The Shoe's On the Other Foot
Cybersecurity wins often seem few and far between. No sooner is one campaign disrupted, another begins. And while the malware families themselves may be taken down, remediated, or otherwise rendered powerless, the threat actors behind them rarely make the same headlines.
I’ve been following the case of Aisuru-Kimwolf since November of last year, when it first came to my attention after an attempted DDoS attack on Microsoft Azure. At that time, the endpoint IP address was somewhere in Australia, but no other information was given. It was my first report on the massive botnet, however. I wrote another report in January covering proxies in general and how they relate directly to this botnet. And then another the following week, after Aisuru-Kimwolf had been successfully null-routed by Black Lotus Labs, with the help of those researchers and investigators who had been mapping the architecture of it.
The creator of Aisuru-Kimwolf had more of less been identified at that time, but discovering the offline identity of an online attacker is time-consuming. Especially one who specializes in proxies, thereby making any attempt to track down their true location something like a riddle. But Krebs On Security thinks he may have solved it. Published a few days ago, Krebs’ latest report breaks down who the mysterious ‘Dort’ is, complete with a timeline of activity and thorough examination of all his known aliases.
Generally speaking, I am not in favor of doxxing, which is the act of revealing private information with the intent to leave its victim subject to public harassment. In fact, I will not be including the personal details Krebs uncovered in this post; you can follow the link and read it for yourself if you’re interested. But there is a sense of righteous comeuppance, considering that Krebs himself, as well as the founder of Synthient, have both suffered the effects of the bullying tactic, including threats of violence and swatting (where law enforcement agencies are called to respond to what is a hoax report at someone’s home). What goes around, comes around.
What follows in Krebs’ report reads like the premise of a story where mischief suddenly goes too far. In one of my earlier reports on this whole thing, I mentioned that it reminded me of fandom discourse, complete with Discord servers where participants escalated simple insults into active harassment. From an outside, meta perspective, this entire sequence of events highlights something that many younger users of the IoT seem to have forgotten, or never learned in the first place: the internet is forever. Nothing online is ever truly deleted, there is always a copy of it somewhere. Everything Krebs published in his article was publicly available, or at least retrievable. It was just a matter of putting it all together.
Krebs narrowed down the identity of ‘Dort’ to one person, and even was able to contact him for comment. This person then claimed that everything that had happened in the last few years regarding Aisuru-Kimwolf was not him, but someone impersonating him. And while that could be true, certainly spoofing is a thing, to me it feels very much like a child trying to say they did nothing wrong, it was the other guy (who is invariably made up). And indeed, Dort seems to be someone who was a teenager when he began writing Minecraft cheats, which would put him in his early to mid 20’s now. Comments on the article run the gamut of being entertained by the public callout to sentiments of ‘don’t mess with the big boys, kiddo’.
It might be petty to vicariously celebrate this reverse UNO card of doxxing. And ordinarily I would not enjoy it. But in keeping with some of the themes I’ve been writing about lately with regards to accountability, this is rather fitting. However much the inception of Aisuru-Kimwolf might have been merely a proof-of-concept (early versions carried no malicious payload, after all), real world harm has been done. That means real world consequences are warranted.