DEF CON 33 - So Long, and Thanks for All the Phish - Harrison Sand, Erlend Leiknes

DEF CON 33 - So Long, and Thanks for All the Phish - Harrison Sand, Erlend Leiknes

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 36:12

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Security researchers investigated SMS phishing scams targeting postal services and traced them to a sophisticated phishing operation called "Darcula" 0:30-0:52.

Key Takeaways:
• The phishing platform used real-time data transmission via socket.io, allowing scammers to see victim information as it was typed 6:23-6:31
• Researchers traced the software to a developer through a Telegram group with nearly 500 members sharing their criminal activities 9:16-9:25
• They located the licensing server and extracted data showing over 5,000 licenses issued in just 4 months 18:52-19:00
• The investigation identified the main developer as Yuang Chong from China's Han province 25:37-25:40
• After media exposure, the original operation shut down, but similar groups continue to steal approximately 650,000 credit cards monthly 35:42-35:55

The research demonstrates how phishing operations have evolved into sophisticated platforms with real criminal enterprises behind them 35:48-35:55.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

So this is now 3:30 uh talk with Harrison Erland and the talk is called so long and thanks for all the fish. All right, give these guys a first talk so give them a good warm uh round of applause. They're from Deutselan. Yes. >> Hello. Is the sound okay? >> Good. Thank you everyone for coming to our presentation called so long and thanks for all the fish. This presentation is about the story. It's a storytelling presentation where we will guide you through all the steps that we had to go through from receiving a text message to identifying uh scammering and the people behind the software. So, my name is Does the clicker work? No. No. My name is Aron. I work in a security company called Nemonic in Norway. Uh, where I do pent testing. >> Yes. And my name is Harrison and I do the exact same th…