Secret Team Saves $1B from Hackers
45sThe mystery of an anonymous team saving billions sparks curiosity and awe.
▶ Play Clip"Title is catchy but the content delivers on the promise of a dramatic cybercrime story with real substance."
The video explores the work of Bitdefender's Draco team, a group of cybersecurity experts who volunteer to hunt down cyber criminals. It details their takedown of major ransomware operations like GandCrab and REvil, saving victims over a billion dollars, and discusses the growing threat of AI-powered scams and the defensive measures being developed.
The Draco team is a group of volunteers at Bitdefender who hunt cyber criminals on the dark web. They are real malware researchers and forensics experts who volunteer their time.
The Draco team targeted the GandCrab ransomware group after they infected the computer of a team member's girlfriend. GandCrab operated as ransomware-as-a-service, with a core group and affiliates splitting profits 30/70.
The team created decryptor tools that allowed victims to recover their files for free, disrupting the criminals' business model. They released five decryptors over two and a half years, destroying trust between the gang and its affiliates.
After GandCrab, the team targeted REvil, which shared 50% of its code with GandCrab, indicating a rebrand. REvil was responsible for high-profile attacks on meat supplier JBS and tech giant Apple's supplier Kaseya.
The team produced a decryptor for REvil that stopped $1 billion from being paid to criminals. A backdoor discovered in the malware revealed that REvil was actually a rebrand of GandCrab, leading to its collapse.
Cyber criminals are now using AI to create more convincing phishing scams and deepfakes, eliminating the skill gap between junior and senior developers. This has made scams more personal and harder to detect.
Bitdefender has built an AI defense team to fight back. They use AI to detect deepfakes, analyze intent, and run scammer honeypots that waste scammers' time and gather intelligence.
Scammers are now using multi-platform scams, starting on one platform and continuing on another, making detection harder. Bitdefender is developing multi-touch point attack detection to correlate events across platforms.
The team shares stories of victims, including a PhD student who lost a month of research and a couple in Syria who had photos of their deceased children encrypted. These stories highlight the personal impact of cybercrime.
Bogdan, a director at Bitdefender, states that cybersecurity should be a fundamental human right, emphasizing the importance of securing digital life.
The Draco team's efforts have saved over a billion dollars and dismantled major ransomware operations, but the fight against cybercrime is ongoing. As criminals adopt AI, defenders must also innovate, and the video underscores the personal, human impact of this work.
What is the Draco team?
A volunteer group of cybersecurity experts at Bitdefender who hunt cyber criminals.
00:17
How did the Draco team disrupt GandCrab?
By releasing five decryption tools over two and a half years, destroying trust between the gang and its affiliates.
06:10
What was the profit split in GandCrab's ransomware-as-a-service model?
30% to the core group (developers) and 70% to the affiliates.
03:41
What was the default ransom amount for GandCrab?
$600.
04:52
How much money did the REvil decryptor save victims?
Over $1 billion.
08:39
What evidence linked REvil to GandCrab?
REvil shared 50% of its code with GandCrab, and a backdoor revealed the connection.
07:40
How has AI changed cybercrime?
It eliminated the skill gap between junior and senior developers, making scams more convincing and personal.
10:40
What is a scammer honeypot?
An AI that answers scam calls and wastes scammers' time while gathering intelligence.
15:25
What are multi-platform scams?
Scams that start on one platform and continue on another, making detection harder.
17:36
What did Bogdan say cybersecurity should be?
A fundamental human right.
24:46
Systematic Disruption
The strategy of releasing multiple decryptors over time was key to dismantling GandCrab.
06:10Billion Dollar Save
The REvil decryptor prevented over $1 billion in ransom payments, a massive impact.
08:39AI Levels the Playing Field
AI has made cybercrime accessible to less skilled criminals, increasing the threat.
10:40AI Honeypot
Using AI to waste scammers' time is a creative defensive tactic.
15:25Cybersecurity as a Human Right
A powerful principle that reframes cybersecurity as essential to modern life.
24:46[00:00] They have saved victims over a billion dollars and helped dismantle criminal empires and almost no one knows who they are. Let's change that.
[00:17] but Defender HQ inside this building are the members of the Draco team, I think. Can you tell me who's on the team? No, that's for safety reasons. But what they do is we lower on the dark web and we look at dark markets.
[00:33] This decryption tool stopped $1 billion from being paid to the criminals they infected the computer of the girlfriend of one of our most
[00:45] We're going to dive into all that, them this, do you feel like you're winning the war with cyber crime? Now, what Alex just said right there is terrifying,
[01:00] AI scams are everywhere, deep fakes, phishing attacks, and you can't tell they're getting too good. But later in the video, They're using their own AI to waste scammers, time to detect deep fakes.
[01:16] get you coffee ready. Let's dive into the world of the Draco team. Bitdefender HQ is because every member of the Draco team works for Bitdefender,
[01:29] and that's important to know because they are a real malware researchers, real forensics experts that by day help keep individuals and businesses safe, but by night they volunteer to hunt down cyber criminals, fight cyber crime.
[01:42] It's like the Avengers without the enthusiasm. they need a day job to help cover their after hours crime fighting activities, They also flew us out there and sponsored this video, so thank you.
[01:55] My name is Alex Ve and I'm the chief security strategist for Bitdefender. I think he might be the Samuel L. Jackson in this scenario, but again, is crucial.
[02:09] That's why the members don't make public the fact that they are involved But what have they done to make all these cyber criminals so upset with them?
[02:24] They infected the computer of the girlfriend of one of our Now this story is crazy for two reasons. First, I love the motivation. We're coming after you. Now, that's not always the case.
[02:39] Sometimes law enforcement reaches out to us to ask for assistance. Criminals move fast. They see you come in, they close down shop, and the Draco team has to wait months for law enforcement to catch up and they
[02:54] and they found a genius way to take down these criminals. Now, disclaimer, So instead of breaking down the doors, Welcome to Cyber Criminal Enterprise 1 0 1, ransomware as a service.
[03:11] Ransomware as a service operates like a franchise, kind of like McDonald's. burger recipes, and then you have the franchisees, There was a core group that was building the infrastructure that was coding
[03:27] And then you have the affiliates who like the franchisees make sure the product computers. And they split the money. Like 30% goes to the core group,
[03:41] the developers, 70% goes to the affiliates. you see this infection they're putting on these computers. It's ransomware. It will lock them up to where you can't access the files and you have to pay a
[03:56] But criminals are kind of paranoid, right? I heard there was even cases where they were performing tests with
[04:09] so they make sure that they're not hiring undercover police officer. pay for them, they're willing to pay to have their files unlocked. Otherwise,
[04:24] It's that system that Draco attacked and they made it almost impossible to turn They controlled 50% of the market at its peak, huge presence,
[04:37] but then they made a huge mistake. It got personal. penetration tester on the Draco team, and these guys hold a grudge. This was a two and a half year vendetta. Now again, crab was nasty,
[04:52] The price they were asking was directly coordinated with the amount of interesting files on the drive, and there was a default $600. nothing interesting there, $600.
[05:08] ransom. That's not the case. It's worse. which also looks at the actual databases of people who paid, Think about that. Small businesses, families, grandmas,
[05:24] The criminals were making millions. There was a recent arrest in Russia a couple of months ago and they were filming his house. He had one Ferrari, one Lamborghini,
[05:39] But here's the thing, what if the victims didn't pay? That's the situation. They created what's called a decryptor. This tool is a big deal. It can be used to decrypt the files encrypted by the gang crab.
[05:54] Ransomware for free problem solved right victory. They did it not quite. Every time there was a decryption tool that was released to the public, So now you will not be able to decrypt the new version.
[06:10] Systematic disruption. Over the course of two and a half years, the Draco team released five decryption tools, getting crab couldn't keep up. what happened was that we severely destroyed the trust between the
[06:26] which means the affiliates moved away to work with other groups and the we're closing shop. And they were kind of mad, like really upset.
[06:40] They were even giving interviews in the media. They had a Twitter account. They were cursing the defender quite often. So I'm guessing, yeah, they were aware that they're provoking some frustration back there.
[06:55] the Draco team helped save victims over a hundred thousand dollars. When you compare it to the millions that gang crab gained, They publicly claimed they made enough money and we're moving on to something
[07:10] They came back with a vengeance. The next case that was interesting to look into was another ransomware group This group was from Russia.
[07:25] I just finished Resident Evil four. Amazing. they were a fan of making sequels. How do we choose?
[07:40] The reason we started to look at this one is because it was sharing 50% of the code with Gantt grab. So basically they rebranded. You serious? So Gang Crab said they were done, they made enough money,
[07:54] they got greedy and they rebranded putting on a disguise and hoping no one would They were responsible for several high profile ransomware attacks like the meat They disrupted the food supply chain or the oil company,
[08:09] Kaseya and a supplier of the tech giant Apple Millions were paid out, but Draco, This was another investigation that took about two years, so it finalized in 2019, something like that.
[08:24] And we were also able, in this case, to have another decryption tool. this decryption tool stopped $1 billion from being paid to So similar to Gang Crab,
[08:39] they were able to produce a Decryptor tool and they just gave it to everyone for You could even still download the rebuild to crypto. Let's try it out. It's an E xe. Hopefully this is safe. I'm sure it is. Yeah, here it is. I agree.
[08:54] they had affiliates distrusting Reveal Corporate. A backdoor was discovered in the malware that revealed that Reveal Corporate was
[09:07] And that was the last nail in the coffin. Dismantling that empire. It took four and a half years, They helped so many people saving over a billion dollars.
[09:23] let's zoom into his face. Bogden. Actually, he's right here. My name is Bog Atu. I'm a director of threat research at Bid Defender. it was the time I had with Bogden outside of the interview when we went out for
[09:40] We talked about these situations, and we're sitting across from each other and he's got tears in his eyes telling it's the other people at Bitdefender.
[09:55] It's the members of the Draco team being there. I got to feel it. It's real. These guys are superheroes, but are we winning? Are we stopping ransomware? I mean, we're not definitely not stopping it. We're definitely not derailing it,
[10:07] So no, we're putting a dent in it, but it's still a huge criminal enterprise. They're still raking in money and the Draco team proves something important. When the Draco team comes at them, takes 'em down, they change tactics.
[10:24] And ransomware is just one front in this war because now the criminals are using Cyber criminals can now easily integrate AI into everything they're doing, And it's not just that it's level the playing field,
[10:40] but because being a cyber criminal, it's not easy. You have to have skills, What AI brought to the table for the criminals was that it completely eliminated the gap between a junior developer and a senior developer.
[10:57] So we obviously have to do the same thing on this side. They can now use AI to generate better written phishing scams.
[11:11] So the phishing scams that are happening right now, you're getting the grammar's perfect and it's personal. They know things about you. You have to really sit there and go, huh,
[11:24] the director of innovation at Bitdefender, So the more confident they get, the more money they lose because the education and the
[11:39] he's lacking and people are becoming more confident, So that's really worrying for me. No. Matter how good you think you are, even if you're a tech expert, you can be,
[11:53] Can you transfer me just for Id not paying or anything? I don't know. I to call. I promise I'll pay that first thing tomorrow. Hey, it's me.
[12:08] And then we had this stuff. We had over 1 million of these ads detected by us at Bitdefender. hijacking live streams with AI celebrities, Elon Musk, Bitcoin scams, flooding,
[12:25] Most people cannot tell their fake and voice cloning. That's scary. especially for scams that are trying to mimic your family members or friends.
[12:37] Imagine that if your mom gets a call from someone that sounds just like you, Now think about how much of your voice is already out there like I'm cooked, And on top of that, you bring AI and you do all these celebrate scams.
[12:55] So here's the thing, we're kind of in an AI arms race right now. they don't work. Criminals adapt too fast. So how we fighting back ai,
[13:08] but Bitdefender built an entire AI defense team to fight fire with fire. Again, and he showed me some absolutely insane stuff. Just dropped like 150 milligram edible and I'm feeling
[13:27] suited. I'm about to design 30 new space cars and get us some Mars. you can either upload a file or send a link for the most popular platforms This is also specifically aim that manipulating people.
[13:44] it's high confidence because most of the audio is manipulated. So here we have details on which segments are manipulated, And also here you have the intent analysis.
[14:00] So basically what are the indicators and detailed analysis? So we know that the manipulated segments contains the repetition to emphasize the intoxicated impression and making sure people believe that's really Elon
[14:14] Musk getting high on some drugs and stuff like that. Yeah. it's getting pretty hard to tell. Like this one here from Elon Musk, they're able to now detect this.
[14:28] We can see if it's a totally synthetic audio, if it's a modified deepfake is not just understanding why you're but also the reason behind people showing you that deep fake.
[14:43] They're not just analyzing to see if it's fake or a deep fake. We're going to show you the intent of the. Let's say for a short period of time,
[14:58] you can say that you are 100% confident that you get every lip fake, but it doesn't last that much, right? So again, it's a constant arms race. Bitdefender improves detection.
[15:13] But detecting DeepFakes is only half the battle. They're also trying to catch these scammers in the act. This one was crazy. They have an AI scammer honeypot.
[15:25] They talk with an AI for 15 minutes and they still dunno. It's an ai. you know that scam calls are a thing and they suck and they're not going away. Now what are we doing about this fighting fire with fire? We're using ai,
[15:40] this AI scammer, honeypot answer scam calls and just waste their time. And this AI is playing the victim and it actually has personality. I'm.
[15:52] What kind of loan are we talking about? So I'm going to send you an email. I have sent it over. Can you see the email?
[16:08] Can you just tell me the account number and I'll take care of the transfer? 3 4, 5, 6 7 8 9 8 2 1.
[16:21] Is that a checking or savings account? What's the total amount I'd be getting? You mentioned $5,000 earlier, So basically it's going to.
[16:36] Drive the scammer crazy. No, I'm not kidding. As we're recording this, This sounds amazing. Even down to the southern accent, you would not be able to tell every minute a scammer spends talking to AI is a
[16:49] but defenders gathering intel data analytics. Basically we're going to collect the intent. So if this is a scam or not, why we think it's a scam, what are the red flags of the scam?
[17:04] We're going to catch that URL and we're going to open it separately and analyze it Also for additional information of scam or malicious criminal enterprises.
[17:19] You have scammers that do not know they're working for a scamming So I love this, but again, the criminals keep evolving. It keeps getting worse. There are attack scammers are running that are really hard to keep track of
[17:36] because yeah, we do have systems in place to kind of analyze and go, But they found a way and it's called multi-platform scams. The next. Big thing is actually multi-touch point attack detection because you now see
[17:51] scammers starting a scam on WhatsApp and continuing it on your So here's how it works. First, can you share your screen? They want to help you. The bank's caught on.
[18:06] So your banking app only shows blank when you're screen sharing. That's awesome. Open it in your browser. Instead.
[18:18] then just going to tell the victim to go in a browser and open the banking And this is hard to detect because there's nothing to detect. We cannot detect a conversation or a scammer
[18:34] email. but they are. That WhatsApp message seems normal. The phone call chill, But these three things happening in a sequence,
[18:50] So the next big thing is actually having all these events and correlating them to detect the scam without actually seeing the scam. The defenders got it. They're starting to learn the attack chain.
[19:07] They're constantly gathering intel on these situations and trying to develop job. sit down with them and talk with them.
[19:19] These are actual machine learning engineers, They're developing their own models to be able to detect these things, that, but also even they admit some things they can't detect.
[19:37] Are you guys ever tricked by ai? I'm also tricked personally and in general is that you are going home, you are watching something on social media and it just pops a rail
[19:53] or something and you don't really expect to see a deep fake Do you feel like we're winning the war with cyber crime right now? I would say maybe again, when I asked Alex about this, he said, yeah,
[20:08] They've saved over a billion dollars with the crypt. They're building AI defenses with honeypots, deepfake detection, voice analysis, and the Draco team is working with law enforcement worldwide. You're a poll,
[20:20] You're going to hear about millions of people being tricked with a Taylor Swift Rus told me about it, and by the way, I'll have it on my second channel if you want to go check it out and you should
[20:36] but it kind still feels like the criminals are winning, because every single victim that we save is real person, and I got to hear a few of their stories.
[20:51] He wrote that article about the Rebuild decryption tool. This guy is a wealth of knowledge and he told me some crazy iot stories about surveillance, cameras broadcasting families lives just live on a stream.
[21:05] but the things that stuck with me were the stories he told about the victims I have a lot of stories coming for from victims who were seeking out
[21:17] And what I love about this is they're not just statistics like they're people. Everything was ready. Years of work coming to a conclusion, I have this PhD student who was on the verge of defending his
[21:32] He kind of lost one month of work in the backup was one month old and whatever he
[21:45] An entire month of research just gone. Years of effort about to be meaningless. But then that. I got word from one of my colleagues that we have a decryptor and we were
[22:00] How cool is that? That night they were able to figure it out, get the decryptor, This very sad story of a couple in Syria.
[22:15] Syria was shaken down by worst and it was 2019. There's this couple who were mentioning on the internet that the computer there was no surprise in that and that their pictures had been taken
[22:31] They couldn't pay it. 350 bucks May as well have been $35,000. Not much by Western standards, but a lot But here's what made this different.
[22:44] What stood apart from the rest of the cases was They had pictures of took two of their kids who
[22:56] So that was the only proof of them being part of this life in the past. the children that had died in the war, But they were able to decrypt that information and that was personal for them.
[23:11] We managed to decrypt that information and we took You see, that's what I'm talking about. It's personal. Cyber crime is personal.
[23:23] As I was talking with Bogden and Raw and Alex and hearing their stories about hours fighting cyber crime. It's not just about stopping malware. their memories back.
[23:38] You have to do it perfectly every single day because your detections are the ones that make the
[23:50] difference between Honey, I'm home and honey, They're standing between normal people and complete digital devastation. A lot of the people I talk with there have been a bid defender for over 10
[24:06] Bogan told me this story during COVID, hospitals were getting attacked. and these hospitals had no cybersecurity budget and they were getting hammered
[24:18] And we reached out proactively to a couple of hospitals, provided security software for free and also expertise and SOC monitoring for their businesses to make
[24:34] sure that the lights stay on and that people get treated in a timely manner. It wasn't a bottom line issue at that point, and I love what Bogden said.
[24:46] I believe that cybersecurity should be a fundamental human right, just like the right to liberty and the right to critical thinking.
[24:58] but once you realize how much the digital life has impact people understand that you need to secure your digital life to enjoy
[25:12] You love that. I love that so much. Cybersecurity is a human right. and then I asked Bogged in the same question I asked Alex in the beginning,
[25:24] Well, we're still here, right? So here we are kind of at the end of the video, and I don't know about you, And you might be wondering, Hey, how can I join something like the Draco team?
[25:40] Yeah, well, first of all, you need to work for Big Defender. there are other companies out there which have similar teams, so it's not like we invented Pot water or anything.
[25:55] So each company has some sort of team that's working with law enforcement. They have their own cool names. Ours is Draco. you need to want to do this,
[26:11] So once you talk to one of the members, and then it's up to you what you want to do.
[26:23] there's plenty of malware that's involved into law enforcement investigations that you can look at. Cryptocurrency investigations. Sure, there's a lot of crypto you can look at. No problem. Botnets, forensics,
[26:39] it was awesome going out to Romania to visit bid defender and learn about what Me and my team are extremely grateful that we got to see everything we did I'll catch you guys next time.
⚡ Saved you 0h 26m reading this? Transcribe any YouTube video for free — no signup needed.