episode.ascii — live render
● episode

The Lorebook Cult

TL;DR764, an online abuse cult started by Texas teen Bradley Caden Head, coerces minors into self-harm and documents it as tradeable "lore books." Two leaders were arrested in 2025, and the FBI links 764 to broader cybercrime networks…

Content warning: This episode contains descriptions of exploitation, self-harm, and abuse. Listener discretion is advised.

A network called 764 has turned abuse into currency. It spread through Discord, Telegram, and gaming platforms—built around “lorebooks,” collections of coerced violence traded for status. In a strange twist, this harm group has connections to cybercrime groups we've covered on this show before.

Note: I was recording in an office, which between that and the subject matter, explains why my tone is pretty hushed in this one.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: Heads up. Listener discretion is advised. This story contains depictions of abuse, including self harm and exploitation of minors. I think a good way to understand this story is to start with the concept of lore books. In certain very dark corners of the internet, lore books are a kind of currency. They're how members join, they're how they earn status, they're how they move up. A lore book is a collection of files photos, videos, and screenshots documenting harm. Sometimes physical, always psychological. These are unfortunately some specific examples a lore book might contain photos of a person cutting a username into their skin, a pet being harmed, or a victim being coerced into something explicit. The more extreme the material, the higher its value inside of these groups. That's a lore book. A portfolio of evidence of abuse. I think we're all unfortunately aware that there are, like, dark corners of the internet that exist where this kind of exploitation is produced, traded, and consumed. But in those communities, the abuse material is kind of the end goal. It's the product, it's a marketplace for that kind of thing. What makes this weird is that in groups like seven sixty four, which is what we're talking about today, due to some recent arrests, the abuse isn't the entire point. It's more like a tool. Kind of a mechanism used to manipulate, to initiate, to radicalize, and to indoctrinate someone into joining what's basically a cult. 764 is a decentralized online abuse network where members coerce mostly minors into acts of abuse, self harm, and violence, and then trade that content as a digital currency. It started on Discord, it spread to Telegram, Roblox, Minecraft, and while it might look on the surface like a grooming ring, which it is, its structure operates more like an online extremist movement. One that builds loyalty through obedience, tests boundaries through cruelty, and rewards participation through this really rigid hierarchy. To give a little bit of evidence that we're dealing with something different here, the FBI has now opened more than 250 active investigations into seven six four, and federal prosecutors are beginning to treat the network not just as a child exploitation ring, but as a domestic terrorism threat due to the extremism and cult inspired structure, it has it's happening in The U S Canada, Romania, Germany, The UK, Turkey victims have been identified across three different continents and as dark as it is. I think this story would still land within our wheelhouse as it stands. But here's where it starts to get really odd. This isn't actually the first time we found ourselves circling this group on this show. We just didn't know it at the time. Seven six four is a small part of a broader ecosystem known as the Calm. It's a loose network of cyber criminal clicks that includes like SIM Swappers, data brokers, social engineers, classical, just just cybercrime, nothing to do with harm or abuse. Many of whom have been tied to really high profile attacks that we've covered on this show. The Calm, and again, this is not seven six four, but the larger org was tied to the MGM Resorts hack, the Snowflake breach, taxpayer groups like Lapsus and Scattered Spider. Seven six form is an online harm cult. Those are cybercrime groups. Some recent reporting from spots like Krebs and Wired has revealed that at times throughout that history, it was the same people in both. And that overlap kinda really matters because what we're starting to see now is a growing intersection between cybercrime crews and this harm based extremist model. The circles of the Venn diagram aren't touching too much, but the fact that they're touching it all is alarming. People using extortion tactics developed in cybercrime forums to recruit victims into this cult like environment. In April of this year, two alleged court members, Leonidas Vargiannis, a US citizen living in Greece, and Persan, Nepal from North Carolina, were arrested and charged with running one of the group's most violent subgroups, which is why we're talking about it now. So let's dig into it. The rise of seven six four from a teenager's discord to a global cult of digital abuse and the growing convergence between online harm, radicalization, and cybercrime. You're on Hacked. How you doing, Scott?

Speaker 2: Pretty good. Pretty good. This story sounds like it's gonna be pretty intense, but I am good. How are you doing?

Speaker 1: I'm doing okay. I definitely spent quite a bit of time reading about a pretty dark thing, but it's an interesting one, and it seems pretty important.

Speaker 2: I'm intrigued. Like, obviously obviously, you know that stuff like this exists on the Internet. You know that there's, like, dark there's dark souls out there, not the game reference, but, you know, the people reference. There's dark souls out there. And there's, like, corners where those dark souls hide in the Internet. So you say you kinda have a a gut check that, like, if there's something that could happen on the Internet, it probably is happening on the Internet. Mhmm. I'm I'm fascinated by the overlap to cybercrime. That's where it gets me, because to me, those two things don't typically go together. To me, young cybercriminals or hackers or people that I assume are problem solvers and, you know, interested in challenges and overcoming things, and then they're kind of pursuing it from that angle. I don't see them. I but I guess in every bell curve, there's three standard deviations for the mean either way. So it's like if a community is large enough, you can assume that there's representation from every other community inside of it.

Speaker 1: I think that's a good way putting it. Like, in order to do a lot of the stuff we cover on this show, in order to be a, like, a problem solver, a hacker, a puzzle kind of cracker, you have to be willing to break things.

Speaker 2: Mhmm.

Speaker 1: And there's always, you know, say 95% of people are willing to break something in order to do that goal. We've kinda seen stories like this where 5% of them are in it for the breaking. I think what this is is that same ratio, but maybe seen on the social engineering side.

Speaker 2: Mhmm.

Speaker 1: Or more often than not, people are willing to manipulate, betray trust, but it's normally part of a larger project. The betraying of trust and manipulating people and getting control that way isn't the end. It's a mean. And I think what we're seeing here is like, well, what if a community spun up where that was the end? That was the thing they were trying to do was the social coercion. There was no point to it other than the control.

Speaker 2: Yeah. So I guess to to carry on the analogy of breaking into things and breaking things, maybe you're just figuring out how to break humans, which is kind of what it sounds like.

Speaker 1: There's been some really good, reporting by this. Wired has done a bunch. Krebs on security has done a bunch. He was really who made the connection between this group and the comm, which again is, to be clear, not a harm group. This is a cyber cybercrime group, that has connections to this. But CBC did some really good reporting. And to your point, what they found was that it was the reason this is going after minors is mostly just because they're easier to manipulate and to break. Sure. It it the minor is almost incidental. It seems like if they could be doing it to adults, they would be. It's more about can you trick a person and dominate them in that way remotely over the Internet. And kids are just an easy target, and this is a not a cool group of people.

Speaker 2: I feel like that's such a I don't know. I was I was at the mall yesterday, and I was firsthand saw teenage angst. It's not often around me. I'm not often surrounded by minors. But I went to the Apple store to pick something up and got the firsthand display of teenage angst all around me. And and and I remember those days. You know, I remember

Speaker 1: 100%.

Speaker 2: Junior high high school. I remember your, you know, your biochemistry is all messed up, and everything's the most important thing. And the funny thing is is, like, if you when you're when you get old like us, high school, junior high is, like, such a tiny little fraction of your life. But when you're in it, it feels so important that especially because you're biochemically, you know, kinda messed up.

Speaker 1: You're vulnerable. You're vulnerable. Totally. You're really vulnerable. Yeah. It makes things like social engineering a lot easier. And then as we've seen in, again, social engineering and cybercrime contexts, there's like a compression of sunk cost where you're already two steps into something and it feels like I've already come so far. It's like, no, you've just been on a phone call for ten minutes. You can hang up, you can back away. You haven't, you're right where you started. But when you're young, that's accelerated. And then when these groups slowly start to bring people in and indoctrinate them with increasing levels of, well, you've already done this, now you've already done this. There's a little bit of a cycle that starts to develop. So like I said, we're gonna talk about this, then we're gonna take a break, then we're gonna talk about some other stuff on this episode brought to you by Push Security. So in April, US law enforcement arrested two men accused of leading a group called seven six Inferno, which is a faction of seven six four, Leonidas and Persson, who I mentioned. According to statements from the Department of Justice, both men helped direct operations targeting minors using blackmail extortion, helped create and distribute these lore books, these graphic packages of evidence of abuse, traded this content inside of these communities to build credibility and to recruit other peoples into it. The DOJ has labeled this a I find this interesting language. It's a nihilistic violent extremist network, which is not language that is normally used in these kinds of cases, but is very seemingly accurate to the groups like tactics and ideology. The FBI's counterterrorism division is now looking into it. It's driven. It looks there's a a good quote from Allison Nixon. She's a researcher at unit twenty two one b. It's a comm related crime wave that's driven by a small, small number of highly prolific actors. So rests seem to work because this isn't a huge crew of people, but they are doing this so aggressively and spending so much time in it that there's a relatively small number of people that seem to be behind it. So as I mentioned in the intro, there's this larger digital ecosystem called the comm. It's an umbrella term that encompasses a bunch of different, organizations. A lot of it are just doing cybercrime data brokering, SIM swapping, but then it starts to intersect with these other groups like cult and court league society. And, wouldn't even get into all of their names because the names alone are gross. But there's, there's just overlap between these two different groups. The overlap became especially clear in the aftermath of the 2023 ransomware attack on MGM Resorts carried out by Alfie and Black Cat. A 17 year old British hacker using the handle at Holly claimed credit for the intrusion and pretty quickly researchers started discovering that the same, Telegram account was active in the seven six four linked harm channels where Holly was actively trading these lore books, which is how we started to see some of these connections.

Speaker 2: The I think can you explain the calm to me? Like, what makes up the calm?

Speaker 1: Krebs has a really good answer to that, I think. I'll just quote him here. Quote, collectively, this archipelago of crime focused chat communities is known as the calm, and it functions as a kind of distributed cyber criminal social network that that facilitates instant connection. But mostly the Calm is a place where cybercriminals go to boast about their exploits and standing within the community or to knock others down a peg or two. Top Calm members are constantly snagging over who pulled off the most impressive heists or who has accumulated the biggest pile of stolen virtual currencies. As often as they extort victims for financial gain, members of the comm are also trying to wrest stolen money from their cyber criminal rivals, often in ways that spill over into physical violence in the real world. There are action figures. It's a whole thing, the calm. It's an online community. Social network seems like a good term for

Speaker 2: it. Like a criminal, a dark criminal, I guess it's like a modern manifestation of the dark web. Totally. Yeah. The Yeah. The like a dark criminal social network. Yeah. And points and clout.

Speaker 1: Yeah. Chirping each other and bragging, and someone else brags back, so you get mad. It's exactly that. So seven six four particularly starts with a guy named Bradley Caden Head. He was a teenager from Stephenville, Texas. He was a a troubled guy. Caden Head founded a Discord server in 2020 named after his ZIP code prefix 764. He used aliases like Felix and Brad seven six four and created the space where, people, obviously minors based on the context, were lured into the community through Minecraft, Roblox, and gradually coerced into increasingly, extreme acts, which they were told to document and share there. Cadenhead was finally arrested in August 2021 after Discord flagged him 58 times for uploading abuse material. When police seized his phone, they discovered dozens of abuse files and images of his username, like, literally carved into people's bodies. In 2023, he was sentenced to eighty years in prison.

Speaker 2: This is seven six four is Stephenville, Texas. When I first when I first heard the group name, the first thing I did was convert it to letters, like, so many things and, like and it's Sure. Yes. Seven six four is GFD, which could be anything, but I was intrigued to hear that it was based on an area code because I thought it would be something more subverted.

Speaker 1: Yeah. It's also not good operate like, I'm glad it's not good operational security. This person Yeah. Yeah. Should not be in the the public. And I I would imagine that that probably helped lead to his arrest at a certain point, but, a postal code isn't exactly on the down low.

Speaker 2: Exactly. I'm looking up how how many people live in Stephenville, Texas. There's 20,000 people.

Speaker 1: It's like a That's actually a pretty small pool.

Speaker 2: Yeah. Yeah. We've narrowed it down.

Speaker 1: Yeah. A 100%. And there's a lot of traffic coming from this one house. So Cainhead gets arrested and a bunch of new people from the community sort of level up into being leaders. There's recurring motifs here, and I think you can kind of see it in the, like, larger manifest of this, which is like there isn't really it's a the the point of the cult isn't a charismatic leader. The point of the cult isn't a story about what's gonna happen in the world. The point of the cult is that, like, we use sadism and harm to control people. It's like a nihilistic Mhmm. Kind of philosophical group. And as such, other nihilistic philosophies seem to be drawn to it. Duck slash Gore Butcher, otherwise known as Angel Luis Almeida. Who was also arrested a Florida man with a violent criminal history, a devoted follower of the order of the nine angles, which is a satanic neo Nazi cult. It's very interesting to see what other groups are drawn into this. When he was arrested in federal detention, Almeida managed to post from a contraband phone and threatened a courtroom full of people saying, quote, when I get out of here, I'm a kill all of y'all. So Sure. Yeah. Just a crackerjack crew of crew of folk.

Speaker 2: Yeah. Maybe it's my own innocence, but, like, I I don't I'm learning so many words right now.

Speaker 1: I know. And I'm leaving most of them out. That's the really wild thing. Like, I have my notes, and they're made up of a bunch of different documents I had the unpleasant experience of reading. And I'm leaving out a lot. Again, if you want full kind of not gross detail, but if you wanna really understand this, Krebs' coverage was admittedly very, very good. Wired has done some great work, and there's a forty minute CBC doc on it that is is worth watching. It's it's a rough watch. Crazy.

Speaker 2: Yeah. I'm just, like, reading about cut signs. Yeah.

Speaker 1: So let's jump into that then. Why don't we?

Speaker 2: Why why don't we? Because I've been getting dark. Hopefully, everybody's having a great morning out there. Yeah.

Speaker 1: Hope y'all are doing good. Darkness. Yeah. That was yeah. So like you mentioned, there's cuts. So let's zoom out a little bit on that. It's a gamified abuse cult is a pretty good way of understanding this. There's social status gained through coercing people into these, like, increasing levels of brutality and then getting them to post it. And those tools, as part of this, like, we talked about lore books a little bit, fan signs, which is their sort of internal language for photos and videos documenting these different acts of, like, Abuse. Abuse. Correct. And then cut signs, which is, as we have alluded to multiple times, the act of carving a username into someone's body.

Speaker 2: Or doing it to yourself to to prove that you've been completely manipulated and are part of the

Speaker 1: Which is the sort of escalating levels of obedience that are asked by the structure. Typically, in a few cases, and we'll talk about this, result in people then being asked to well, the next act of obedience isn't showing what you'll do. It's getting someone else into this. Totally. It's pyramid scheme. It's pyramid scheme stuff. It's called structure. It's all the exact same psychology. It's that once you've social engineered one person, can you social engineer them into social engineering three other people and the thing kind of continues downward forever? Luckily luckily is the wrong word. There's a brittleness to this because the harm is so extreme that it it simply can't spread in the way that certain things would. Most people just won't cut a username into their body. Most people won't just document something that horrific, which again is why I think minors are targeted.

Speaker 2: So I read Helter Skelter as a kid. Oh, yeah. A book about Yeah. Manson. Manson Cult, and I can't help but feel like this is some modern day dark reincarnation of that.

Speaker 1: A 100%. And that used, like, aesthetics of cultural symbols for, like, evil and danger. Like, there there was a, like, an edge lordiness to it. Like, Like Mhmm. You gotta talk about the devil and Nazi stuff because that's the scary stuff. And it's, like, is it relevant to this? It's, like, it's that's not relevant. It's that it's the scary thing. It's the darkest thing we can think of, and that's kind of all part of it. And it's why you see someone like Gore Butcher wearing his satanic neo Nazi cult shirt, and that's the best of his shirts. I'm not even joking. There's more shirts implicated.

Speaker 2: You've seen his closet? His closet is part of his evidence?

Speaker 1: There's literally, like, two garments of clothing mentioned in the court documents, and the satanic neo Nazi one is the more tasteful of the two. Like, so we're talking about this because there were these two most recent arrests. We've already talked about a series of other arrests that have taken place. It's still going. There's dozens of these channels still active on Telegram, reporting on Discord band, a 130 groups with 34,000 accounts in 2023. There's still researchers are finding stuff on Instagram and meta platforms that are connected to this. SoundCloud weirdly has is hosting playlists that seem to reference, like, insider seven six four lingo, and then Roblox and Minecraft still seem to be the top of the funnel for bringing people into this. It's just a concentrated pool of minors hanging out that you can go to and bring over.

Speaker 2: Great way to repurpose, like, business development sales lingo. The top of the funnel. It's like, oh, we use Roblox. Tons of vulnerable 12 year olds in there.

Speaker 1: To do what?

Speaker 2: Like We bring we move them from there into Discord where we resocialize them, and then, you know, we advance them. The ones that are that are willing to advance in the queue, we get them into the private Telegram channels. And, yeah. Then we document

Speaker 1: The harm. Their journey. Their user journey.

Speaker 2: Their user journey.

Speaker 1: So it seemed relevant because of, a, that connection to the comm, the larger cybercrime hacking group, and the fact that, these two larger figures, Leonidas and Preston, were recently arrested. They were, according to the US Department of Justice, directing and managing operations for seven six ferno, just one of these subgroups. They were actively on the ground targeting minors, distributing this material, compiling and trading these lore books. Nepal was arrested in North Carolina on April 22. Varga Yanes was arrested in Greece on April 29. US is currently working on his extradition at the time of recording. The FBI affidavit described both men as core figures in the ongoing structure of seven six four. And it also references, like, their leadership role across not just that group, but multiple different platforms. They were doing this, like, I can't say that they were doing this full time, but they were actively organizing across Telegram channels and Discord channels. They were in the games themselves. It's a extension not just of these, like, online communities where social engineering is prominent, but it's the same kind of thing that you I think you were right to bring up Manson, where this, like, nihilistic violent extremism, how does it live online? What does it look like in a modern digital context? And it seems like the answer to that is

Speaker 2: Mhmm.

Speaker 1: Something like seven six four. Great. Yep. I feel like I don't normally feel like we need to do any kind of public advisory warning y type thing, but this one seems heavy enough

Speaker 2: to Sure. Yeah.

Speaker 1: If you think this could be happening to someone in your life and you're in The States, tips.fbi.gov, 988 suicide crisis hotline. You can call or text. There's 988 Like, if you know someone and you think they need help, please, please try and help. I would imagine that any parent watching this show knows the importance of maintaining a, like, tech literacy parity with your child, which is tough, but increasingly pretty important. Mhmm.

Speaker 2: But I

Speaker 1: think this is also just a really good reminder of that is that you should probably you should aspire to know as much about the Internet and technology that your kid is using as your kid does. And that's I know that's not always possible. It certainly wasn't possible when I was a kid. Yeah. But it it's still a pretty dang good idea.

Speaker 2: Yeah. No kidding. I'm surprised this is gonna sound terrible but I'm surprised that the police forces are capable and with it enough to engage. I kind of have a perspective on police, which is maybe not accurate, but I don't see them like the Canadian police, the RCMP, American police, and state troopers. I get that the FBI and the NSA and the CIA and Canadian Secret Service has a more tech literate departments. But for general policing, like, I'm kind of surprised that they actually have the competency to rip through this. But I guess nowadays, like, I think back to our campus

Speaker 1: Yeah.

Speaker 2: Campus action.

Speaker 1: Remember when

Speaker 2: we talked about, like,

Speaker 1: That's our campus.

Speaker 2: Yeah. We we had an episode where we discussed kind of, like, monitoring of social media by campuses to to kind of make sure that they knew the ongoings. And I guess Telegram is probably that new platform, not for campus protests, but like for everything on the internet. It's like you need to be kind of monitoring Telegram channels to see what's going on, what's being planned, what's being discussed. Like, every group that I can think of that's I wouldn't call them extremists, but I'll say that they have moderate to extreme views. Like, if there are two two standard deviations either way on the bell curve, uses Telegram as a communications platform. So it's like I imagine the the policing and law enforcement departments have really grown their ability to track and monitor Telegram.

Speaker 1: Yeah. I think the dedicated cybercrime divisions inside of law enforcement are definitely a a growing thing. Like, I think just a lot of crime takes place on the Internet. And then the other thing I would attribute to this is that when you think about, like, the thing about trying to keep an online physical abuse nihilistic death cult secret is that there tends to be a lot of physical evidence of it. Like, you have kids with, like, again, it's dark, but it's like you have kids with, like, self mutilation and dead pets. It's like there there's there's simply signs that something is wrong. And if all of this happened in a bedroom with a computer and a phone, it's like, yet there's there's evidence. Like

Speaker 2: Not even that. That evidence is then collected, categorized, and put into lore books, which are essentially like legal evidentially, like, portfolios. It's like a dossier Lit up a portfolio

Speaker 1: of evidence, I think, is how we describe it in the introduction. It's like, it's not It's it's evidence of a crime that took place, but in a weird way, the the victim the perpetrator of some of the crime is also very I mean, in a much realer sense, the victim.

Speaker 2: Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Which gives that culty vibe It's extremely Lancen vibe.

Speaker 1: It's a heavy one. So we're gonna so we're gonna go do

Speaker 2: some ads now, and then

Speaker 1: we're gonna shake this off, and then we're gonna talk about something completely unrelated.

Speaker 2: I almost almost feel like we should flip the episode, but this is the end story because it is so heavy. It's like if you're still

Speaker 1: with us talk about this.

Speaker 2: The next now we're going to talk about, like, library vulnerabilities and popular software. It's gonna be much more complex.

Speaker 1: Much more fun. Stuff. Because I don't have the the editing capacity to flip a roo this whole episode. So it is we are gonna lead with the giant downer, probably. Hopefully, you're still here.

Speaker 2: Hopefully, you're still here. And, we'll see you after the break. Identity attacks, phishing, credential stuffing, session hijacking, account takeovers are the number one cause of breaches right now. But most security tools still focus on endpoints, networks, and infrastructure. Meanwhile, the browser, the actual place where we're working, has been ignored.

Speaker 1: Push changes that. They built a lightweight browser extension that observes identity activity in real time, gives you visibility into how identities are being used across your whole organization, like when logins skip multi factor authentication, when passwords are reused, or or when someone unknowingly enters credentials into a spoofed login page. Then when something risky is detected, Push can enforce protections right there in the browser. No waiting, no tickets. And it's

Speaker 2: not just about prevention. Push also monitors real time threats like adversary in the middle attacks, stolen session tokens, and even new techniques like cross IDP impersonation, where attackers bypass single sign on a multi factor authentication by essentially setting up a fake identity provider for your company. The way to think about it, it's kinda like EDR, but in your browser.

Speaker 1: Team behind it, they're all offensive security pros. They publish some of the most interesting identity attack research out there, like the software as a service attack matrix, which breaks down exactly how these kinds of threats bypass all those traditional controls. Identity is the new endpoint and push. Our proud sponsor push is treating it that way.

Speaker 2: Check them out at pushsecurity.com.

Speaker 1: Starting some new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.

Speaker 3: Thinking about refreshing the carpet in your home? Now's the time to do it. For a limited time at The Home Depot, get 10% off installed carpet projects on trusted brands like Lifeproof, Lifeproof with PetProof Technology, Home Decorators Collection, and Traffic Master. Plus, with installation starting at just 49¢ per square foot, upgrading your space is more affordable than ever at The Home Depot. Offer valid 06/11/2026 through 06/28/2026. Exclusions apply for licenses. See homedepot.com/license numbers.

Speaker 2: Study

Speaker 4: and play. Come together on a Windows 11 PC. And for a limited time, college students get The best

Speaker 2: of both worlds.

Speaker 4: Get the Unreal College deal, everything you need to study and play with select Windows 11 PCs. Eligible students get a year of Microsoft three sixty five premium and a year of Xbox Game Pass Ultimate with a custom color Xbox wireless controller. Learn more at windows.com/studentoffer. While supplies last, ends June 30, terms at aka.ms/collegepc.

Speaker 2: Yeah. So the thing I wanna talk about is supply chain attacks into software libraries and packages that people are using in the development of their software applications.

Speaker 1: Okay.

Speaker 2: Does that make sense?

Speaker 1: I think so. So when people are developing software, they're using these preexisting packages, like, these, like, third party libraries Correct. And it's a supply chain attack into that thing. Correct.

Speaker 2: So like k.

Speaker 1: Take me through it.

Speaker 2: If you're using like Python, like a big part of using Python is like it has all these packages you can install. The Python package index and PIP is like a way that lets you grab chunks of source code that like are containerized to do a specific thing that your application needs to do. So instead of you writing all that code, you can just grab these packages to facilitate it. Same thing with, like, Node. There's a package manager there called Node Package Manager NPM or PNPM if you're using a better one. The but essentially, there's, like, boatloads of open source source code that gets included in tons of production systems. Like, it's something like 80% of most, like, contemporary developed program systems use, like, 80% of this code is coming from packages that they're including.

Speaker 1: Okay.

Speaker 2: So it's become a target. It's become an attack vector. So a lot of nation states, especially North Korea, have been looking at and compromising or publishing their own packages for very basic things that they know a lot of users are going to want to do. And inside of that code package is malware, a remote access Trojan, Crypto thief, username credentials, grabbers, like, you name it.

Speaker 1: Okay. So just so I understand here, when we talk about so the malware comes someone has hacked one of these third party packages. Just so I understand, is the goal to hack the developer that's using it, or is the goal to get the compromise into the software that the developer is shipping out into the general public?

Speaker 2: Correct. That's the the latter. The latter.

Speaker 1: Oh, that's worse. That's the worst one. Mhmm. I ordered them in escalating warseness.

Speaker 2: You can do it both ways, but typically, it is the the latter way. The the the bigger impact is to have it in the latter. Okay. So this just happened again, which is what threw this into my, like Yeah. Sure. Into my eyes. So in just this month, actually, a package ran user agent, was compromised, and including it in it was a remote access Trojan. So, like, a full blown Trojan to get remote access to people's computers was embedded in specific versions of this package. K.

Speaker 1: And just so I understand, what something like RAN user agent, like, broadly speaking, what is that?

Speaker 2: So when you do a web request to a web server, it comes in with a user agent. And essentially, this package, I think, allowed applications to generate random user agent keys. So, like, when you when you submit a request or, like, a web server retrieves a request, it also tags it as what the user agent token is, and usually it's like Chrome, Mac. Like, you you've seen them before, guaranteed. So this, this was a package to facilitate doing that.

Speaker 1: Got it.

Speaker 2: And I think the package had been, deprecated, so the the lead developer that had built it had just kinda walked away from it. It wasn't maintaining it, and somebody grabbed the maintenance of it and then immediately stuffed a, like, a rat in it, a remote access Trojan.

Speaker 1: Sure. So I'm slacking you an x k c d comic that this reminds me of, which is it's just one illustration, and it's this mountain of, like, Lego brick shaped things. And it says all modern digital infrastructure, and then the whole thing is being held up by this narrow skinny little brick labeled a project some random person in Nebraska has been thanklessly maintaining since 2003. And I'm reminded of that in this.

Speaker 2: That is modern software development. Open source software dev and like package development and library development is tons of that. It's boatloads of people tirelessly building a specific library that allows for specific things, and then you get GitHub stars for it. And that's the social media clout, it's like, Oh, my project has a bunch of stars. But it also means that I spend sixty hours a week maintaining this thing for free so that all of these companies can utilize it for profit. So

Speaker 1: Oh, I have so many questions.

Speaker 2: Ask the way.

Speaker 1: But that's the, like, oh, man. I'm really reticent to connect this back to the first story, but, like, what a positive use of the gamification of the desire for clout. Like, a in a positive way. Like, clout doesn't even really feel like it captures it. It's like you genuinely wanna come, like, contribute to something positive in the world and help people make things.

Speaker 2: Yes.

Speaker 1: Okay. So these third party packages, this scaffolding for modern technology is becoming a new attack vector for getting people into it and for getting into people's systems and then getting disseminated out into the world. What like, without just rethinking how software development happens, which seems like it's quite dependent on these things

Speaker 2: Very.

Speaker 1: How do you like, what is the what then is the answer? Like, is it just be really, really careful with all of your dependencies? Like, is there an answer to this, or is it more just a warning?

Speaker 2: The I think, like, if you're a big like, if you're a a commercial enterprise that makes commercial products, you're probably pinning certain versions of it. Like, so you're only maybe you get, like, this package or, like, probably a bunch of packages, and you're, like, taking them at a specific version, like, two point one point eight or something. You've done a code review of it to make sure I I in an ideal sense, you've done a code review to make sure there's no remote access Trojan embedded in it. And then you're kind of consistently, from that moment on, maintaining your own fork of that package. So fork is like a a term that means, like, you grab the source code at that point and you take ownership of it for yourself. So now that it's integrated into your system, you're gonna be the one that maintains that package's source code. Oh, I see.

Speaker 1: I think

Speaker 2: a lot You take

Speaker 1: a little bit of accountability for the dependency in a weird way.

Speaker 2: Instead of just like

Speaker 1: because

Speaker 2: the other thing is is, like, if your system depends on, you know, some some package, and the package maintainer decides to change the entire programming interface for it, and you just have it auto updating in your build script, it could just shatter your system. So good good code, like, good CICD code, and good maintain like, maintenance and security protocol would be to probably, like, take a snapshot of the code base from that library, review it, and then consistently maintain it for yourselves. But, again, that's a lot more work than just letting the guy from Nebraska toil over it.

Speaker 1: Keep keep, supporting that one LEGO brick.

Speaker 2: Your your question is interesting because it's, like, one of the most notable of this style of attack actually happened. It was one of the first ones in 2018, and there was a widely used node package called EventStream, approximately 2,000,000 downloads per week. So that shows you the scale of development activity that was being used on it. And the main maintainer and the person that developed it just got burnt out on it and just wanted out. So they were like, you know what, I'm gonna deprecate it, pass it off. Anybody else wants to take ownership and publishing rights to it and wants to take over the responsibility of developing and maintaining this library. And they transferred it to a user called RightNine Control, who was like, You know what? I'll take it. The first thing they did was embed a crypto mining, like a crap. Like a crypto theft, like Trojan into it or like, malware into it. Sure.

Speaker 1: So wait. It was a lot all it was all just to get down to one crypto wait. It was to get crypto mining on other people's systems or to break into a crypto wallet?

Speaker 2: Break into crypto wallet. So he then here's the thing. 2018 bad, but it's fascinating. 2018, he was selective. He only wanted, or they, I should say, they only wanted wallets that had more than a 100 Bitcoins in them.

Speaker 1: Yep. Okay. Big fish.

Speaker 2: But 2018, so, like, I don't know what the value was then. Let's call it 20,000. So that's, like, still a lot of money. Where today, a 100 Bitcoins is, like, $10,000,000. Is that right?

Speaker 1: Jesus. A 100 bit no. A hun oh, maybe.

Speaker 2: Yeah. 100 Bitcoin is valid due.

Speaker 1: Yeah. Yeah. A 140 k or I guess CAD. Yeah.

Speaker 2: Yeah. Yeah. $100,100,000 US. So, yeah, it's a

Speaker 1: Jesus.

Speaker 2: Anyway, so the yeah, it was like the first thing. It was like the next iteration of the library that came out had this like crypto thieving malware in it. And it would just like any computer that it was installed on, it would scan for a crypto wallet, identify whether it had more than a 100 Bitcoins, steal the keys to the wallet, and, like, send it send it back to home.

Speaker 1: We were, we've talked about the different, like, AI development environments on the show before, and I know you and I have just talked a lot about Cursor. Mhmm. But there was one of these with Cursor too. There's, like, a commonly used package for Cursor that I guess was treated as one of these, like, little little avenues for compromise.

Speaker 2: I think that was to steal API creds, if I'm not mistaken. I'd have to I'd have to look that one up. It wasn't as big and as impactful. Like, I think the biggest one ever was in 2021. UA parser JS, so like a JavaScript parser, parse user agent strings, same same kind of style of things. So the user agent coming in from the server, this was an automated thing that would grab the string and parse it into its components. So you could tell whether it was a OSX or, like, what its OS was, what the agent was, what version the agent was. And, they saw tainted versions of it starting in 2021. You know, some of them actually went as far as to include a a dot e x z in them, which was an actual crypto miner that would run on the computer of the person that had installed the package. So Mhmm. Again, cryptocurrency at the heart of the theft. But

Speaker 1: And, again, I think of the person in Nebraska, it's like maintainers are human beings. Like, people get burnt out. People that are maintaining long term projects get stressed. You don't know what's happening in people's lives. And a person that's, like, tirelessly defending and maintaining something is, like can be as targeted by a thing like social engineering as anybody else. It's easy when these projects are depended on by so many people to kind of think of them as like, well, it's the wisdom of the crowd. I'm sure someone's on this. And it's like, that's not necessary necessarily a reasonable conclusion.

Speaker 2: Well, the it is such a big part of the community, like the development community. There's so much leverage. Like, the value of some of these languages and platforms and frameworks comes down to the accessibility of free tools for them. Like, if you think about Python, Python's become like the machine learning AI, like like Right. Baby, and it's because it's just an amazing set of libraries that are just given out for free to use Mhmm. In that in that space. So it becomes so much easier. Like, if you imagine having to rewrite something like PyTorch and PyChants from, like, scratch just to utilize these things, it would take forever. So, like, to facilitate community growth and innovation, A lot of these packages do that. Like, you can build an app really quickly because if you think of an app like a recipe, you know, if you if you had to had to make eggs

Speaker 1: Yeah. If you had to mill flour every time you wanted to make bread, the process is a lot more complicated, but there's some downstairs.

Speaker 2: Exactly. Totally. Exactly. Yeah.

Speaker 1: Yeah. Yeah.

Speaker 2: So so that's the thing is, like, a lot of these packages are just there. And and what you're seeing now is, like, because it is such a stress, like like, I would never I would love to be a contributor and actually might be becoming a contributor to an open source package because the open source app I was building, some guys from San Francisco released it already. So, like, why would I

Speaker 1: Sure.

Speaker 2: Why would I rush to do it? But, anyway, the what you're seeing now is, like, major companies, like Meta, Microsoft. Like, Visual Studio Code is a Microsoft maintained product. Like, the React framework for, like, node and web development is like a meta maintained framework. And it's like a lot of these massive enterprises now are actually the ones releasing and maintaining a lot of the bigger packages, Mhmm. This is good.

Speaker 1: Yeah. I mean, there there there's just something to be said for, like, redundancy. Totally. One person can burn out and can slip up, but, hopefully I mean, what large organization could get compromised in a in a in a hack? That's never that's never happened.

Speaker 2: Well, like, so the to talk about size and scale, like, UA parser JS, when that one got compromised, injected with malware and crypto miners, it was doing 7,000,000 weekly downloads. So that's like 7,000,000 developers essentially downloading that package. And actually, the most recent one that I mentioned, the other user agent one, they actually didn't release the name of it. It kind of got found out because they were Rand user agent because it was in so many production systems systems that they wanted to give the developers time to remove the remote access Trojan before anybody really found out what it was.

Speaker 1: Okay. So what have we learned here? Open source is cool and useful and kind of a gift that we give each other, but it's also there's a vol there's potential for vulnerabilities there.

Speaker 2: Yeah. As a as, like, it seems like a lot of the big ones are nation state style, like North Korea's,

Speaker 1: kind

Speaker 2: of cybercrime department, for lack of better terms, is big on using this style of attack. And like we've talked about it on the show before, because it just it gives them it opens a lot of doors at once. You know, you put a you put a put a piece of malware in one place, and then somebody else is distributing that for you. All of a sudden, you've got malware all over the place.

Speaker 1: Yeah. Sure. You wouldn't believe who's baking cookies with this flour that we put on all the shelves. It would shock you who's off yeah. Right. No. It's it it's shrewd, and it's, like, stacked sort of like I'm trying to think of, like, the word to use for this. It's like a transitive dependency where, like, you got it into a thing that got it into a thing that got it into a thing, and you're like, I didn't even know where this was gonna end up. Now this vulnerability

Speaker 2: in this one package is in the

Speaker 1: White House. Another thing. Yeah. It's inside of another thing that's inside of the

Speaker 2: White House. Like

Speaker 1: Totally. Yeah. Fun is the wrong word, but there would probably be something kinda neat about being like, you wouldn't believe where it showed up today.

Speaker 2: If if you were, like, for fun activities, if you were the person that was, like, had done this, having it having it like its callbacks, like, when it calls home to tell you where it is, mapping that and getting to watch the three d connected state diagram of as it spreads Spread

Speaker 1: around the world.

Speaker 2: Would be fascinating to watch. But, no, I think that this is this is going to be a place where AI is going to become really successful in both ways, because I think the more people that are writing code and developing stuff without actually knowing what they're doing is going to increase the attack vector. But I think that you're going to see platforms and production environments and IDEs get really intense with AI code reviews, looking for potential vulnerabilities, looking for fingerprints of anything. GitHub at some point will automatically fingerprint whether there's any kind of SUS code in your stuff. I imagine they're already probably building that. We saw that stuff at Defcon where, like, you know, there was that massive multi organization challenge going on, having, like, AIs find vulnerabilities in code and then patch them. And I think you'll see some of that same implementation come to some of these, like, code repositories, code submission, CICD, pipelines, things like that.

Speaker 1: I'm wondering how this is gonna sit with people. The darkest story we've maybe ever told and the most, like, just just so you know, there's a fascinating thing going on with these dependent code packages. It's like, normally, we we like to find a nice middle ground between the tech and the the human and the boy did it. Is there just a chasm there today?

Speaker 2: I don't know. To me, the, like, code one is I love it. The code

Speaker 1: the the the first

Speaker 2: story, seven six four, pretty dark. Learned a lot

Speaker 1: of new

Speaker 2: terms that I didn't care to know about. Gore Butcher. Gore Butcher. Codependency supply chain attacking? Fascinating

Speaker 1: to me.

Speaker 2: Less I agree. Like It's like it's

Speaker 1: the tools that you use. These are, like, the tools used to create modern tools. And it's like, well, what if the hammer was actually evil? It's like, well, that's interesting.

Speaker 2: Yeah. Exactly. Yeah. And, like, the thing is too is, like, we talked you talked about it. You brought it up like like burnout of of project maintainers and Totally. Like, it's a lot of thankless work.

Speaker 1: Yeah.

Speaker 2: And, like, like, you spend it's like the the meme, like, deal. Like, you give me fifteen hundred hours a year of free work. I give you angry comments in GitHub issues.

Speaker 1: Right.

Speaker 2: And it's like, that's what it is. Like somebody complaining about how the code's broken in a specific way. And it's like, that's your payback for it. And some stars, some thumbs ups. And to me, that's the thing. As these maintainers burn out, I think as they transition away from them and hand over the keys to the project to other people to take over the thankless role of pushing the stone up the hill, Those people could be the North Korean cybercrime division, and especially if it's a large enough package that's in so many things. It's like one piece of local, like one package that would be used on local applications that like if it was big enough, could push malware and remote access Trojans to millions of PCs. And it's like, that's such an interesting supply chain attack that could have such a big output. I can see why somebody like North Korea has prioritized it.

Speaker 1: This is a goofy note to end on. I love sci fi. And there's a trope in sci fi of, like, the imagined sci fi world where they still have the futuristic tech futuristic technology, but they're so far ahead of it that they've forgotten how it was created. Like, Warhammer 40 k. That's a big thing in that, like, lore universe of, like, we have these dreadnoughts. Why don't you have new ones? Because we forgot how to make them long ago because we were too busy murdering each other. And it's fascinating to imagine a world where there's all of these software dependencies that were developed by people at at some point in the past and handed off and handed off and handed off, and you have people using them that don't entirely maybe know what's in them and how they work anymore at this stage because of how they learn to develop software in the modern age. It's like it's an interesting world to imagine where we're building things out of parts we don't totally understand.

Speaker 2: Oh, yeah. Well, like the and some of those packages are so small. Like like some of the most common node packages are like basic functions that just don't exist in the base language. So somebody writes one function that does something, like, checks if an array is like, has some specific constraint, and that package gets used, like, 13,000,000 times because instead of people rewriting the one function that does it, they just include the package because it's like somebody else does it. And some of the packages that North Korea was building were things like that. Like, things that are just easy use if you're kind of I don't wanna say too lazy, but, like, you didn't wanna rewrite work that had already been done for you.

Speaker 1: You didn't wanna mill your own flower. Yeah. You didn't wanna mill your own flower. Extremely natural and reasonable to wanna use those preexisting tools, and it's super obvious to go after them if you're that kind of an Asian state actor.

Speaker 2: Totally. And like the Oh. Yeah. We could talk about vibe coding and how that's gonna affect this, but there's no point. I think everybody kinda understands.

Speaker 1: Yeah. We all got

Speaker 2: a gist. So

Speaker 1: Well, everybody, I hope you enjoyed this conversation about, dependence codependency supply chain attacks and Internet death cults. We we sure had fun.

Speaker 2: I'm gonna go lay on the couch for forty minutes.

Speaker 1: Go stare at a wall.

Speaker 2: Deep depressed.

Speaker 1: As always, this was a pleasure. Thank you all for listening and we'll catch you in the next one. Take care.