ᴛʜᴇ ɢʜᴏꜱᴛ ɪɴ ᴛʜᴇ ᴍᴀᴄʜɪɴᴇ
Ir al canal en Telegram
337
Suscriptores
+324 horas
+127 días
+1630 días
Archivo de publicaciones
Louis Michael Gaebler, 23, of Mandurah, Western Australia, was arrested in Perth in connection with the TeamPCP investigation. Reporting from Australian media said he was one of two West Australian men charged after a joint investigation involving the Australian Federal Police, Western Australia Police, and the FBI.
TeamPCP has been linked in reporting to major supply-chain attacks that allegedly spread malicious code through open-source software and affected a large number of organizations worldwide. In this case, the important point is not a single technical failure, but the accumulation of public traces that allowed investigators to connect online identities, platform activity, and real-world records.
For a cybersecurity audience, the lesson is straightforward. Attribution in cases like this usually comes from correlation rather than one dramatic breakthrough. Names, usernames, account histories, public profiles, and infrastructure references can all become part of the same investigative picture when they overlap consistently over time.
The case also highlights how operational security failures tend to be cumulative. A handle, avatar, social profile, or business record may seem insignificant in isolation, but repeated across services it can create a durable identity trail. That trail becomes more valuable when it is preserved for years and can later be matched against other account activity or public records.
Gaebler’s arrest in Perth therefore matters not only as a law-enforcement action, but as a reminder that long-term identity reuse can become an attribution risk. In modern cyber investigations, the strongest cases often do not come from one isolated clue. They come from multiple small clues that point to the same person.
#TGITM @TheGhostITM
Two people linked to TeamPCP were reportedly arrested in Australia today. TeamPCP is believed to be behind a string of major supply-chain attacks that sent shockwaves through the cybersecurity community.
- Cross-platform alias persistence: Handles and identity fragments were reportedly retained across HackerOne, GitHub, Hugging Face, TikTok, Steam, and Telegram.
- Infrastructure exposure: A domain reportedly associated with malicious command-and-control activity was publicly linked from developer-facing profiles.
- Weak identity separation: A possible real name, initials, aliases, and related account data were sufficiently connected to enable further OSINT pivots.
- Historical timeline overlap: Steam VAC-ban dates and account interactions reportedly aligned across multiple identities.
- Visual-identity reuse: The same distinctive cat avatar reportedly appeared on Steam and Telegram accounts associated with the wider TeamPCP ecosystem.
- Public-record exposure: A business reportedly operated under the name OPSEC EXPRESS created an additional real-world attribution surface. Corporate records are routinely useful when they can be correlated with online identifiers, financial activity, communications, or infrastructure evidence.
Analytical Takeaway
This case demonstrates that operational security fails cumulatively. An individual does not need to expose a home address, leave a real IP address in a server log, or publish a direct confession to become attributable. Small artifacts—an old Steam ban, a contact comment, a reused profile image, a domain on a public developer profile, or a social-media video—can persist for years and later become critical evidence.
The central mistake was treating individual accounts as isolated identities. They were not isolated. The reported evidence indicates that each platform preserved a fragment of the same operational history. Once one fragment was linked to a real-world identity, the remaining artifacts could be examined as part of a single pattern.
For cyber-intelligence teams, the lesson is equally practical: prioritize pivots that establish independent corroboration. A username is a lead, not a conclusion. Confidence grows when a handle is supported by shared infrastructure, time-based correlations, platform relationships, visual markers, and verifiable public records.
#TGITM @TheGhostITM
Case Study: How Reused Digital Identity Exposed an Alleged TeamPCP Member
By Yara Tabet (The Ghost In The Machine)
Executive Assessment
The reported arrest of Ruben Thomson in Western Australia illustrates a common failure in hacking OPSEC: identity reuse across platforms with radically different levels of visibility. The reported attribution was not built around a zero-day, a covert implant, or a single leaked identifier. It emerged from publicly accessible traces that, when correlated, connected a long-standing online persona to an alleged TeamPCP member.
The core failure was poor compartmentalization. Handles, infrastructure references, historical account activity, profile imagery, and social-media content allegedly overlapped for years. Any one artifact would have been weak evidence. Together, they created an attribution chain that was difficult to dismiss.
Scope and Attribution Caveat
This assessment is based on publicly reported material and open-source observations. It does not independently establish guilt or validate all claims of group membership. The reference to Thomson’s reported arrest and alleged connection to TeamPCP should be read as an attribution assessment pending the outcome of judicial proceedings.
Initial Identity Pivot
The investigation reportedly began with the handle DeadCatx3, which was associated with a HackerOne profile connected to the name Ruben Thomson. The account was significant because it created an initial bridge between a real-world identity and an established online alias.
Researchers then identified what appeared to be an associated Hugging Face account using initials consistent with the same name. That profile reportedly referenced masscan[.]cloud. The domain had been identified publicly as command-and-control infrastructure associated with the Mini Shai-Hulud npm worm activity. The same domain was also reportedly present on the DeadCatx3 GitHub profile.
This overlap mattered because it was not merely a reused username. It connected a named identity, developer-platform profiles, and infrastructure allegedly tied to a malware campaign. The evidentiary value came from convergence: distinct services independently pointing toward the same operational ecosystem.
Social-Media and Steam Correlation
Once Ruben Thomson became a working lead, investigators and researchers reportedly pivoted through account-linked data and open-source records. This led to a TikTok account using the name yolosolo17.
The account reportedly contained a single video, published in March 2017, showing a Steam profile named YolocrownZ. The footage showed that the account had received a VAC ban $$175$$ days earlier. This places the likely ban date at approximately September 13, 2016.
Further Steam research reportedly identified an account called Ellis that had also received a VAC ban on September 13, 2016. Public Steam-profile interactions and comments reportedly established a relationship between the Ellis and YolocrownZ identities.
This is a valuable example of timestamp-based correlation. A shared ban date does not identify a person on its own, but it becomes meaningful when aligned with connected accounts, relationships, alias reuse, and the wider attribution record.
The Avatar Link
The strongest and most memorable pivot was visual rather than technical. A distinctive cat avatar appeared on a Steam profile associated with the identity chain. The same image was reportedly reused by the PCPsh Telegram account linked publicly to TeamPCP.
Reverse-image searches reportedly produced few or no unrelated uses of the image. This gave the avatar limited but useful attribution value. Profile pictures are generally weak indicators because they can be copied, but their value rises when they appear consistently across accounts that also share timelines, contacts, aliases, and operational context.
The cat image did not prove identity. It corroborated an identity chain that was already supported by multiple independent sources.
OPSEC Failures Identified
Repost from Cyber Dispatch™️
Proton is currently experiencing a major outage affecting Proton's services due to a cooling failure in their Frankfurt datacenter.
Repost from Cyber Dispatch™️
The Uwais al-Qarani Hacker Group claims responsibility for a cyberattack on Israel's power grid, targeting critical infrastructure and sending a message of resistance.
#TGITM @TheGhostITM
THE FOREIGN HAND: ISRAEL’S ROLE IN U.S. SURVEILLANCE INFRASTRUCTURE
Unit 8200 and Its American Footprint
Unit 8200 is Israel’s elite signals-intelligence and cyber unit, often compared to the U.S. National Security Agency. Its role includes intercepting communications, conducting cyber operations, and gathering intelligence. Over decades, it has developed a reputation as one of the world’s most capable cyber-intelligence organizations.
For people across the Arab world, especially Palestinians and Lebanese, this is not an abstract subject. Israel’s surveillance capabilities have been used in the region for military occupation, targeting, intelligence collection, and monitoring civilians. That history should matter when technologies and companies shaped by this ecosystem enter public institutions abroad.
Unit 8200 is also known as a powerful pipeline into the technology industry. Many former members have gone on to found or work for prominent cybersecurity, software, and data companies. Israel’s technology sector has benefited heavily from skills, networks, and experience developed through military intelligence service.
Some of those companies have expanded into the United States, where they may work with corporations, police departments, public agencies, and security institutions. Their products can involve sensitive information: license-plate records, location data, video feeds, emergency communications, biometric data, and other forms of digital surveillance.
That raises legitimate questions—not about the ethnicity or nationality of individual engineers, but about accountability. Who owns the data? Where is it stored? Who can access it? What safeguards prevent misuse? And what public oversight exists when surveillance tools move between military, private-sector, and government environments?
The case of NSO Group offers an important warning. Founded by former members of Israel’s military-intelligence ecosystem, NSO developed Pegasus spyware, a tool that has been linked to the targeting of journalists, activists, political opponents, and human-rights defenders in numerous countries. The company said its technology was intended to fight crime and terrorism, yet repeated investigations showed how easily powerful surveillance technology can be abused when oversight fails.
The issue is larger than any one company. It is the wider military-to-tech pipeline: intelligence experience becomes commercial technology, commercial technology enters foreign markets, and public institutions adopt it in the name of safety. Once these systems are embedded, they can quietly expand beyond their original purpose.
In the United States, automated license-plate readers, facial-recognition systems, border-surveillance platforms, and large-scale data-sharing networks have become increasingly common. These tools affect ordinary people every day, often with limited public debate and weak safeguards against misuse.
From a Lebanese perspective, there is every reason to view this trend critically. Lebanon and the wider region have lived with the consequences of Israeli military power, intelligence operations, aerial surveillance, and cyber capabilities. When systems shaped by that security model are exported abroad, the public deserves to ask whether they bring the same assumptions: that mass monitoring is normal, that privacy is expendable, and that security institutions should operate without meaningful scrutiny.
This is not an argument against cooperation between countries or against technology itself. It is an argument for transparency, democratic oversight, data sovereignty, and human rights. No foreign government, military-linked network, or private contractor should gain privileged access to the personal data of another population without clear safeguards and public accountability.
@TheGhostITM
Repost from Cyber Dispatch™️
نشر وثائق عن تعاون شركة Novamill مع الصناعات العسكرية التابعة للاحتلال الإسرائيلي
نشرت جبهة الإسناد السيبراني أجزاءً من وثائق داخلية لشركة Novamill Systems، بتبيّن تفاصيل تعاون الشركة في مجال القطع الصناعية والتكنولوجيا مع الصناعات العسكرية والفضائية التابعة للاحتلال الإسرائيلي.
بتشمل الوثائق عقودًا، واتفاقيات تعاون، وتقارير فنية مرتبطة بشركات، منها Elbit Systems وRafael والصناعات الجوية الإسرائيلية (IAI).
ومن بين الوثائق المنشورة مخططات هندسية، ومعلومات عن القطع، وتفاصيل عن أوجه التعاون التقني كمان.
Documents Released on Novamill’s Cooperation with Israeli Military Industries
The Cyber Isnaad Front has released portions of internal documents from Novamill Systems. The documents reportedly show details of the company’s cooperation in industrial components and technology with Israeli military and aerospace industries.
The documents include contracts, cooperation agreements, and technical reports related to companies including Elbit Systems, Rafael, and Israel Aerospace Industries (IAI).
The released materials also include engineering designs, information on components, and details of technical cooperation.
#TGITM @TheGhostITM
Repost from Cyber Dispatch™️
نشر وثائق عن تعاون شركة Novamill مع الصناعات العسكرية التابعة للاحتلال الإسرائيلي
نشرت جبهة الدعم السيبراني أجزاءً من وثائق داخلية لشركة Novamill Systems، بتبيّن تفاصيل تعاون الشركة في مجال القطع الصناعية والتكنولوجيا مع الصناعات العسكرية والفضائية التابعة للاحتلال الإسرائيلي.
بتشمل الوثائق عقودًا، واتفاقيات تعاون، وتقارير فنية مرتبطة بشركات، منها Elbit Systems وRafael والصناعات الجوية الإسرائيلية (IAI).
ومن بين الوثائق المنشورة مخططات هندسية، ومعلومات عن القطع، وتفاصيل عن أوجه التعاون التقني كمان.
(Documents Released on Novamill’s Cooperation with Israeli Military Industries
The Cyber Support Front has released portions of internal documents from Novamill Systems. The documents reportedly show details of the company’s cooperation in industrial components and technology with Israeli military and aerospace industries.
The documents include contracts, cooperation agreements, and technical reports related to companies including Elbit Systems, Rafael, and Israel Aerospace Industries (IAI).
The released materials also include engineering designs, information on components, and details of technical cooperation.)
#TGITM @TheGhostITM
Repost from Cyber Dispatch™️
Cyberattack on Boston Scientific, a Medical Device Company
Boston Scientific, a medical device company, has been targeted by a cyberattack that has disrupted its network and some operational systems globally.
#TGITM
Repost from Cyber Dispatch™️
A large-scale DDoS attack has targeted the shared infrastructure of Norway's digital government services since Monday, causing disruptions to some public services.
From the refugee camps of Jordan rise voices no border can silence. Amani al-Jundi carries not only the dreams of her people, but the unbroken belief that Palestine will one day be free.
Repost from 𓂆 Palestine
Governments Are Blind, and We Are the Eyes
By Amani al-Jundi
In every age, there comes a moment when ordinary people must become the voice of the unheard. For the vulnerable, the oppressed, and those who have been pushed aside, activism is not a hobby or a slogan. It is a duty. When the world turns away, someone must stand and say what is happening, name the injustice, and refuse to let silence protect wrongdoing.
Activism matters because power does not always correct itself. Many governments, institutions, and leaders respond only when pressure grows too loud to ignore. That is why activists are often the eyes of society. They see what others prefer not to see. They document suffering, expose corruption, challenge abuse, and remind the world that human beings are being hurt behind closed doors, in forgotten communities, and in places where the powerful expect no one to look.
Yes, activism is hard. Often it feels like losing battle after battle. Change can be slow, exhausting, and painful. People get discouraged. Movements are mocked. Voices are ignored. Sometimes the truth is buried under politics, fear, or indifference. But losing battles does not mean losing the war. History is full of people who were dismissed in their time but were later recognized as the force that changed everything. Progress rarely arrives all at once. It is built through endurance, courage, and refusal to surrender.
What keeps activists going is belief. Deep inside, they believe justice is stronger than fear, and truth is stronger than propaganda. They believe that if they do not give up, victory is still possible. A movement may stumble, but as long as it continues, it remains alive. Every protest, every article, every testimony, every act of solidarity is a step forward. Even when the result is not immediate, the struggle shapes the future.
Activism also matters because it reminds society of its moral responsibility. It says that suffering should not be normalized. It says that power must be accountable. It says that human dignity is not negotiable. This is why activists speak even when their voices shake. They are not speaking out of hatred. They are speaking out of love for justice, for peace, and for a world where people are treated as human beings, not as numbers.
So do not ignore the call. If you see injustice, do not look away. If you know the truth, do not stay silent. Stand with the vulnerable. Speak for the voiceless. Be part of the generation that refuses to accept cruelty as normal. We may lose many battles, but if we keep going, we can still win the war for justice, dignity, and freedom.
Join the movement. Become an activist today.
Repost from 𓂆 Palestine
By Amani al-Jundi
The fight over Warner Bros. Discovery has become a much larger story about media power, political influence, and the concentration of corporate control in the hands of one family. At the center of the takeover battle is David Ellison’s Paramount Skydance, backed by Oracle co-founder Larry Ellison, whose wealth and influence have made the bid one of the most closely watched media deals in years.
Larry Ellison gave about $45 million to a Trump-supporting political nonprofit in 2024, money that helped bolster Trump’s election effort without going directly through the campaign. Ellison has also backed Friends of the IDF with large donations, including about $26 million.
What gives this story added political weight is Oracle’s long-running relationship with Israel. Critics say the company’s software and infrastructure services have been used by Israeli state institutions at a time when Palestinians are facing mass displacement, bombardment, and a catastrophic humanitarian crisis in Gaza. Oracle executive Safra Catz has also drawn attention for describing the company’s work as providing Israel with powerful technology, language that critics say shows how deeply corporate systems are tied to state violence.
That is why the public comments of actor Mark Ruffalo have mattered so much. Ruffalo has argued that criticism of Oracle’s role is not antisemitic, but a legitimate response to the way advanced technology can support oppression. He has warned that the Ellison family’s growing control over media and technology raises serious concerns about who gets to shape public narratives, especially when those narratives involve Palestine and Gaza.
The Warner Bros. takeover fight is not taking place in a vacuum. It is happening in a media landscape already dominated by billionaire ownership, where decisions about news, entertainment, and political coverage can be influenced by the interests of a very small number of powerful families. If one family can help steer both a major technology company and a major entertainment empire, the question is not only whether the deal is legal. It is whether such concentration of power is healthy for democracy.
For Palestinians, these concerns are not abstract. They are tied to everyday realities of occupation, displacement, surveillance, and war. Technology companies that support Israeli institutions are not neutral actors in that context. They are part of the systems that can deepen inequality and make oppression more efficient. That is why critics see the Ellison-Oracle network not just as a business story, but as part of a broader political structure that helps sustain Palestinian suffering while controlling the media conversation around it.
Ruffalo’s intervention brought those issues into mainstream attention. By linking media consolidation, Oracle’s Israel ties, and the devastation in Gaza, he highlighted a pattern many activists have been pointing to for years: power in the boardroom often connects directly to power on the ground. The Warner Bros. deal has therefore become more than a corporate acquisition. It is a test of whether the public can still scrutinize the interests behind the institutions that shape culture, politics, and public opinion.
Who I Am—and Why I Write
I was raised in the shadow of a classroom, inspired by a man who believed that knowledge could change lives: my father, a Palestinian professor of computer science from Lebanon who was appointed in 1980s.
He taught programming, algorithms, operating systems, and the theory of computation. His office contained a terminal connected to the university’s mainframe—a small window into a rapidly changing world. I grew up witnessing his dedication, curiosity, and discipline, and his legacy shaped my own path.
I studied computer science and cyber forensics. Today, at a young age, I am a professor of cybersecurity with experience in offensive security, threat intelligence, and AI policy. Technology is my profession, but truth is my responsibility.
Why Journalism Belongs Here
Some people may wonder why a cyber-resistance channel publishes investigative journalism and political articles.
The answer is simple: journalism is part of who I am.
I studied journalism because I believe information is a form of protection. Investigative writing exposes what powerful people try to hide, gives communities a voice, and preserves evidence when facts are threatened by silence, fear, or propaganda.
Cyber resistance challenges oppression. Journalism protects the truth.
Activism Is Part of Our Resistance
I am an activist, and journalism is one of the ways I express my activism.
For me, resistance is not limited to one form. It can take the form of research, documentation, education, digital security, storytelling, or standing beside people whose voices are being ignored. Every verified fact matters. Every honest article matters. Every person who refuses to look away matters.
This channel may be associated with cyber operations and the broader field of cybersecurity, but its purpose is broader: to understand threats, challenge injustice, protect people, and defend the truth.
About Our Team
The main administrator is currently unavailable for security and personal-safety reasons. Her private life has been deeply affected by the recent Israeli-Lebanese conflict, and we ask viewers to respect her privacy.
Until she can safely return, this space will continue sharing knowledge, analysis, investigations, and perspectives that matter.
We will not allow fear to erase our voice.
Our Message
I am not only a cybersecurity professional. I am also a daughter, a researcher, a journalist, and an activist.
My father taught me how computers work. Journalism taught me how power works. Digital security taught me how vulnerable people and systems can be; activism taught me to use that knowledge to defend truth, justice, and those most at risk.
So, if you wonder why this channel speaks about politics—not only hacking and digital security—here is the answer: journalism is part of who we are, and activism is part of our resistance. Security is not limited to networks and devices; it is also about protecting people, defending the truth, pursuing justice, preserving memory, and ensuring that every voice has the right to be heard.
Journalism is part of us.
Activism is part of our resistance.
Truth is the connection between them. — Yara Tabet (The Ghost In The Machine)
With Palestinian roots, Lebanese pride, and the love of Jesus: Long live the Palestinian and Lebanese resistance.
Repost from Cyber Dispatch™️
Yemeni Cyberattack on the Zionist Regime's Power Grid
The hacking group "Uways al-Qarani" (أويس القرني) claimed in a statement that it carried out a cyber operation against the Zionist regime's electricity infrastructure.
The group stated that in this operation, the power grid's industrial control systems were targeted, and a large solar power plant near Tel Aviv, comprising more than 5,000 solar panels, was taken offline.
Hebrew-language media covered the news with concern, and in referencing this attack, warned about the vulnerability of the Zionist regime's critical infrastructure to cyberattacks.
This attack shows that Yemen has extended its confrontation with the Zionist regime into cyberspace, targeting the regime's critical infrastructure.
#CyberAttack #Yemen #ZionistRegime #Hacking #CyberWarfare #TGITM
@TheGhostITM
Repost from 𓂆 Palestine
An Immigrant Family Became a President Twice
By Yara Tabet
The story of Donald Trump’s family begins with a German immigrant who arrived in the United States as a teenager and eventually helped establish a family fortune that influenced American politics for generations.
Donald Trump’s grandfather, Friedrich Trump, was born in Kallstadt, Bavaria, in 1869. At the age of 16, he emigrated to the United States, arriving in New York in 1885. Like many immigrants of his era, he came seeking opportunity in a rapidly expanding country. He later became a U.S. citizen and began building a life through business.
During the Klondike Gold Rush, Friedrich Trump traveled north to Canada, where thousands of miners and prospectors were searching for gold. Instead of mining himself, he made money by providing services to the people who came to mine. In Bennett, British Columbia, he and a business partner operated the Arctic Restaurant and Hotel. The establishment offered food, alcohol, lodging, and entertainment to miners who had arrived in the remote gold-rush settlement.
Historical accounts and newspaper advertisements suggest that the hotel also accommodated prostitution. Advertisements referred to “private boxes for ladies and parties,” while the hotel reportedly provided rooms where miners could spend their gold dust. The evidence does not prove every detail of the business, but historians generally agree that establishments of this kind served as centers for drinking, gambling, lodging, and sexual services. Friedrich Trump’s success came from “mining the miners”: earning money from the needs of prospectors rather than extracting gold from the ground.
After making money in Canada, Friedrich returned to Germany with his wife, hoping to settle again in his homeland. However, Bavarian authorities rejected his return. He had left without properly completing military-service requirements and had not followed the required procedures for departing the country. Officials ordered him to leave, so he returned to the United States in 1905.
Back in New York, Friedrich Trump continued working and invested in property. He died in 1918, but the money and connections he left behind helped his son, Fred Trump, enter and expand the real-estate business. Fred Trump became a major New York developer, building apartments in Brooklyn and Queens and accumulating substantial wealth.
Donald Trump inherited not only money but also access to an established family company, real-estate holdings, and influential connections. He later expanded his public image through hotels, casinos, branding, television, and political campaigning. His rise shows how an immigrant family’s economic foundation can develop across multiple generations.
In 2016, Donald Trump became the 45th president of the United States. After losing the 2020 election, he returned to the White House following the 2024 election and became president again in 2025. Thus, a family that began with a teenage immigrant, a Canadian gold-rush hotel, and links to prostitution eventually reached the highest political office in the United States—twice.
“During the Canadian Gold Rush, Friedrich Trump’s hotel provided miners with food, alcohol, lodging—and prostitutes in exchange for gold dust.”
“A man who claims to hate Canada owes part of his family’s fortune to Canadians and the gold-rush miners who helped make his grandfather rich.”
“While waging war on immigrants, he married an immigrant and rose from an immigrant family—a contradiction woven into his own story.”
Fact-checking note: This article is based on information reviewed across multiple sources, including historical records, reputable reporting, and insights from my friend at Columbia University. It is intended to present the story accurately and inform readers respectfully, without offending or targeting anyone. - Yara Tabet
What is AI, and what are AI chips?
Artificial intelligence refers to systems that perform tasks requiring human-like intelligence: understanding language, recognizing patterns, making decisions. Modern AI relies on neural networks trained on vast datasets using AI chips—specialized processors (like GPUs, TPUs, or custom ASICs) designed for parallel computation. These chips, built by companies like Nvidia, Google, and Huawei, enable the training and deployment of large language models (LLMs) that power everything from ChatGPT to autonomous cyber agents.
Old-School Hackers vs. AI-Era Hackers
The difference between old-school and modern hackers is profound:
- Old-school hackers were artisans. They wrote every line of code, understood every syscall, and prized deep expertise. Their talent lay in creativity, persistence, and technical mastery.
- Today’s hackers are increasingly orchestrators. They use AI to automate reconnaissance, generate exploits, and evade detection. A novice can now prompt an LLM to produce working malware or scan a network for vulnerabilities—tasks that once required months of study.
This isn’t laziness; it’s leverage. AI amplifies impact. One operator can now launch campaigns that previously required entire teams.
Hacktivism Then and Now: From IRC Botnets to AI-Driven DDoS
In the 2000s and 2010s, hacktivist DDoS attacks relied on volunteer botnets, IRC-based C2, and tools like LOIC. Participants manually joined “operations,” flooding targets with traffic. Impact was limited by coordination and bandwidth.
Today, AI transforms DDoS in three ways:
1. Automation: AI agents can identify high-value targets, spin up cloud instances, and launch attacks without human intervention.
2. Adaptation: Machine learning models adjust attack patterns in real time to bypass mitigation systems, mimicking legitimate traffic or rotating IPs dynamically.
3. Scale: AI-powered botnets can recruit compromised IoT devices or cloud resources autonomously, creating larger, more resilient attack networks.
Hacktivists now use AI not just for DDoS, but for deepfake propaganda, automated disinformation campaigns, and targeted spear-phishing against officials. The goal remains political—but the methods are faster, smarter, and harder to trace.
Why Hackers Are Turning to AI
Hackers adopt AI for the same reasons militaries and corporations do: efficiency, scale, and advantage.
- Speed: AI reduces the time from vulnerability disclosure to exploit from weeks to hours.
- Accessibility: LLMs democratize hacking, enabling less-skilled actors to perform advanced attacks.
- Evasion: AI-generated code can polymorphically change its signature, evading traditional antivirus and endpoint detection.
- Autonomy: Emerging AI agents can operate with minimal human oversight, probing networks, escalating privileges, and exfiltrating data.
This shift doesn’t eliminate the need for skill—but it changes its nature. The most dangerous hackers today are those who can effectively direct AI systems, combining strategic thinking with prompt engineering and adversarial machine learning.
The Road Ahead
AI is not replacing hackers; it is augmenting them. Just as the internet scaled hacking in the 1990s, AI is scaling it again—this time with intelligence baked in. Defenders must respond not only with better tools, but with new paradigms: continuous validation, AI-augmented threat hunting, and international norms around autonomous cyber operations.
The spirit of hacking—curiosity, rebellion, mastery—endures. But the interface has changed. From phone phreaks to AI agents, the evolution continues. And in this new era, understanding AI is no longer optional for cybersecurity professionals; it is essential.
The author is a Lebanese professor of cybersecurity with experience in offensive security, threat intelligence, and AI policy. Views expressed are personal.
@TheGhostITM
From Phone Phreaks to AI Agents: How Hacking Evolved—and Why Hackers Are Turning to AI
By Yara Tabet (The Ghost In The Machine)
Hacking has never been static. It evolves with technology, culture, and power. Today, we are witnessing perhaps the fastest transformation yet: hackers are increasingly turning to artificial intelligence (AI) not just as a tool, but as a collaborator. To understand why, we must trace how hacking has changed from the 1980s to the 2020s—and what AI means for the future of cyber conflict, crime, and activism.
The 1980s–1990s: Curiosity, Counterculture, and Code
In the 1980s, hacking was largely driven by curiosity and countercultural ethos. Early hackers—often teenagers with dial-up modems—explored telephone networks (“phone phreaking”) and nascent computer systems like ARPANET. They wrote their own scripts in BASIC or assembly, reverse-engineered software, and shared knowledge through underground zines and bulletin board systems (BBS). Talent was measured by deep technical understanding: knowing how memory worked, how to exploit buffer overflows, or how to write a packet sniffer from scratch.
This era also produced figures who would later redefine information warfare. Julian Assange, then known by the handle “Mendax,” was a founding member of the International Subversives, a small Australian hacking group that penetrated telecommunications systems and, allegedly, military networks like MILNET. Assange’s trajectory—from teenage hacker to cypherpunk to founder of WikiLeaks—epitomizes how hacking culture seeded modern transparency activism.
The 1990s saw hacking mature alongside the public internet. Groups like Legion of Doom and Cult of the Dead Cow became legendary. Hacktivism emerged, with collectives using defacements and early distributed denial-of-service (DDoS) attacks to make political statements. Tools were still largely handcrafted: Perl scripts for scanning, custom C code for exploits, and manually coordinated botnets for DDoS. Skill barriers were high; you needed to understand networking, operating systems, and programming intimately.
The 2000s–2010s: Criminalization, Commodification, and Scale
The 2000s brought monetization. Cybercrime became industrialized with ransomware, banking trojans, and exploit kits sold on underground forums. Script kiddies could launch attacks using point-and-click tools, lowering the barrier to entry. Meanwhile, nation-states entered the arena: Stuxnet (2010) demonstrated how hacking could achieve geopolitical objectives.
This period also saw the rise of sophisticated botnet architectures. Early botnets relied on Internet Relay Chat (IRC) servers as command-and-control (C2) channels: compromised machines—“zombies”—would connect to an IRC channel and await commands from the botmaster. The 1999 Trin00 botnet, used in the first major DDoS attacks against Yahoo and other sites, exemplified this model. Later, web-based C2 and peer-to-peer (P2P) botnets like Storm Worm made takedowns harder by decentralizing control.
Hacktivism scaled with tools like LOIC (Low Orbit Ion Cannon), but also with more advanced techniques. LulzSec, a splinter group from Anonymous active in 2011, combined traditional DDoS with Remote File Include (RFI) attacks to hijack web servers and turn them into DDoS bots. Their operations against the CIA, Sony, and PBS demonstrated how hacktivists could blend social engineering, SQL injection, and botnet-like tactics without relying on traditional zombie networks. Anonymous, meanwhile, leveraged volunteer-driven “ops” where participants manually launched DDoS attacks in coordinated waves.
The 2020s: AI Enters the Chat
Today, AI is reshaping every layer of hacking. Generative AI models—powered by specialized AI chips in massive data centers—can write code, analyze vulnerabilities, craft phishing lures, and even adapt malware in real time. Unlike earlier tools, AI doesn’t just execute commands; it reasons, learns, and iterates.
Repost from Cyber Dispatch™️
Home Wi‑Fi Routers Now Track Motion
By The Ghost In The Machine
Comcast’s new WiFi Motion feature is drawing attention for what it reveals about the modern home: even without cameras, a network can still detect whether people are present, moving, or asleep. By analyzing subtle changes in Wi‑Fi signals, the system can infer occupancy patterns and activity inside a household. Comcast says the feature does not record images or directly identify individuals, but the privacy implications are hard to ignore.
The technology may be marketed as convenient, but it also exposes a deeper concern about surveillance built into ordinary consumer devices. A system that can tell when someone is home can also create a detailed picture of daily routines. That information is sensitive on its own, and it becomes even more concerning if the modem or connected account is compromised.
Security researchers have long shown that wireless signals can reveal more than many users expect. The same data used to detect presence can, in the wrong hands, become a tool for monitoring household behavior. If a criminal were able to access the system, occupancy details could potentially help identify when a home is empty or when residents are least active. That makes protection of the device and account essential.
The issue is not limited to Comcast. It reflects a wider trend in smart-home technology, where convenience often advances faster than public understanding of the risks. Consumers are increasingly asked to trust that opaque systems will collect only what is necessary and store it responsibly. But when those systems can infer intimate details about everyday life, trust alone is not enough.
Any company offering this kind of feature should provide clear disclosure, strong default security, and an easy opt-out. Homeowners deserve to know not just what data is captured, but what can be inferred from it. In the age of connected living, privacy is no longer only about cameras and microphones. Sometimes, the most revealing device in the home is the router.
#TGITM
