandex will simply give us this for free. >> There are exits to Siz, I think, and Wi-Fi and so on, right? >> Well, that's already internal. General statistical advertising information, it's very much age group, gender, interests, city of residence. But further, when we start, uh, to do an advertising campaign in Direct, we can start tracking. We have a created audience with this identifier. We launch Geotargeting, we select geozones where this advertising should be shown. Place of residence, work, train stations, airports, recreation areas, each separate advertising campaign. And then it all works when the user enters the geozone, they receive this advertisement, and we receive notifications in our personal account that they have entered there. The same thing is now offered by mobile operators, but there the story is a bit different, because a live mobile phone number is needed, to which they will be linked. But in principle, the possibilities are also colossal. We just, uh, before our meeting, discussed an interesting story with the possibility of unfair competition, precisely using modern advertising tools. The fact is that, let's take some major electronics manufacturer, well, any absolutely, like LG, for example. This is not related to it, but it might be interesting. The company is forced to support service centers that repair their equipment, they usually repair it for free. And then scam appears, as they think, either insight or scam. Someone is either leaking data of people who contact service centers, complaints appear. That is, clients say that your company's master came to them, said that you now owe us a lot of money for equipment repair, and if you don't give it, I might not return the equipment. The first scandals, lawsuits, proceedings begin. We join this investigation and find out an interesting fact. It turns out that all the phone numbers of the company's service centers were collected from the internet. Then, from telecom operators, advertising was ordered for them. Everyone who called the service center should have received a message within 10 minutes: "Master such-and-such has been assigned to your order." Call him back at the following phone number. That's all. No crime, no insight, no leaks, just marketing, nothing personal. Thank you. Igor Bederov, please love and cherish. Internet intelligence, by the way, write any questions you have, what you have formed about the release, what we haven't covered yet, and I think we can meet on a more regular basis. That's it. Subscribe to the channel. Hugs to everyone. Bye. Lyuti. I'll tell you a thousand schemes to multiply by two to make a profit. I've been well-known for a long time. Now I'm sitting opposite you. This is our manual, according to which someone will decide to earn money. People about people about only your and my life experience. I'll tell you a thousand schemes to multiply by two to make a profit lyuti. I've been well-known for a long time, now I'm sitting opposite you. People, this is our manual, according to which someone will decide to earn money. People about people about only your and my life experience. People about people about It's people's curse. It's people's curse. It's people's curse. It's people's curse. It's people's curse.