惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
阮一峰的网络日志
阮一峰的网络日志
博客园 - 聂微东
F
Fortinet All Blogs
H
Help Net Security
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
D
DataBreaches.Net
MyScale Blog
MyScale Blog
B
Blog
I
InfoQ
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
GbyAI
GbyAI
Google DeepMind News
Google DeepMind News
IT之家
IT之家
The GitHub Blog
The GitHub Blog
有赞技术团队
有赞技术团队
博客园_首页
L
LangChain Blog
V
V2EX
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
T
The Blog of Author Tim Ferriss
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - Franky

The Register - Security

India's cyber agency sets clock at 12 hours to tackle exploited bugs as AI turns up the heat Are we human? MyPillow must decide whether to be firm or soft as ransomware crims demand pay Experts pour cold borscht on Farage's Russian hack claim AI eyes scanning for bugs create a worrisome Linux security trend A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Techie claims Trump Mobile website was leaking thousands of people's data Dems slam Trump for making cybersecurity hold out the tin cup while splurging on ballroom and Jan. 6 'slush fund' Attackers spill plaintext passwords of 46k Myspace93 users after 2021 breach Microsoft open-sources agentic AI safety tools Are we human? America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames America's top cyber-defense agency left a GitHub repo open with passwords, keys, tokens – and incredibly obvious filenames Shai-Hulud copycat worm infects yet another npm package MPs want social media treated more like unsafe toys than harmless apps Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data To gain root access, intruder just had to ask AWS patched Quick auth bypass, says customers weren't using control Disgruntled researcher releases two more Microsoft zero-days Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files US bank reports itself after slinging customer data at 'unauthorized AI app' Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator Best Western Hotels confirms web app data breach Arctic Wolf cuts 250 jobs in AI push 1 in 8 workers say selling company logins is justifiable Iran cyberspies LARPing as ransomware crims in espionage ops UK age-gating plans risk breaking the internet, privacy groups warn India orders infosec red alert in case Mythos sparks crime 'CopyFail' attackers start cashing in on Linux flaw
Don't glamorize cybercrims, roast them instead
Jessica Lyons Jessica Lyons · 2026-04-05 · via The Register - Security

Security

Researchers didn’t want to glamorize cybercrims. So they roasted them

True-crime tales of criminals making fools of themselves

INTERVIEW Cybercrime crews have become almost mystical entities, with security vendors assigning them names like Wizard Spider and Velvet Tempest.

They hide out in hidden corners of the dark web (often accompanied by a clearnet leak site), leading some infosec folks to talk about these miscreants as if they are invincible. But not everyone is on board with this trend.

Former CISA boss Jen Easterly and others have called on the industry to stop glamorizing these groups, and instead give them horrible names like "Scrawny Nuisance" or "Evil Ferret." 

During an interview with The Register at the RSA Conference, Trellix VP of threat intel John Fokker said he's sick of it, too. 

"I'm trying to spark a debate, or a healthy conversation, about what we can do as an industry," he said. "Everybody's glorifying threat actors, and that's not helping our customers or organizations. These are just individuals, they just use computers, and they just want to steal your data and make money. They're not mythical. They don't have superpowers."

These are just individuals, they just use computers, and they just want to steal your data and make money. They're not mythical. They don't have superpowers

So his team at threat detection and response firm Trellix decided to take an "almost psyops" approach to covering the criminal underground. "We don't want to glorify them, what's the opposite we can do? We're going to roast them."

And thus, the Dark Web Roast was born. It's a regular blog complete with memes, mockery, and a Ricky Gervais' "they're just jokes" inspired disclaimer: "While these incidents are genuinely amusing, they represent real criminal activities causing significant harm. This content is for threat intelligence and educational purposes only."

The most recent edition features a ransomware gang that bulk-drafted and scheduled their extortion attempts like a content calendar: "Considering the sheer, numbing volume of their posts, it's a solid bet that their 'victims' are probably just fake sites they spun up themselves for content, because nothing screams legitimacy like inflating your stats with phantom compromises," the researchers wrote.

There's also an exploit developer named cortana9000 who found a Cisco remote code execution bug (CVE-2026-20045) under active exploitation by government-backed goons and asked on a forum, "so how much is this worth" ... then listed it on another forum for $70,000. 

"A fellow forum member, KlopInko, swooped in with the devastating one-liner: 'since it's known, it's a 1day exploit' - essentially telling cortana9000 that his $70K payday had already started depreciating the moment he opened his mouth," according to the roast.

There's also a crim, using the handle patagon on DarkForums, who tried to sell full domain admin access to Russia's energy grid for less than a used car, undervaluing their apparent find by "many orders of magnitude."

When cops go trolling

Fokker points to the LockBit infrastructure seizure and dismantling led by the UK's National Crime Agency (NCA) as the beginning of a deliberate change in law enforcement's response toward cybercriminals. In that case, the cops trolled the notorious ransomware gang via its own website before ultimately unveiling LockBitSupp's true identity.

Taking down groups' infrastructure isn't enough, because they can simply spin up new servers and domains, which, we should point out, LockBit did. Then it becomes a game of whack-a-mole.

"Criminals say, 'OK, I can play this game all day long.' So that doesn't really work," Fokker said. But public mockery (as with LockBit), and infiltration like the FBI did with Hive's ransomware network, can fracture trust among cyberthieves. And this fragmentation can help defenders dismantle criminal operations and keep people and data safe.

"In the criminal underground, it's more network-based and individual-based," Fokker said. Ransomware crews work with initial access brokers or exploit developers to break into victims' networks, and they have developers who are writing malware, and affiliates carrying out the attacks. 

Fracturing trust among thieves

"This also creates dependencies," Fokker said. "You have groups that were in the partnership with the ransomware group, and they were breaking into or they were stealing data, and then you have exit scams, or the decryptor didn't work, and that causes cracks in the business model."

Trellix assisted international cops in the long-running Operation Endgame, and during the November 2025 Rhadamanthys infostealer takedown, officials released a smug animated video hinting at intelligence gathered during the operation and designed to undermine trust within criminal organizations.

The video shows an administrator skimming the most valuable secrets and cryptocurrency keys for personal gain, while passing only less lucrative data to customers. Trellix learned about this incident during a briefing with Dutch police.

"They said to us, 'We found out that this admin is also stealing from his own customers,'" Fokker remembers. After the Europol press release came out, Trellix unleashed the snark in a Dark Web Roast.

"We basically said you're stupid if you work with him, because he's just getting rich, and we just make fun of him," Fokker said. "We don't know if the impact was measurable, but still, we had an opportunity to run with that story and make a complete fool out of this admin. So that's something." ®