← All talks

Exploring The Dark Web: Forums, Markets, And Scam Insights

BSides London · 202512:34592 viewsPublished 2024-02Watch on YouTube ↗
Speakers
Tags
CategoryResearch
StyleTalk
About this talk
Stefan Bargan surveys the landscape of dark web communities, focusing on forums like Dread and Sinisterly, illicit marketplaces, and common scam tactics such as fake hacking and assassination services. The talk examines Tor usage statistics across countries, highlighting both criminal activity and legitimate privacy uses in censored regions.
Show transcript [en]

so let's get started with an agenda for today first of all we'll be talking about um an introduction for myself then we'll move on to a dark web and tour introduction and then will delve into dark forums markets and scams followed by a conclusion alongside with some Tor data okay so a bit about myself I've been with search light cyber for almost a year now working on a lot of fun projects and I learn a lot about the dark web before that I used to work as a first line it support analyst for University of Portsmouth I'm currently also doing my masters in cyber crime terrorism and security with a focus on dark we actors

feel free to follow me on X and medium where I post my blogs so let's get started with a dark web introduction so dark web is the concealed part of the internet with both legal and illegal cont content happens tour also known as The Onion router is an anonymous tool for directing internet traffic operated by volunteer servers uh tour is not the only way to access the dark web there's also it and freet as you can be seen on the slide the difference between to and i2p is that to uses onion routing while ITP uses garlic routing but for this St will mainly stick with tool as it's one of the easiest way to get on the dark web

you just download the browser and you can get [Music] started so I want to start this part by showing you a couple of forums we have thread CSS and sinisterly alongside with their creation dates and what type of activities occur on the the amount of users and the number of post in the last 12 months first up we got thread which is one of the most popular dark web forums so far for 2023 it had almost 300,000 posts uh Dre is one of the more interesting dark web forums as there is a lot of different chatter similar to Reddit where they have subread communities talking about a lot of things for example markets exit scamming a lot of

questions about drugs and hacking and operational security also back in July um ASAP Market took over dread when they announced that we close operations which is not something that often occurs on the dark web usually markets just exit scam moving on to sinisterly so I can't say exactly when sin was first founded as there's a post that dates back to 20 8 so that makes it about 15 years old which is one of the oldest forums is that if that's the case uh during the pandemic sinisterly experienced a surge in users having almost 41,000 users online at the time but sin is not as popular as dread as it only hit 1 million posts in

2022 uh sin is also known that picture is very pixelated for having leaked databases as it can be seen I'm not sure there's a leaked database with over 159,000

records okay moving on to markets we'll be talking about Bohemia with the n and Biden cast similar how it was with forums so then again we have the creation date the type of activities that occur on there and the number of posts that have been present the last 12 months but unlike forums markets do not TR their track their users they more they focus on vendors and the reviews of the products so I want to start this one by showcasing Roker's Market which is a vendor type Market started in sometime in 2022 but gaining more popularity in 2023 so I want to add this just to see showcase how a vendor Market is compared to a full on Market which will be seen

in the next slide they only focus on themselves and have created this website just to gain more popularity they do operate on other marketplaces as well now talking about with the not this Marketplace is a Canadian focused one launched in 2021 before this used to be called Canada HQ so they have a heavy focus on drugs and fraud but that's not the only thing that they sell they do also sell premium software like the duby suit or copy of the windows they sell Premium Accounts usually for half the price they also sell marware rats and red kits and one of my funnier finds which I found on WE the N is that you could buy an ounce of

silver for some

ex okay moving on to scaming sides it'll be the picture on the left to start with where we have hackers for fire they promise they can hack almost anything from credit score cleaning to emails to social media all for a fee for anyone that has done any ctfs or will be doing the CTF on B sides they know that hacking is not as easy as it seems moving on to Hitman for higher so not sure how visible that is I wanted to highlight the picture on the right side with the red box as it shows the Hitman information privacy and protection Act of 1964 so this is a fake Act make everyone aware um the notion of this fate act

dates back to around 2005 when Bob a first created a similar bgus website to assist law enforcement with this theory for I want to share for anyone else interested in Hitman for high I would highly recommend looking into the basa Mafia and what was learned from

that

so let's start with some stats for to and 2023 so the table on the left side showcases the daily main average of users in top 12 countries and how they use St either by relay or by bridge and the graphs on the right side showcase the estimated number of users connecting again with ra or direct directly connecting to toour for 2023 more details about the source are available on the corner and now with the recent introduction of the UK Online safety act in the UK there's expected to be high numbers of users using to uh for the UK so say enough talk about the bad side of the dark web I want to share shine

some light of the on the good side of the dark web and why it's used for as well the majority of tour users in China Iran and turkistan will often just want to use the tour browser to avoid um tracking by governments or internet service providers looking at the metrics for tour in 2020 I ran Tristan were not on the top 12 list for the statistics so these countries just want to access the internet without any fears or or privacy concerns uh and on the slide it can be seen that there are some articles on how to help the citizens of these countries circumvent the

censorship so looking back at everything showcased earlier I've discussed that there's a lot of activity on the dark but it's not all just bad there are good reasons to use tour as well looking at dread almost reaching 300,000 posts with not Market expanding Beyond typical drug Trad selling a sort of different things and looking at the most common scams of the dark web which should be hackers for higher or Hitman for higher then discussing the statistics for tour so out of the table showcase the the top three countries combined make almost 2 million

users so that is all for me if anyone has any questions or they would like to ask now I'm available on Twitter or you could ask me in person after this talk as it be [Applause] here any questions great talk thank you very much my first talk well well done um I saw on the stats it looked like Germany had a really really high number of um I can't remember if it was Bridge or relay but I don't know the difference between the two so is there any reason why Germany had such a high number of relay users more than the us more than it so Germany the citiz of Germany are heavily focused on privacy they don't

want the governments to spy on a really good example that would showcase this if you go on Google Maps for Germany and you just look around on streets some buildings will be blurred that's because they don't want the buildings to appear Ms and that is why a lot of people use to in [Music] Germany thank you I'm a total new P so apologize if my question answer a b who who owns store who owns store uh so it was show Cas toour was first developed [Music] by by the US Naval research laboratory in 2002 but it then became published so open sourced it can be used it's not owned by anyone and it can be run by volunteers Serv yeah

okay any other questions sorry one last Quick One got a big go so um stepan you mentioned earlier about Sinister yes why do you think that was why do I think that was so Sinister had over 41,000 users at the time and I would say people just wanting to experiment they it got a lot more publishing material especially because of the leaked databases it made the news that's it about Sly we have time for one more if anyone else has one cool well once again thank you [Applause] uh