episode.ascii — live render
● episode

Unmasking a Cybercriminal With Open Source Intelligence

TL;DRBaptiste Robert, OSINT researcher and CEO of PredictaLab, used publicly archived profiles, old usernames, and digital footprints to unmask Brazilian hacker USDOD (Luan G), who breached National Public Data, Airbus, and CrowdStrike before…

We wanted to know: How was USDoD, the hacker behind major data breaches, unmasked? On this episode, we trace his journey from infiltrating FBI-linked networks to leaking sensitive data, and hear from OSINT specialist and Predicta Lab CEO Baptiste Robert, who used open-source intelligence to follow USDoD’s digital trail, revealing what law enforcement missed along the way.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: It's like, I I don't know if it is a word in English, puzzle? Puzzle. Yeah. But it's like a puzzle.

Speaker 2: About a month ago, a story broke about 3,200,000,000 Social Security numbers that were hacked and leaked from a Florida based data broker called National Public Data. We talked about it on this show. The person behind that hack used the handle USDOD. He had been operating since at least 2020, likely earlier. The day before I'm recording this, on October 16, he was arrested by Brazil's federal police in what they called Operation Data Breach. This is the story of how he was unmasked. US DOD's name is a troll. He adopted it in December 2022 after exposing the data of 80,000 InfraGard members. InfraGard is a collaboration between the FBI and the private sector. US DOD impersonated a InfraGard CEO, got access, and compromised the project. His handle, US DOD, was a swipe at US defense agencies. Weirdly, it was not in pissing off the FBI that we see the beginning of his downfall. It was in getting on the wrong side of a private security firm called Crowdstrike. July 2024, USDOD leaked a 100,000 line indicator of compromise list from the company, and Crowdstrike swiftly retaliated, doxxing USDOD in a blog post. His alleged real identity, Luan G, a 33 year old Brazilian citizen. Weirdly, Crowdstrike wasn't the first to identify him. In an interview with Hack Read, Luan later revealed that another cybersecurity group, Intel four twenty one, had already unmasked him before the InfraGard hack. But it wasn't until that national public data breach that his identity became really widely published. The question that all of this raised to me is if two companies were able to dox this person's identity, a) Why wasn't law enforcement? And b) What are the clues that they were both finding? In response to all of this, Luan publicly declared his intentions to step away from cybercrime. John Bambenek, a cybersecurity expert, remarked in an interview with Hackery that Luan's announcement could be a tactic to muddy the waters and create a PR smokescreen while he continued to do exactly whatever the hell it is he wants. Mulan has since been arrested. So it's a mess. There's all these big companies pointing fingers at the lawn, and there's still that question. What were the breadcrumbs that led all of these separate groups right to Lawan's door? For me, the answer to that question rested with a guy named Baptiste. Of all the people who unmasked USDOD, Baptiste Robert is the one I was most fascinated by. Baptiste works in open source intelligence or OSINT, taking information that's openly available for anybody to find and doing the work of turning that into actionable intelligence.

Speaker 1: Creating intelligence from information you find on the Internet is complicated, and it's not only, it's not just a question of, oh, I managed to find a tool on GitHub, and, I do have some information. Yeah. I'm doing OSINT. No. The most important thing on OSINT is to be able to analyze what you have to investigate, to understand the biggest story, behind something.

Speaker 2: Batiste was able to reproduce not just the findings of these other massive cybersecurity companies, but to find the trail of breadcrumbs leading to a person that had apparently evaded law enforcement for years. And then post those findings in granular detail on social media, which is where I found it is remarkable piece of research. The thing I was maybe most fascinated by was how concerned the Baptiste is with understanding the whole person, not just their alleged crimes, but them, their whole life. Are they a family person? Are they social? Are they isolated? Is this behavior a trend or an exception? And to hold that whole image of the person in their mind even as they unravel alleged wrongdoings. So I called him up, trying to understand not just you as DOD, but how people like Baptiste use the trove of public information that's trailing behind an actor like him to try and create a picture of a person that doesn't want to be found. The bad and the good to find the story in the facts. This is the doxing of USDOD with Baptiste Robert, researcher and CEO of PredictaLab, here on Hacked. Batiste, thank you for being here.

Speaker 1: Thank you for the invitation.

Speaker 2: US DOD. That's who we're here to talk about. Prior to all of this, what had this actor done? Why did people know this name US DOD?

Speaker 1: So US DOD was a very famous actor since 2022, I think, something like this. This guy, did a lot of things, a lot of, data breaches you heard, in the last two years. He was involved, and, he one of the biggest data breach he made was was very recently when he leaked all the Social Security numbers of The US, citizens. So this is very, very big, data breach, and used to be a very famous on on the ground forums on the and also on on Telegram and on the the natural hacking forums.

Speaker 2: Yeah. You made reference to the national public data breach in which a great deal of Social Security numbers and personal information were leaked to data brokers. A lot of damage done from that. There was the Airbus breach. There was the CrowdStrike breach, an earlier one, a LinkedIn breach. This actor, in spite of all these very, very high profile attacks, USDOD managed to stay anonymous for a very long time. In spite of everything that you were able to find during your investigation, how is it that you think that he was able to keep below the radar in spite of these very, very high profile attacks and this very visible, trail of breadcrumbs leading to him?

Speaker 1: So this guy was very was super visible, for sure in the hacking ecosystem. So, I mean, everyone know knows his name for sure. The thing is when you create a new persona, when you create a new identity, like USDOD, you need to be careful of everything, like, really everything. You need to to be careful when you create a a new profile on social networks and, and, and you you need to create a new email to be careful of the IP you used, everything. So this is what we are calling, OPSEC, so operation security. And OPSEC is super complicated. The thing is cyber cybercriminals leaves always some traces behind, and you you are always able to find their real identity because, because at one point, they forget something. They missed the fact that this phone numbers was linked with a previous profile with their real identity, something like this. So, yes, he used to target some very high profile companies and and, people, but he made a lot of mistakes, to be honest, and this is why we managed to find him. But we were not the first to find it to find him for sure. So real question, and, this is something we will raise, in the future. I'm pretty sure the FBI was able to find him, almost two years before, but I don't know why they did nothing. So I don't think his identity was super complicated to find, but for some reason, no one talk about it.

Speaker 2: Interesting. I wonder why that is. Such a high profile person doing such high profile things, and yet the evidence was right there.

Speaker 1: The the thing is, he managed to he he is behind a lot of the wittries, but he was not a super sophisticated, actor. So sometimes for the for the public, it can be super impressive. Okay. You actor with your act, national public database. Oh, this is crazy. But at the end, the technicality behind these hacks are not that crazy. So this guy was good for sure. He managed to do a lot of things, a lot of data breaches, but he was not a super skilled actor. And in general, a good actor is some someone who is not, super public, who is not visible. A good actor is someone super discreet. Discreet. He he don't want to be seen. And because if you are seen, it means you are losing your access to to your victims. So this guy was seeking some fame for sure, and this is why he how can I say that? Ego is, Ego is one of the biggest motor for the hackers. So in general, authorities, law enforcement managed to catch cyber criminals because they are pretty young, very motivated by, by ego, by fame, by money. And, because of everything, they they are not in the control of what they are doing. And if you are motivated by this this this kind of feelings, you will make a lot of mistakes. And with only one mistakes, sometimes we manage to find your real identity.

Speaker 2: Sure. He he seemed to want to make a name for himself at something that you don't really want to make a name for yourself at. So we're we're here talking a bit about an unmasking that you kind of took part in and and shared because it's fascinating. I wonder if you could just take us through that. Beat by beat, how did that where did it start? What was the first clue you found? And just take us through the whole thing.

Speaker 1: So in order to find his real identity, you need to, you need to put the investigator at and to try to to follow his, to follow his steps. So what I started to do with my team is, to just, list all the information we have about this guy, all the public information we have. So this guy was very famous on Twitter. He was very famous on the on the hacking forum called, Bridgeforms. So his profile was the label, publicly. And with this information, you were able to find, previous version of all of his profiles. What you have to understand and keep in mind is that Internet have memory. So everything is archived somewhere by someone by someone, and, you have some public archive. For example, you have the website called archive.org, which is crazy. This this website is just, is awesome. You can find a lot of things. And for one web website, you can find the previous version, of this website, archived by people. I mean, it can it can be, it can be doing, you can find a lot of different versions. So what we did is we listed all the information we have, his his Twitter profile, his website, his profile and acting forums. We extracted all the information, contained in these profiles. So some links to, to messaging application, links to Telegram profiles, this kind of thing. We also consult, the the previous version of his profile. So we go to the archive, and, we managed to do some links to, to, a Twitter, to a to one of his previous Twitter account. And it it was his first big mistake because what what you have to understand too is before, before being a cyber criminals, before being a a criminal, this is not something you plan in advance. So this kind of guy in general are some some geeky guy, who loves, who love, computers. They had some passion for computers, for security, for reverse engineering. And so when they are a teenager, they are talking on forums, they created profiles. I mean, like like like us, you, when they discovered, the computers, they started to create a a digital life. But then life goes on. They decided to go to be a cybercriminal, and and they create a new identity. But still, they a lot of time, they created they created their cybercriminal identity based on the previous identity, based on their real identity. So we used with CredicLab to tag some cybercriminals, and what we can find is there is always a way to to to type what they did in the past. And for US DOD, this is exactly the same thing. We can find his passion. For example, this guy, this guy is producing some music, so he loves some techno techno music. I I don't. This is not my choice. I I don't know the the the Sure. Precise style of music, but this is some techno thing. He also we were able to find his first nickname on the hacking forums because, I mean, before being very good at what he is doing, ten years ago, he was just a script k d, publishing some YouTube video, and, and, just explaining how to act something. It was superb as it, but still, this video is still here. And, also, because even if you are a cybercriminal, you have a life. You can have a wife. You can have, you husband. You can have kids. You can have some patient. And so we were able to find a I I think it was a Foursquare, profile. And this guy was kissing his dog, so it was a a small puppy on the on on his profile, profile picture of this guy. He's kissing the dog. So you have the image of cybercriminal. This guy was, was talking a lot. Yes. I'm a very strong cyber criminal. No one will be able to catch me. Foxy, FBI, blah blah blah. And, at the end, you can find his four Foursquare profile with him, kissing his dog. So so reality so real life is always more complicated, because you have a life before being, being a bad guy. You can find all the digital footprint, and, what people have to understand is you some OSINT when you are good at OSINT, open source intelligence, a good OSINT investigator will be able to to find a lot of information about you, about all the the, your digital traces, and, a good investigator will be able to to to understand your life history. So based on the digital footprint you live, you will be able to understand, okay. So in during this year on this year, he was producing music. He was living here. Then he started to go to acting forums, so he created his first identities. He published some video on YouTube, and then he he was trying to sell some services.

Speaker 2: Interesting. It's, it's something we hear a lot that the mistake that ends up catching someone is the mistake they've made long, long before the thing that they're being caught for. How much I'm I'm struck by, you know, figuring out that this this person likes to post to YouTube, that they like to make some kind of electronic music, that they love their dog. How how much when you're doing OSINT, is it about the tangible details versus that sense of who they are as a person, holding that in your head and really understanding who this person was?

Speaker 1: This is complicated. This is always complicated because, when you are working on a case, you are obviously, there is one big person of interest. He obviously is USDOD. But this guy has a family. So this guy has a wife. I think he have some kids too. And, it's you you cannot start your investigation, saying, okay. This is a bad guy. He deserve he deserve what he got what what he got on blah blah blah. No. This is complex because life is complicated. You can do some mistakes. And when you are working in cyber sec security, you can talk with a lot of cybersecurity professional, and you will see that in their past, they did some stuff.

Speaker 2: Mhmm.

Speaker 1: You can some some blurry stuff. Let's say it's like this. Because when you are working in the in this field, you have some skills, and you want and when you are young, you want to test. You want to test. You want to prove that you are the best. And, what the difference is between, becoming a cyber criminals and becoming a cybersecurity professional is not that big. It's sometime it can be your wife. It can be your kids. It can be your education. It can be the fact that, you have a good situation or not. It can people you met, it can be, I mean, life is complicated, and you have also the right to do some mistakes and to take some bad decisions. So when you are investigating, a cybercriminal, I'm trying to stick to the fact and to what I'm able to find. So big the the the issue you have when you are doing some investigation, so based only on digital traces, you have to be sure that the information, the account you found is release the account of the person of interest. And, for this, it can be a little bit complicated sometimes because it for example, I'm using the, the username fsociety, but I'm not fsociety on all the website because when I started to become, famous on on my on my field, people started to create the account with my username. And for example, I do have an account on OnlyFans, but this this is not me, obviously. And, an India a a guy from India created an an account with my username. So you need to be really careful. Yeah. You need to be really careful when you, when you do an investigation because you will find a lot of information, then then you have to be sure that, you you you linked, you are talking, and you are, you are following the the good, the correct lead. So what I want to do, what I want to emphasize, is, you you can have the capacity of extracting a lot of data, and this is why on the Internet, you will find a lot of APIs, tools, methodology in order to get data. Then then you have to be able to analyze, to quantify, the quality of the data you are able to extract. And for this, you can there is some some methodology to, to give a notation to the information, to the data you you you have. You need to, to be able to to quantify the rely reliability of the data and all the quality of the data on also the source, of the data. So if someone you cannot trust give you some data, even if the data is super cool, this is a meh. You, yeah, you don't know. So you need to be super careful. And, also, when you go, to a court, to to the justice, this is another story because everything need to be, you need to be able to repeat everything. All all the steps need to be public, need to be, redo if necessary. And, for this, you need to link everything. You need to have a source for all the information you have. You need to archive everything. So this is super important to preserve all the links, all the proof, you have. Yeah.

Speaker 2: I was struck by how thorough the documentation, even in your public posting about this OSINT project was. Right at the same time as as you came out. I think shortly prior, Crowdstrike published a piece saying that they were pretty sure that they figured out who USDOD was. As you talked about earlier, it was inevitable that the FBI was probably looking into this actor as well. Your project was an OSINT project. It was stuff that was just out there in the world. How did your work differ from potentially, what CrowdStrike was doing, what other parties were doing to figure out who this person was?

Speaker 1: So the real story is, we one morning, I I find a post. I'm I just read a post on Twitter, about Portuguese. I think it was a Portuguese, article, saying, we manage, an anonymous source give us a report from CrowdStrike. These reports say this guy, US DOD, he's called blah blah blah. He has an Instagram account, and they in this article, this article was not that good. And, they wrote some information about USDOD, but it was super incomplete. There were no source at all. And I I read this article, and I was like, okay. This is interesting. I can smell some I can smell something. I this is interesting. If they manage to find it, to find this guy, I am probably able to do it too. So I will start to find it by, with my tools, with my following my way, but I want to source everything. I want to have some clear, a clear way on the logical way to find him. So I started with my team. So we were three people from PredictLab working on it. And, I mean, ten hours later, we managed to to redo all the analysis and to find a lot of information about him. And then the day after, I was not that happy because I wanted to find another way to find him, and I managed to find a second way to, find this real identity. So this guy made a lot of mistakes. And, when I did this work the second day so when I was saying before this guy, the biggest issue this guy made is he used he convert his he he convert his Twitter account, his personal Twitter account to the USDOD, Twitter account. So everyone was known this USDOD account, But so this Twitter account was used before with an email address. And when you find when you search this email address on Databridge, you are able to find a lot of personal information about him, and this is how you can find him. But I'm not I'm not from law enforcement, but law enforcement has a special power, obviously. And, and they were able to do a request to Twitter to ask some information about this Twitter account long time ago. So by doing a request to Twitter, they were able to get some IP, the previous usernames used by this guy, but also this email. And when you have this email, you can search on data breaches and find everything about him, find where he is living, his name, and everything. So this is why I don't really understand why this guy is still free. It's probably, due to some geopolitical reason. I guess there is no treaty between between US and Brazil, and this is probably why they did nothing. But we I published this Twitter thread, few weeks ago now, and I'm I am pretty sure the FBI knew who this guy was a long time before.

Speaker 2: Starting some new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.

Speaker 3: No one goes to Hank's for his spreadsheets. They go for a darn good pizza. Lately though, the shop's been quiet, so Hank decides to bring back the $1 slice. He asks Copilot in Microsoft Excel to look at his sales and costs and help him see if he can afford it. Copilot shows Hank where the money's going and which little extras make the dollar slice work. Now Hank's has a line out the door. Hank makes the pizza. CoPilot handles the spreadsheets. Learn more at m365copilot.com/work.

Speaker 4: Where's your playlist taking you? Down the highway, to the mountains, or just into daydream mode while you're stuck in traffic? With over 4,000 hotels worldwide, Best Western is there to help you make the most of your getaway, wherever that is. Because the only thing better than a great playlist is a great trip. Life's a trip. Make the most of it at Best Western. Book direct and save at bestwestern.com.

Speaker 5: Whatever your thing, it could be anything. Canva helps you make that thing a thing. Canva is a simple online tool thing. It's a way to design with our magic AI tool things. You can social media your thing, generate images or videos of your thing, make decks for presentations to show your thing. Whatever needs to be done for your thing, Canva can make it an even better and bigger thing. Canva, the thing that makes anything a thing.

Speaker 2: He he's also been posting since all of this happened. Have you been following his response to this identity becoming public?

Speaker 1: So when it happened, when the Portuguese, when the Portuguese newspaper, published the article, saw a lot of media attention. He received a lot of of media attention saying, is this true or not? Are you this guy? And he I think the article was published in the morning and for the French. And during at the end of the day, he confirmed to one of the, US newspaper that, yes, I am this guy. I will not hide. So if the authorities want to meet me, there is no issue. I'm not a threat. And, I I can help you, and I will not hide, and I will assume what what I did in the past. We a few days after that, we he did some modification on, his, Instagram account, which was a way to find him also. So this it was a second way to find his real identity. And, also, he locked, his Facebook account. So he did some modification, but, to be honest, this guy was not super clever because, there is still a lot of information about him on the Internet.

Speaker 2: Mhmm. And as we said earlier, it seems as though the mistake that gets you caught is the one you already made. So locking down an account moving forward doesn't do a whole lot.

Speaker 1: But I know for I know for a fact that this guy, a lot of people tried to dox him before because, you know, the hacking community, hacking community is weird. You have a lot a lot of young people trying to take the trying to take the lead on the when someone is super public, famous, like US DOD was, they want to, take him down, basically. And so, a lot of people, discussed with him before, long time before that, and they warm him saying, okay, guys. Okay, guy. You you we can find your identity. You did some mistake, blah blah blah, but he did nothing. He didn't correct it. So it it was not clear hiding.

Speaker 2: Before we kinda wrap up, is there anything about the story that I haven't asked you about? Is there, like, a big element to this that we didn't get to?

Speaker 1: What we can bring to people, police on us, is so this guy was a very famous actor, for two years. He leaked a lot of information, but he was not super skilled. He was not really hiding. Some a lot of cybersecurity, film managed to find his real identity. But at the end, he was able to do what he was doing. So life is complicated. He was publicly, this guy was super strong, was threatening the FBI, saying no one will be able to catch me, blah blah blah. But, in reality, this guy is not that not very happy. And, it's super important for people, police and us, and and, especially young people who love cybersecurity, who want to work in cybersecurity that it doesn't pay at the at the end. Maybe if you choose to be a cybercriminal, you will get a lot of money, But at one point, you will lost everything, all your life, personal life and also professional life. It doesn't worth it. So it's super important for young people, for people in cybersecurity to understand that, okay, it can be sexy sometimes. Yes. This guy managed to do a big data breaches for sure. That at the end, he will lose everything, and he will face some some he will probably go to present at at one point. So, to jail to jail, at one point. So be careful of what you are doing. Be a cyber a cyber security professional is super cool. We have a lot of things to do legally, and so, don't hesitate to to do the the correct choice.

Speaker 2: For anyone who's looking to get into OSINT for the first time, kind of on the side that you're on, on the side that doesn't have people like you looking into you, what what what do you recommend? We have a lot of folks that are interested in this field. Where where should someone who likes OSINT start?

Speaker 1: So OSINT is complicated. What you'll have to understand what OSINT is. OSINT is an acronym for open source intelligence. Open source means publicly accessible, and intelligence, is a super strong word with a big background with, a real meaning and a lot of history behind. Working, I know in The US, a lot of people, have a military background more than in France or Europe general. And, being from the intelligence community is, is super different from being from from the real real world that is like this. And so creating intelligence from information you find on the Internet is complicated, and it's not only, it's not just a question of, oh, I managed to find a tool on GitHub, and, I do have some information. Yeah. I'm doing. No. The most important thing on is to be able to analyze what you have to investigate, to understand the biggest story, behind something. So if you want to go on OSINT, you need to be logical more than technical. And technical being technical is important. You will be able to create some tool for sure. But at the end, if you have a lot of of information and you don't know what you have in front of you, it's just that it doesn't matter.

Speaker 2: Mhmm. That's fascinating. It's about being able to, as we were talking about, hold the person behind this data that you're finding in your head as they come into clearer and clearer, you know, image relief?

Speaker 1: Yes. It's like, I I don't know if it is a word in English, puzzle.

Speaker 2: Puzzle.

Speaker 1: Yeah. But it's like a puzzle. It's I mean, when you are watching a movie, a movie about, I mean, when you are watching a movie, you see the investigator trying to understand what happened. And at the end, this is super clear. Okay. This this guy is guilty. He did that blah blah blah. But in real life, it's more complicated than that because you have everything. You have a lot of data, but you need to your brain must be able to do the correct link. You need to understand the situation based on data, which can be in incomplete. And, you need to sometimes try some stuff, try some hypothesis, be wrong a lot, and, come back, try to find more data, and understand what happened. So it's complicated because life is complicated, and, it's not just black or white because life is not black or white. If you want to work in Osint, this is past your this is really a passion. You will learn a lot of things. You will work on a lot of different topic because, I mean, I met a lot of cool people and worked on different stories, but you will also work on on horrible stuff sometimes because this world is made of horrible people sometimes, rebel crimes. And we need, as a society, people to investigate and to do this work, and this is why, the work of law enforcement all over the world is super important because, we need these guys, to to do their work and to find to catch the bad guys. So, also, just a small part of what law enforcement all over the world is doing. It's cool, and some citizens can do it. But be careful of what you are doing because great power, great, big responsibility, as always.

Speaker 2: Matisse, this is a fascinating investigation. It was great to read about, and thank you for sitting down and taking me through it. This was a very fascinating conversation.

Speaker 1: Thanks to you. Cheers.