episode.ascii — live render
● episode

The King of Ad Fraud

TL;DRRussian cybercriminal Alexander Zhukov, self-dubbed 'King of Fraud,' ran a massive ad fraud and money laundering scheme. Human Security exposed him and later uncovered an even larger operation called Vast Flux targeting programmatic…

The story of how profitable it can be to serve ads to nobody, featuring Zach Edwards from HUMAN Security. We discuss Methbot, Vastflux, how organized criminals use ad fraud to launder wild sums of money, and how HUMAN took down some of some of the biggest ad fraud networks online today.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: Every couple of years when a company like ours comes out and says, hey, everybody. Look. We just took down another giant ad fraud operation. Shocker. It's connected to another Russian cybercriminal. Shocker. They've been indicted and when charged with money laundering. Shocker. The scale of this network would only be possible if you started with a giant pile of cash.

Speaker 2: So back in 2017, a guy named Alexander Zhukov gives himself this nickname that in retrospect probably got him more negative attention than it was worth.

Speaker 1: Yeah. To be fair, if you do that and you make yourself, a little bit of a target when you call yourselves the king of fraud

Speaker 2: The king of fraud. Is it hubris to self identify yourself as the king of a kind of crime? But to be fair,

Speaker 1: he was pretty good at crime. So let's

Speaker 2: Seems like he was really good at crimes.

Speaker 1: He he was really good at crime, but also, was extremely loud about it. And I I briefly, I wanna mention one thing. So Mhmm. His indictment. People can go read the Department of Justice indictment. You can read tons of of open court documents and reports from our company and and other folks. What's important to read as you get into those details, he was charged with basically an ad fraud scheme and fraud, but also money laundering and conspiracy to launder money. And it's crucial for everyone to understand that ad fraud is, for many cybercriminals, merely a vehicle for money laundering.

Speaker 2: So we make a tech show, and we've worked in digital advertising. And somehow the idea of even looking into digital ad fraud never really popped into my head because I thought it was a little story. I thought it was like people spoofing websites, maybe. It's kinda interesting, but not enough to hang a whole episode on. But it's not. It's way weirder and way bigger than at least I thought. If you were to draw a diagram of the big categories of ways that people steal with computers, like ransomware, phishing credentials, like scams, you should probably include ad fraud as its own whole category because it's huge, and it's not used for really what you think. There's plenty of TV shows and fun,

Speaker 1: narratives so you can understand money laundering. And the simple process is usually a criminal hands someone a big bag of money. That person has to find ways to buy things or push that money into shell companies. And, usually, some cut of money disappears. So let's say you're handed a million bucks, and you can only launder 800,000. Because 200,000 had to go to the various people that helped you take that illicit money and turn it into gold bars. And so, historically, there's been gold money laundering and all these different cash and currency and and precious minerals that resulted in a reduction of money. But what's scary about ad fraud money laundering is these criminals can be handed $10,000,000. And if they have a legit ad fraud operation that triggers dozens of fake auctions, they turn that 10,000,000 into 30,000,000. And they're not laundering with a reduction. They're actually increasing revenue, and it's more like an investment scheme. It's laundering, but profitable.

Speaker 2: Wild. And it's all happening inside this labyrinthine system that delivers you ads when you consume media online. It's less common in audio, but even hacked uses a form of programmatic advertising. So, I called up the folks at Human Security because I wanted to talk to whoever took down that king of fraud. And they said, oh, you wanna talk about ad fraud? Just hold on a sec. And then a couple of days later, they dropped this press release, announcing that since that King of Fraud, something even bigger had come along. And now, they'd gone to war with it. A campaign called Vast Flux that pitted human security against a large organized crime syndicate with a lot to lose. So, we're going to discuss the history of ad fraud online, the fall of the king of fraud, and the strange new frontier that is vast flux, featuring Zack Edwards of Human Security, here on Hacked. How are you doing, Scott?

Speaker 3: Well, I've been better. I'm, just getting over an illness, as you might be able to tell by a moderate amount of an increase in my nasal, sound, which is which is normally very high, but it might be even higher now as I am quite quite stuffed up.

Speaker 2: You turned it up to eleven a little bit on that one?

Speaker 3: I I live at 09:10. So the last few days, it's been it's definitely been an eleven.

Speaker 2: Yeah. I'm I'm kinda getting over a little bit of a a head cold type thing over here too. So we're gonna have two really, really broadcast ready hosts for this episode. It's gonna be

Speaker 3: great for

Speaker 2: for listeners.

Speaker 3: Well, you know, it's it's good though. Like, I don't think either of us have had COVID. Like, this isn't COVID. So we're starting to get, you know, the regular the regular stuff again, which is yeah. I don't I don't know. It's for me, it was actually worse. Having had COVID, I actually found COVID easier than than, strep throat. So

Speaker 2: You you're you're wistful for the halcyon days of COVID.

Speaker 3: Exactly. Exactly.

Speaker 2: What a time to be alive. So we typically we we typically do our shout out to our patrons on Patreon, best patron on the Internet. At the end of the episode, before we jump into things, do you wanna you wanna mix it up and thank them upfront?

Speaker 3: Sure. Sure.

Speaker 2: I think we do it. Matt Bowe, thank you so much for your support. John Cortes, Damien Castile, thank you. Both of you. Ryan Thompson, thank you. Orla, thank you so much. Emile Peron, thank you. And Alyssa, thank you for editing your pledge. And if you wanna support your show with all those fine people, you should check out hackedpodcast.com because it redirects to our Patreon.

Speaker 3: And And. Our now very active Discord.

Speaker 2: Oh, that's true. It's a thriving thriving community.

Speaker 3: It went from went from went from zero to to a to a semi active little Discord pretty quickly.

Speaker 2: Of a lot of people sharing, like, links to the sketchiest stuff on the Internet. Like, the the links aren't sketchy. They're all very, like, safe links, but just to the sketchiest stories. It's it's where I wanna hang out on the web. Just people talking about the dodgiest stuff.

Speaker 3: Thanks to all the new patrons and and all the existing patrons, obviously. It means a lot to us.

Speaker 2: So much love. Appreciate your support.

Speaker 3: A little bit of an update on our merch stuff. We're waiting on the first round of designs from our art director. So hopefully, we'll have that stuff soon. And in that, I think we're gonna do our first round of stickers, which many of which are owed out to patrons. So so so thank you for your patience. And, yeah.

Speaker 2: So we're talking about the weird world of hacking programmatic advertising. And when someone says programmatic advertising, what they're really talking about is all almost all digital advertising. And to get your feet under you on that one, it's probably worth starting with a bit of an evolution of where ads came from, starting pretty much all the way back with newspapers.

Speaker 1: And what does that sort of mean historically? Ads were for hundreds and hundreds of years, sold in newspapers. That was the core way that they were being sold. There's legacy ads. They're always fun to explore, selling everything from horse glue to wagon wheels. And as we got into the Internet age, a lot of the newspapers started to make ads on their website. And so people were basically buying one ad on the print version, and there would be maybe a page on their website that had all the ads for that week, just sort of listed out. And as sort of this opportunity to show ads on the Internet became better understood, companies started to say, well, how can we have to show the same ad every time you load that page? What would happen if we had different ads waiting to be shown and people maybe paid more money to get at the front of that list. And people started to explore these topics, ad queues, and various simple technologies until eventually around 2,000 ish time, this concept of basically an auction on the Internet was created. Programmatic advertising is essentially digital ads being auctioned on the Internet as soon as you load that website or app.

Speaker 2: When you go to a website, you load a page, there's this brief moment before the ad shows up where this real time auction is taking place. A little blip of time, different advertisers are bidding for the rights in that moment to show

Speaker 1: you an ad. That process, that brief moment where the ads were on the page is known as the programmatic auction or the real time bidding auction. There's other sort of technical phrases for it. But, basically, just this is the process where a series of companies are basically, auctioning off your attention. And a variety of companies work in this ecosystem both to secure it, to help monetize it, to support the deployment of these tools. It is a giant, hundreds of billions of dollars ecosystem. And so when someone says programmatic, you can get really into the into the weeds and talking about how it technically works. But when you take a step back, it's important to really understand this is we're getting close to a trillion dollars in programmatic advertising revenue being shared across thousands of companies.

Speaker 3: Should we should we tell everybody that the ads in our podcast are actually programmatic?

Speaker 2: We probably should. I I think that's what's interesting about it is that pretty much all media that anything that isn't hidden behind a paywall, it's probably being supported by ads.

Speaker 3: Absolutely. The revenue of the Internet is is ad revenue. So the like, we in the Hacked podcast, like, our ad insertions are dynamic. And, actually, I think geographical. Because recently on one of the recent episodes, one of our listeners, who's a close friend of ours, actually said that they heard a school board ad Uh-huh. For the regional school board that he lives in. So that means that they geotargeting their dynamic insertions to to people downloading the episodes within a region. So it's not just, you know, an auction for the space, which does occur too. So, like, we have standing ad contracts with companies that we read the ads for, but the ads that we don't read are dynamically inserted based on an auction.

Speaker 2: You take that like, that's a relative amount of complexity for our little podcast. You've got all these different ways that ads are ending up in the show. Now rinse and repeat that and scale it to the size of the entire Internet, and you start to get a sense of how big this is.

Speaker 3: Well, you you go look at Google's income statement Mhmm. And you'll see how big it is. It sure will. Because I believe Google is the single largest ad auctioneer on the Internet.

Speaker 2: Yeah. AdSense is still king. Mhmm. You got this whole industry. On one side of it, there's the eyeballs, the the viewer, the listener, the consumer. And then on the other side, you've got the content, the website they're going to visit, pretty much all media, journalism, and content distributed online. And this giant nearly trillion dollar network of ad buyers and sellers right in the middle of all of it. Anything that's not behind a paywall, paid for by ads. And this is the economic relationship, like you said, that kinda pays for the Internet.

Speaker 1: A good way to think about the importance of the online advertising ecosystem is that the modern news infrastructure, And we're not gonna get into discussions about the different news sources and their trustworthiness, but almost across the board, news organizations in this world are funded through a majority of online advertising. And so as people sort of start to understand what is programmatic advertising literally funding right now, it starts to become clearer that this is an economy on the Internet. And when you are talking about something that is nearly a trillion dollars, it is easily one of the largest global marketplaces that has ever existed. It is also one of the few marketplaces that are not restricted by geographic lines in the exact same extent that physical goods are?

Speaker 2: A trillion dollar marketplace. So broadly speaking

Speaker 3: It's quite substantial.

Speaker 2: I should say so. So broadly speaking, how do folks hack it? Off the top of your head, where do you start? You wanna make a buck tomorrow exploiting the vulnerabilities of the system. Where do you begin, Scott?

Speaker 3: Well, if if you're gonna make a dollar and not from selling something, then there has to be some process that allows you to generate funds. So whether that's crypto mining or whether that's, you know, you name it. There must be some way to leverage the computers of the people looking at the ads to generate revenue. At least that that's to the best of like, my best guess. Because other than

Speaker 2: Yeah. Sure.

Speaker 3: Other than just outright crime and stealing stuff from those companies, maybe putting on ransomware and charging a percentage return on that or something like you know, something along those lines. But but to me, if you're just doing an ad scam, there must be some way to generate revenue from the scam. And I'm I honestly don't know. Once you have a way to generate funds, you use the ad networks as essentially a delivery vector for the Trojan malware, you know, you name it. Whatever you're trying to put on somebody's computer, use to leverage somebody else's hardware. You're just using the, the ad networks as a as a broadcast system to deliver your attack. Interesting. So am I right or am I wrong?

Speaker 2: You almost brought up, like, a a another way of thinking about it than most of what we talked about, which is using ads to deliver other exploits to people, and that does come up. Botnets are a really big part of this. But a lot of it has to do not with using ads to deliver something malicious, but about using malicious techniques to trick the people paying for ads to giving you that money.

Speaker 3: Like forcing clicks, things like that.

Speaker 2: Exactly. If we started the simplest version, it's as basic as just spoofing. Way back when you wanna read the New York Times, Here's my weird, dodgy, fake version that I'm gonna spam all over the Internet.

Speaker 3: Sure.

Speaker 1: One of the historic examples of a an organization that faced really significant ad fraud attacks, is the New York Times. And so you can imagine the New York Times is a company that their web infrastructure has always been of some interest to, people trying to make money through various schemes, through comments, spam, and and all the different online schemes that could exist. But on the programmatic advertising space, there's also been the concept of spoofing websites. And so this is fortunately, we're a few years past when this was the biggest problem for the industry, but there was a time, five, six years ago when you could essentially say, I'm the newyorktimes.com. And you could broadcast this information, and it could be inaccurate. And so there were countless bad actors that would look at a website, and if it had a good reputation and what's known as a CPM rate, which is a cost per mille or cost per thousand advertising impressions, If their rates were high, where whereas, basically, brands would pay a large amount of money to show their ads on that website, criminals would then pretend to be that website and take money from major brands who thought their ads would be showing up on the sidebar of the New York Times, but were showing up on some black hold, garbage website.

Speaker 3: So wait. I just gonna I just gonna reframe this because I think it was just reframed for me. Bingo. These people aren't making money using ad networks to exploit people. These people are using they're creating their own ad platforms and then selling that property in these dynamic marketplaces. And they're making money

Speaker 1: Exactly.

Speaker 3: Through set like, through people thinking they're buying legitimate ad space, but they're actually buying illegitimate ad space. Exactly. This makes complete sense.

Speaker 2: And that simple version of a fake site is the, like, rubbing two sticks together that eventually scales up to, like, rocket ships. It's the crudest version of this idea and it just gets more and more complex from there.

Speaker 3: Well, Jordan, I don't know how much sports you watch. If you ever try and find a stream

Speaker 2: Oh, yeah.

Speaker 3: Of, of any kind of sporting event online Sure. Usually, there's been one I'll I'll use the term legitimate streaming site. Like, there will be, like, some somebody or some group has created a site that rebroadcasts sporting events and stuff like this. And then there's a 900,000,000 knockoffs of that one legitimate, quote unquote legitimate a a legitimate source of stolen content, then there'll be 900 illegitimate copies of it Yeah. That are just there to force ad clicks. And it's mayhem. So I I completely I completely see where you're going now.

Speaker 2: You're talking about the to to borrow Zach's phrase, black hole of a garbage website.

Speaker 3: Yes.

Speaker 2: I'm trying to name these more literally now for discoverability. But if it wasn't for that, that is definitely what I would call this episode, black hole of a garbage website.

Speaker 1: And we we refer to them more in the industry as made for advertising websites, MFA. So that will be the industry term. I call them black hole garbage websites because once you hit them, you have no idea where you're gonna end up, and they will likely rip your your data into a million pieces and then send it off somewhere to be, monetized. That's approach one.

Speaker 2: Spoofing real sites. But over time, ad networks and media companies, they start to catch on to that. So you gotta move on. You gotta complicate it a little bit. The grift must evolve as we click into the two thousands. From there, we arrive at this concept of invalid demand and impression fraud. Because underlying how those ads are served is a little bit of code, a little bit of JavaScript. That kinda defines the terms of how the ad gets served up to the person.

Speaker 3: Of course.

Speaker 2: Importantly, to start, how long the ad displays for. So maybe you muck with that. This concept of creating invalid demand

Speaker 1: or impression fraud can be as simple as a multiplication times two. So just to just to catch everyone up, most of the Internet sends data in websites and apps through, a code language called JavaScript. And there's countless other languages. And all the languages have one thing. It's pretty much in common. They can use math. And so the simplest way to think about a the simplest ad fraud scheme is the appropriate length of time to keep an ad on the page is, let's say, thirty seconds. This varies depending on the ad, but one of those display ads is just sitting on the page. And so let's say instead of thirty seconds, someone wants to make it go for ten seconds. They could literally do timer equals 60 divided by whatever the number is they're looking for or throw in a couple variables to make it spicy, make it a little not plain math staring at you. But the concept of what this would result in is it would create impression fraud where they were only supposed to basically change their ads every thirty seconds, but a developer realized they had access to do it differently, decided to violate the terms of the network, started refreshing the ads every ten seconds.

Speaker 3: Or layer them. Mhmm. Stack six or seven ads on top of each other because nobody's really checking for visibility. Like, they're visible, but they're just z index behind something else. Totally. So you could have a million ads on a single website that nobody knows that you can't see any of them.

Speaker 2: And this is happening at such a massive scale. I think the number everyone sites is between six to 10,000 ads per day for the average Internet user, will see, essentially. This is happening at such a huge scale that probably no one's ever really gonna notice. But over time, if you do it enough at a big enough scale, those networks, which do have a an incentive to try and catch this behavior, will start to catch on because they start to notice patterns. Wow. This one site is serving up ads at a rate that is kind of impossible. They're clearly breaching our terms of service, so so we're gonna nerf this. They come up with another thing, another exploit like this, we nerf that. So over time, the complexity has to ramp up again. So it switches. Moves from impersonating a site or fudging the math on how quickly ads display, and it gets into what Zach calls stealing bandwidth. Taking control of devices and directing that traffic to wherever you're hosting ads. Say, I wanna take control of hundreds, if not thousands, if not millions of devices and direct their traffic to whatever black hole garbage website I control. How would you go about doing that?

Speaker 3: DNS stack would be my easiest way to do it or, like, the way that I'd probably start. If I had to choose choose a trajectory to to force people's legitimate traffic to go to illegitimate places, To start a DNS attack or to to artificially add people's, you know, modify people's local lookup records, you'd need some form of local access. So it'd be something in the malware space, I would assume.

Speaker 1: Well, I could develop malware. And so that's been the classic way that, almost every ad fraud investigation that we've looked into, at least some portion of their traffic were compromised devices. And one way to think about it is ad fraud is like a big affiliate scheme or affiliate market. And specific criminals know that they can create an infrastructure, through malware or specific compromises and then rent it to other criminals. And so it's a classic scheme of basically crackers, software crackers,

Speaker 3: who install

Speaker 1: basically marketing malicious marketing as a service technologies into it. And then once they get someone to install that malware, they can sit back from where they're located, reach out to other criminals saying, hey. I've got a couple thousand devices who installed this malware. Do you want them to do anything? Do you want them to DDoS a website? Do you want them to try and commit account compromises? Do you want them to juice impressions on specific websites or apps? And so a lot of what this impression demand comes back to is who has access to compromised devices, or who has code that could be inserted into an online auction to dynamically compromise devices, or who has thousands of fake publisher websites that they can install malicious code into. And so there's just basically different places along these supply chains where you could inflate the impressions in all these different ways directly on the website, through the banners that people buy, through malware on the device, and all of the above are basically used by these malicious networks. And so core companies like ours, we are looking for threat actors, what they are trying to make money from, what they're using to make that money, and who they were targeting. And it oftentimes can result in large victimless from real user devices to the publishers impacted, to the brands who were buying millions in fake ads that never showed, to the advertising networks that lose credibility or, have to fight back from maybe dozens of fake accounts created by a bad actor group.

Speaker 3: In the in the online legal streaming section, which I know is rampant with this issue Yeah. Not that I spend any time in it, but the No. There's there's always some at some point, you always end up clicking something that you isn't meant to be clickable.

Speaker 2: Mhmm.

Speaker 3: And it's and all of a sudden, you're downloading an EXE file. Like, even if you're on Mac or Linux, it's it's like you can tell that they're forcing the delivery of a lot of this malware through these networks.

Speaker 2: A lot of the modern versions of this rely on compromised devices to do it, but this system is also a fantastic way to compromise devices. It becomes the Exactly. The snake and its tail in that kinda metaphor. It's not one hack. It's this whole category. You can spoof real sites to get real real eyeballs to watch real ads in the wrong place. You can trick real ads to run on fake sites that you control. You can trick ads to work incorrectly. In this nearly trillion dollar system of unsupervised auctions, distributing god knows how many ads a day is a lot of ways to make a buck. And back in 2014, Alexander Zhukov puts this all together, and inadvertently ends up having something of an example made of himself. Zach referenced this earlier, I think, But the name of Zhukov's big ad fraud botnet thing was called methbot. And I felt like kind of a dummy for a while because I kept reading about this and thinking, when does meth get involved? Like, who put the meth in meth bot? Alexander Zhukov.

Speaker 3: Was it was it the Method Man? It'd be

Speaker 2: a lot cooler if he did.

Speaker 3: Sorry. I've I've been watching I've been watching the, Wu Tang dramatization on Disney plus.

Speaker 2: Oh, yeah.

Speaker 3: Sure. So Method Man is at the top of my mind these days.

Speaker 2: Alexander Zhukov, who is not this is so annoying to Google. Who is not the famous Russian businessman named Alexander Zhukov or the famous politician named Alexander Zhukov is the founder of a company called Media Methane. Methane, botnet, methbot. Methbot. Media methane was supposed to be a digital ad agency dedicated to helping customers deliver advertisements to Internet users. Way back in 2014 when it starts, it began by establishing pretty much legitimate business arrangements with other legitimate advertising networks. According to The United States superseding indictment filed on February 2020, MediaMethane received payments in in return for placing ads on behalf of legitimate ad networks. It had this, again, legitimate front end. But instead of taking those ads and serving them on real sites that they had deals with, with real eyeballs going to them Zukoff and others rented thousands of computer servers located at commercial data centers in The US and elsewhere and used those data center computers to simulate humans viewing ads on fabricated web pages. To convince these systems that the ads were being washed by humans, because again, this is all the way in 2014. These networks have been dealing with this for a while. They're pretty sophisticated. Quote that document. Zukov and Co developed programming code that caused the data center computer servers to operate an automated browser, click on online advertisements a randomly determined number of times, simulate mouse movement, scrolling around on a website, pausing, getting back to it, controlling and monitoring video playback including the length of time the video is watched, all while being falsely signed in to popular social media services like Facebook. All of this to create this illusion of a real person and trick their customers, these ad networks, into thinking they were serving their ads to real people. So you've got these real ad networks in The States contracting out ad placement to Zhukov's company, spending the money of their real clients who are trying to get ads served somewhere, which Zhukov was then serving to his fake sites and tricking him to appear real with this whole smokescreen of fake activity. The result? Media methane falsified billions of ad impressions. Victims of the scheme include companies like New York Post, Comcast, Nestle, Purina, Time Warner Cable, all of which paid millions in advertising fees for this fraudulent traffic. Some of which he reinvested to keep the fraud going, and most of which he just sort of took out, transferring to offshore accounts and international bank accounts.

Speaker 3: So funny enough, at around the same time, we were doing a campaign for a company in our ad agency. And Mhmm. We got approached by somebody who we used to do business with. They were I think an ad sales rep for a local media company, TV, radio, somebody trustworthy. And they had just started working with a new online digital ad network and they were like, hey, you know, we're setting up this big thing and we help a lot of like local businesses and stuff like that. Would you be interested? We'll give you a very favorable rate for your first few campaigns for your first few customers. So we're like sure. So we ran ran some some kickoff campaigns for them. I remember requesting the, like, sheets to justify the the justify where they serve the ads. All of the legals that usually you get the back end from from this stuff is you pay money for it. So you expect it. And I remember after a a while of back and forth, they finally delivered them. And it was mostly to, like, all of the same kind of stuff, illegitimate copies of websites

Speaker 2: Oh, weird.

Speaker 3: And things like that. And I was like, and and the other thing is is that the conversion rate per click was very high, but the but the the conversion from click was very low. So you had a lot of the ads being clicked on. Oh. But then once that traffic came to the website, the traffic would just go away.

Speaker 2: It ends. Yeah. Sure. So I was

Speaker 3: I was like I was like, I'm pretty sure we're being boughtted. Like, this is just bought traffic on these, like, illegitimate sites. So we actually ended up getting in a fight with this company, pulled all of our revenue about them or from them and all of our our clients from them. And and it ended poorly. But I think and I'm not sure what they're doing today, but I feel like they were kind of caught up in the same scheme.

Speaker 2: Interesting. So you kinda glimpsed firsthand into this.

Speaker 3: Yeah. Yeah. And they were just trying to do it at a massive national level. And the other thing is is, like, we were one of the few agencies that they approached, but they were typically direct to consumers. So they were going into small businesses and selling it like you would a traditional newspaper ad or a traditional radio spot. And I I think they were having and gaining a lot of traction. But I'm sure, you know, after some time, you know, you're just not making any money

Speaker 4: Yeah. Sure.

Speaker 3: Because you're not showing any value serving ads to bots. And, like, that was the other thing, is I remember getting the geographical report of where a lot of the traffic was coming from, and it was all coming from Florida. Sure. So our local ads being served to about local businesses within region, supposed to be targeting people within region were all getting clicked from Florida and predominantly from the same IP address.

Speaker 2: Yeah. Like a server farm somewhere where the whole thing was just Exactly. Unfolding on a computer system, falsifying all of that traffic. And I was just like, system, falsifying

Speaker 1: all of

Speaker 2: that traffic.

Speaker 3: And I was just like, hold up. I was like, hold up. This is this is fake. Like, we're not paying for this, and our clients are not gonna be a part of this. So, anyway, I'm I'm not sure what ended up happening to them. It's been, you know, whatever, six, eight years. But, I'd be intrigued to know.

Speaker 2: But that sales rep's name was Alexander Suchart. Exactly.

Speaker 3: Crazy. Anyway yeah. So firsthand experience of this exact thing and then the exact kind of in the similar era too. I think that was 2013, 2014.

Speaker 2: Yeah. Well, back then, it wasn't really, this whole story ends with him having kind of a big example made of him because this wasn't really it was certainly illegal, but no one was going after it. And it's about that point when human, at the time known as White Ops, gets involved. White Ops was aware of Methbot's fraudulent activity, but it was pretty tricky to stop, especially because Methbot was updating their system constantly to avoid detection. Eventually, they make a mistake, and it was not a technical mistake, it was a very human mistake, which raises the question of how long this would have gone on for had they not made this mistake. At some point, a deal between Media Methane and one of their customers goes wrong. We don't know how. But Zhukov decides to retaliate, and spams the customers inventory generating millions of fraudulent and presumably very expensive views. But this giant spike in traffic as this very expensive F U to their ex client that they were beefing with, was ultimately how he had caught them. A warrant gets put out for Zhukov's arrest, he flees to Bulgaria in 2018 to try to remain free, is eventually extradited back to New York, and in late May of last year, Zhukov goes on trial and is found guilty of money laundering, wire fraud, money laundering conspiracy, and fraud conspiracy. Though he pleads not guilty, they find him guilty, and he is sentenced to ten years in prison in order to pay millions in forfeiture.

Speaker 1: What everyone needs to appreciate is every couple of years when a company like ours comes out and says, hey, everybody. Look. We just took down another giant ad fraud operation. Shocker. It's connected to another Russian cybercriminal. Shocker. They've been indicted and when charged with money laundering. Shocker. The scale of this network would only be possible if you started with a giant pile of cash. And so as people start to get through these facts and understand that, and then they say, okay. Wait. So this vast fraud thing that you just took down a few months ago was conducting 12,000,000,000 fraudulent auctions a day? How much money is that? How much money would you need to start that operation? Where would someone get that money, and then what would you do with the profits you made? And so as people start to mentally work through, oh, fraud, we have billions of dollars that are knowingly going through ad fraud schemes, yet we are connecting that dot to who's funding this. And then once that money is generated, what are they doing with it? What type of operation are they building with the proceeds that are in the b's? And so more and more folks need to be understanding that when we say Russian cyber criminals and the department of justice says Russian cyber criminals, and the gentleman is, he he has hubris as folks would like to say, but he he's the the king of fraud, and he openly would, brag about various things and we would appear. We need to basically start connecting the dots to what are other Russian cyber criminals involved in. Ransomware. Once you get ransomware money, what do you need to do? Oh, launder it. And there's a series of money flows and crimes where we're investigating one crime, we're investigating another crime, and we are aware that there's large amount of money flowing through these ecosystems, but not enough people are trying to connect the dots for how the money got there in the first place and what people are doing once they've generated the illicit money. And so, hopefully, more folks can start to wrap their heads around this is an economy of crime. And ad fraud both can generate illicit revenue, but it also can be a vehicle for money laundering, and that money could have come from other illicit proceeds.

Speaker 2: So wild. So human takes down this guy, who in a text unearthed by the Department of Justice refers to himself as the king of fraud. But in light of what Zack just said about how operations of this scale require large institutional capital to set up essentially require large organized crime venture capitalists looking for a return on their investment and a way to launder money you arrive at the obvious question. Now that they've taken down the king of fraud, where do those financiers point all that money? Bringing us to vast flux, And the answer to that question, which seems to be pump more money into this than anyone ever else has in the history of advertising or computers after the break.

Speaker 3: Never stop pumping money in.

Speaker 2: This episode of Hacked is brought to you by massive scale ad fraud. With traditional money laundering, for every dollar you put in, you might hope to get out 80, maybe 90¢. But with unprecedented scale digital advertising fraud, not only can your large organized crime syndicate launder funds, but you can expect to see a two to 300% return on the money you were laundering. It's laundering, but profitable. Right now, you can vanish unfathomable sums of money into the nebulous pit that is our attention economy using the promo code hacked podcast to get 10% off. That's promo code hacked podcast for 10% off massive international advertising fraud. Starting some new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's going to work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify ify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.

Speaker 5: No one goes to Hank's for spreadsheets. They go for a darn good pizza. Lately though, the shop's been quiet, so Hank decides to bring back the $1 slice. He asks Copilot in Microsoft Excel to look at his sales and costs and help him see if he can afford it. Copilot shows Hank where the money's going and which little extras make the dollar slice work. Now Hanks has a line out the door. Hank makes the pizza. Copilot handles the spreadsheets. Learn more at m365copilot.com/work.

Speaker 4: Whatever your thing, it could be anything. Canva helps you make that thing a thing. Canva is a simple online tool thing. It's a way to design with our magic AI tool things. You can social media your thing, generate images or videos of your thing, make decks for presentations to show your thing. Whatever needs to be done for your thing, Canva can make it an even better and bigger thing. Canva, the thing that makes anything a thing. Where is Daredevil? A miner.

Speaker 5: Don't miss the return of Marvel Television's Daredevil Born Again.

Speaker 3: So what's next?

Speaker 2: I've been liberated. We're gonna take this city back.

Speaker 5: Over Medicaid. In an all new season now streaming only on Disney plus.

Speaker 6: They're hunting us. It's time we started hunting them.

Speaker 2: I can work with

Speaker 1: that.

Speaker 3: This should be tons of fun.

Speaker 5: Marvel Television's Daredevil Born Again, streaming only on Disney plus.

Speaker 3: I just I just pulled up the data from that, I don't wanna say the company's name. No. No. But I just I I just pulled up the data from all of that stuff from that, like, ad campaign that just triggered it in my mind. And and I went through and, yeah, we had I remember one of the issues was that it ruined Google Analytics because all of a sudden we had this, like, massive discrepancy in traffic coming in from Windermere, Florida.

Speaker 2: Oh, a a den of fraud and crime.

Speaker 3: Yeah. Exactly. Everything that goes on in Florida is always very up and up. You know?

Speaker 2: Especially in Windermere. So,

Speaker 3: anyway, yeah, very, very interesting.

Speaker 2: So let's let's discuss let's discuss the big guys and what they got up to next. So far, most of the stuff we've talked about has involved tricking the ad networks into serving ads somewhere they shouldn't or tricking people into looking at ads on a place they didn't mean to. But hypothetically, if you had the resources, there's this other option. If you could throw the resources at it, throw just like the human capital at this, You could go after all of these networks and actually hack them. Going one by one down the list and spend the time and money developing basically zero days for all of these different ad networks. And once you've gotten control of them, use that to direct the traffic flow of ads really wherever you want. And if you had enough resources to be constantly cycling every element of this plan, It would be exceptionally hard to stop. Until someone were to come along and point a lot of resources at stopping you, you've essentially opened this money spigot. That's fast flux. Every time I tried to condense or summarize this, I was losing a lot of technical detail. So I'm just gonna hand it over to Zach to explain how this worked, how it ran, and how ultimately humankind of mapped and was able to stop Fast Flux. And it all starts with this technical exploit, the one that inspired that name, Fast Flux. VASTFlux is named after a DNS evasion technique called FastFlux

Speaker 1: with an f instead of a v. And so the brief technical description of this is you rotate your domains and the IP address that those domains are hosted on extremely fast. Every minute, every five minutes. And so, basically, the way that it would look would be let's say you load up, espn.com. If someone if a bad actor was in control of it and there was this fast flux infrastructure on it, every few minutes as you reload the page could be a totally different experience. And so there have been criminal actors who have built malicious infrastructure that constantly rotates, and so this name was created to describe this technique. And ad fraud operators basically said, oh, shit. That looks like a really good way to hide your infrastructure to keep it from being blocked and to also, for whatever the purpose, to keep your infrastructure up longer. And so the vast flux bad operators registered a huge amount of look alike domains where at first glance, it may look like an advertising company that you've been working with for years. And they registered a a host of domains that they basically used in a giant fraudulent AB testing infrastructure. And so the simplest way to think about it is these bad actors had access to a large amount of money and at some point developed what some folks would call zero days against advertising systems. So they theoretically investigated dozens of first tier, second tier, and third tier advertising partners. They looked for any literal technical weaknesses, cross site scripting, various injection schemes, looking for any defensive holes. And then once they had established that specific companies had a minor problem here or a minor problem there, they crafted specific code to exploit that, and they basically created code that would exploit the weaknesses and then trigger fake auctions on someone's device that no one else would see. And so the apps, the advertising partners, whole bunch of people in the ecosystem were targeted, and these bad actors sort of saw a door and then created a closet and then filled that closet with bots and monetizing, devices. And no one even knew this this door existed, and no one even knew there was a closet behind it until some of our researchers through the specific methods that we use that we don't really get into, basically saw that some apps that should have been totally fine were generating large amounts of auctions that seemingly were not connected to the, legitimate auction systems. And so when we first saw this, the initial collections, you could imagine, would be maybe two or three domains. Let's just for the simplification stake. And so as we sort of say, oh, look. This one app, it appears that some advertiser is aggressively buying the ads, and, wow, they're doing something really funny here. I wonder if this exists anywhere else. And we basically posed the question through data science means, and the answer that we got back was shocking, horrifying. It was this giant dynamic infrastructure of constantly rotating domains, constantly rotating shell companies, a fake sort of series of companies within the supply chain, where major brands were interacting with these fake companies thinking they were legitimate and basically giving them money, thinking they were buying ads, that were never showing up anywhere. And this infrastructure, we started to map all of the domains they were using, all the IPs, all of this constantly rotating infrastructure. We basically threw up a magnifying glass on it, captured it, and then we deployed defenses across our infrastructure and across all of our ad tech partners where not only, were we explicitly blocking various, infrastructure they may have, but we knew these bad actors, there's an unlimited amount of domains. So if to stop a scheme like this, you can't just block the infrastructure they're using because we block it. Twenty four hours later, they have 500 new domains, and everything is back up and running. And so this type of infrastructure really requires dynamic rule based understanding of these fraud schemes so that we can basically create detections where when a malicious actor somehow can create dozens of fake auctions, we now have detections to see that before people and to stop it so that, less and less money are going to these bad actors. But it's important to understand, and your your audience as they're hearing my voice may not be able to visualize this, but, our company released some graphs showing exactly what the takedown looked like. The literal time, the days, and the the volume of the fraudulent requests. And the narrative, which is important for folks to understand is, we were tracking 12,000,000,000 requests a day that were fraudulent. We broke this scheme, and then almost immediately, they tried to relaunch it targeting new devices and new infrastructure. And then another forty eight hours later, we break that. But the volume of these bad actors has never gone to zero. And these types of actors who could have spent months or years not only developing the infrastructure, developing the plans, but writing the code to exploit specific systems, they absolutely everyone in the industry should expect them to take their infrastructure and now go look for exploits on even lower quality or more niche ad networks that maybe a company like ours doesn't defend on. And so folks who have digital ads and have these ecosystems of money where brands exchange with a publisher, and there are end users that are requesting those ads and generating the volume and and, frequency that that money is leaving the brand's coffers, they all need to be aware that bad actors like this exist. They have schemes to create fake impressions, fake auctions. And if you are not looking for it, you could have a large amount of your money sort of disappear.

Speaker 3: The fact that there's probably just networks of, like, proxy servers and and other technical pieces of infrastructure that allow them to do this probably becomes a big mess of cataloging

Speaker 1: Mhmm.

Speaker 3: Itemizing and removing pieces of that infrastructure. There's probably so many snakes on the on on Medusa's head that it's hard to get them all. So I imagine it's quite the process.

Speaker 2: Quite the process. So I included the methbot king of fraud guy because that story has a really nice cohesive ending. And it's satisfying, right? The guy who self identifies as the king of fraud gets charged with fraud. Because otherwise, this is kind of a story with no end. In this case, FastFlux, the bad guys system does get taken down one by one in that giant feat of cataloging as you described it. But Mhmm. It still made them a bunch of money. They still got the Lambo. And this whole system will now just move, trickling down to sketchier and sketchier ad networks as they work to come up with some new exploit to target those first, second, and third tier ones. But what's neat about it, and we'll wrap up here with a clip from Zack to this effect, is that once you zoom out, you basically have a large organized crime syndicate on one side of it that has invested a ton of money into developing these zero day exploits that would serve, they hope, as the foundation of a money making enterprise long into the future. And on the other side, you've got this group of security researchers that was able to take what those criminals had hoped was gonna be this long term structure and just burn it down. All of that time and money that went into building this giant fraud machine, and they just shoved a wrench into it, and it tore itself apart. That is a lot of sunk cost for these actors, like businesses and businesses worth of it. Will they build new ones? Certainly. Of course. Yeah. It's profitable.

Speaker 3: The infrastructure too is reproducible.

Speaker 1: Mhmm.

Speaker 3: So it's like, you tear it down, you still have the recipe.

Speaker 1: Mhmm.

Speaker 3: You still have the code. You still have you know, you can spin up a a 100 more proxy servers and a a 100 more web servers that serve illegitimate content. It's not hard. I think that as long as there's a financial, you know, as long as there's demand, there'll be supply. For sure. Is, I guess, the easier way to say that. For sure. And I think that we see this, given our advertising side of our lives. Mhmm. We always have a client that's like, hey, you know what? I know of a discount online

Speaker 2: brokerage. We

Speaker 3: can buy we can, you know, instead of paying, you know, x dollars DPM or x dollars or x cents per click, we can pay, you know, a tenth of that. You know, these guys called me. They got all this great network inventory and stuff like that. It's going to be super good.

Speaker 2: Mhmm.

Speaker 3: You know, every time I hear somebody say that, the hairs on my neck stand up because I kind of know what's going on.

Speaker 2: Yeah. Sure.

Speaker 3: I kind of feel like those people are buying space at a discount or who's selling it at a discount? Probably people that don't own. Yeah. New York Times. The New York Times is not selling you their space at a discount. No. So you're buying. You're still buying space and you still might buy space that gets legitimate traffic through deceptive ways sometimes. But, yeah. Anyway, I think the I think to truly stop this problem, it's weird to say and sound even more, you know, monopolistic, but like trusting trusting the the bigger players in the market. I don't know. I don't know if that's the solution or a bigger part of the problem, but it seems like the the more that we let the free market rip with this, the more the more that fraud gets tossed around

Speaker 2: in it. So I think the solution is kind of a multi pronged thing. Because like you said, that that economic like, that that quick math of, well, as long as this is profitable, it sucks that our old thing got taken down, but we'll just build a new one. There's this other variable in that that quick math, which is but we know that there's someone kind of crawling behind us trying to patch these vulnerabilities. And now they sort of know how we did the last batch. So they're probably gonna be even quicker at figuring out the next batch. Yeah. So as long as you have that additional disincentive, it won't stop them from doing this again. They're gonna do this again. But it maybe changes how much they're willing to invest in doing it knowing that it might not be around as long as they'd hoped.

Speaker 3: True. If it re reduce the the future revenues by shortening the time frame, maybe maybe instead of two or 300% returns, they'll only see 100% returns.

Speaker 2: Well, I guess if you can get that number down to sub 100, you're just as good off converting it into gold bars or whatever people used to do for money laundering.

Speaker 3: Yeah. Buy laundromats.

Speaker 2: So let's end there. I asked Zach whether this kind of thing will ever really end, what this vast fuck's crackdown really changed, and how this can be stopped. So that fine, fine media products like Hacked and the New York Times can continue to thrive, brought to you by drop shipping mattress companies.

Speaker 1: We burned a bunch of their zero days. And taking down infrastructure like this oftentimes requires blocking their monetization sources. Modern defense is is really about understanding that these threat actors are relying on the lack of transparency to defraud systems like these ad tech ecosystem. And a modern defense requires communicating to impacted organizations, agreeing on what a wall or a appropriate blocker could be. And in many instances, it's either a let's deploy our walls at x time and date, or in our instance, we help with that coordination on behalf of our clients and deploy those blockers. And so an entity like VAST Flux is run by a criminal group. They're still on the streets. They're still enjoying their espresso. They're still maybe driving their Lambo. They they are still, probably happy as a clam that maybe this worked for weeks on end or, months if to be generous. But they also probably spent a ton of money on the infrastructure, a ton of money developing the exploits. And they are back to ground zero, but ground zero with a bank account full of millions is a dangerous place for the industry to sit back and be like, we got them. Another one bites the dust. And, yes, we got these bad actors. Yes. This is something we should all be super proud, and this is really special collaboration across a large amount of companies. But the bad actors that profit from these games probably still felt like it was some degree a success or learned something about that, and we'll just try and evolve and do it, in a more sophisticated way and with even more off e station. So this time was a vast flux, fast flux dynamic, hundreds of domains orchestration techniques. The next time, it'll probably be something that I don't even wanna allude to and give people bad ideas. So let's just say the bad actors will continue doing what they're doing until we increase the ramifications on their bad behavior.

Speaker 2: When I found out I was gonna be a

Speaker 1: parent, I immediately felt a lot of anxiety and worry. So So I went on to BetterHelp to try to look for a therapist to help me with that.

Speaker 6: My relationship with my family and with my boyfriend and with myself were suffering. I really needed help. I was ruminating a lot. Really getting those thoughts out to a therapist and getting feedback was just life changing.

Speaker 2: Discover what BetterHelp online therapy can do for you. Visit betterhelp.com today.