Normal view

There are new articles available, click to refresh the page.
Yesterday — 25 June 2024Main stream

Cruise, G.M.’s Self-Driving Subsidiary, Names Marc Whitten as C.E.O.

By: Eli Tan
25 June 2024 at 18:14
After a year of safety problems, layoffs and mass executive departures, G.M. is trying to find stability for its futuristic driverless car business.

© Cydni Elledge for The New York Times

Cruise pulled its driverless cars off roads last year.

Cruise, the Self-Driving Car Subsidiary of G.M., Names a New C.E.O.

By: Eli Tan
25 June 2024 at 16:51
After a year of safety problems, layoffs and mass executive departures, G.M. is trying to find stability for its futuristic driverless car business.

© Cydni Elledge for The New York Times

Cruise pulled its driverless cars off roads last year.

Volkswagen Will Invest Up to $5 Billion in EV Maker Rivian

25 June 2024 at 17:56
VW and Rivian, a maker of electric trucks that has struggled to increase sales and break even, will work together on software and other technologies.

© Joel Angel Juarez/Reuters

The Volkswagen investment provides cash to Rivian, which has struggled to ramp up manufacturing of its electric pickups and sport utility vehicles.
Before yesterdayMain stream

On Titan Submersible Anniversary, World Rethinks Deep Sea Exploration

18 June 2024 at 10:15
A year after the first deaths of divers who ventured into the ocean’s sunless depths, an industry wrestles with new challenges for piloted submersibles and robotic explorers.

© Walt Disney Pictures/AJ Pics, via Alamy

A 2003 expedition by a piloted submersible to the wreckage of the Titanic on the sea floor, as documented in the James Cameron film “Ghosts of the Abyss.” A pair of robots are scheduled to revisit the site next month.

On Titan Submersible Anniversary, World Rethinks Deep Sea Exploration

18 June 2024 at 10:15
A year after the first deaths of divers who ventured into the ocean’s sunless depths, an industry wrestles with new challenges for piloted submersibles and robotic explorers.

© Walt Disney Pictures/AJ Pics, via Alamy

A 2003 expedition by a piloted submersible to the wreckage of the Titanic on the sea floor, as documented in the James Cameron film “Ghosts of the Abyss.” A pair of robots are scheduled to revisit the site next month.

Pride month small press books roundup

14 June 2024 at 09:43
Over 50 small press books under the fold! (previous: 1, 2, and 3)

The Ace and Aro Relationship Guide: Making It Work in Friendship, Love, and Sex by Cody Daigle-Orians (Jessica Kingsley Publishers, 21 Oct 2024): Whether we're talking about friendships, romantic relationships, casual dates or intimate partners, this guide will help you not only live authentically in your ace and aro identity, but joyfully share it with others. (Amazon; Bookshop) And Then There Was One by Michele Castleman (Bold Strokes Books, 1 June 2024): Six weeks after Lyla Smith dragged her sister's dead body onto the Lake Erie shore, she escapes her small Ohio town to work as a nanny for distant relatives on their remote private island. (Amazon; Bookshop) Antiquity by Hanna Johannson, trans. Kira Josefsson (Catapult, 6 Feb 2024): Elegant, slippery, and provocative, Antiquity is a queer Lolita story by prize-winning Swedish author Hanna Johansson—a story of desire, power, obsession, observation, and taboo. (Amazon; Bookshop) Born Backwards by Tanya Olson (YesYes Books, 18 Jun 2024): Olson's third poetry collection "reports from inside butch culture in the 1980s American South as it traces how geography, family, experiences, and popular culture shape one queer life." (Amazon; Bookshop) Broughtupsy by Christina Cooke (Catapult, 23 Jan 2024): At once cinematic yet intimate, Broughtupsy is an enthralling debut novel about a young Jamaican woman grappling with grief as she discovers her family, her home, is always just out of reach. (Amazon; Bookshop) The Call Is Coming from Inside the House: Essays by Allyson McOuat (ECW Press, Apr 2024): In a series of intimate and humorous dispatches, McOuat examines her identity as a queer woman, and as a mother, through the lens of the pop culture moments in the '80s and '90s that molded her identity. (Amazon; Bookshop) Dances of Time and Tenderness by Julian Carter (Nightboat Books, 4 June 2024): A cycle of stories linking queer memory, activism, death, and art in a transpoetic history of desire and touch. (Amazon; Bookshop) The Dragonfly Gambit by A. D. Sui (Neon Hemlock Press, 16 Apr 2024): Nearly ten years after Inez Kato sustained a career-ending injury during a military exercise gone awry, she lies, cheats, and seduces her way to the very top, to destroy the fleet that she was once a part of, even at the cost of her own life. Ennis Rezál, Third Daughter of the Rule, has six months left to live. She is desperate to end the twenty-year war she was birthed to fight. But when she brings Inez aboard the mothership, a chess game of manipulation and double-crossing begins to unfold, and the Rule doesn't stand a chance. (Amazon; Bookshop) An Evening with Birdy O'Day by Greg Kearney (Arsenal Pulp, 16 Apr 2024): A funny, boisterous, and deeply moving novel about aging hairstylist Roland's childhood friendship with Birdy O'Day, whose fevered quest for pop music glory drives them apart. (Amazon; Bookshop) Finding Echoes by Foz Meadows (Neon Hemlock, 30 Jan 2024): Snow Kidama speaks to ghosts amongst the local gangs of Charybdis Precinct, isolated from the rest of New Arcadia by the city's ancient walls. But when his old lover, Gem—a man he thought dead—shows up in need of his services, Snow is forced to reevaluate everything. (Amazon; Bookshop) Firebugs by Nino Bulling (Drawn & Quarterly, 13 Feb 2024): After a trip to Paris, Ingken returns home ready for a break from drugs. Their supportive partner, Lily, is flushed, excited about a new connection she's made. Although Ingken wants to be happy for her, there's a discomfort they can't shake. Sleepless nights fill with an endless scroll of images and headlines about climate disaster. A vague dysphoria simmers under their skin; they are able to identify that like Lily, they are changing, but they're not sure exactly how and at what pace. Everyone keeps telling them to burn themself to the ground and build themself back up but they worry about the kind of debris that fire might leave behind. (Amazon; Bookshop) The Future Was Color by Patrick Nathan (Counterpoint LLC, 4 June 2024): As a Hungarian immigrant working as a studio hack writing monster movies in 1950s Hollywood, George Curtis must navigate the McCarthy-era studio system filled with possible communists and spies, the life of closeted men along Sunset Boulevard, and the inability of the era to cleave love from persecution and guilt. But when Madeline, a famous actress, offers George a writing residency at her estate in Malibu to work on the political writing he cares most deeply about, his world is blown open. (Amazon; Bookshop) Getting Glam at Gram's by Sara Weed, ill. Erin Hawryluk (Arsenal Pulp, 3 Sept 2024): A colourful and celebratory picture book that embraces all gender expressions through a fun family fashion show. (Amazon; Bookshop) God of River Mud by Vic Sizemore (West Virginia UP, Jan 2024): To escape a life of poverty and abuse, Berna Cannaday marries Zechariah Minor, a fundamentalist Baptist preacher, and commits herself to his faith, trying to make it her own. After Zechariah takes a church beside the Elk River in rural Clay, West Virginia, Berna falls in love with someone from their congregation—Jordan, a woman who has known since childhood that he was meant to be a man. (Amazon; Bookshop) Healthy Chest Binding for Trans and Non-Binary People: A Practical Guide by Frances Reed (Jessica Kingsley Publishers, 18 Apr 2024): Binding is a crucial strategy in many transgender and non-binary people's lives for coping with gender dysphoria, yet the vast majority of those who bind report some negative physical symptoms. Written by Frances Reed, a licensed bodywork and massage therapist specialising in gender transition, this comprehensive guide helps you make the healthiest choices from the very start of your binding journey. (Amazon; Bookshop) If We Were Stars by Eule Grey (Ninestar Press, 2 Apr 2024): Best friends since they were ten years old, Kurt O'Hara and Beast Harris tackle the typical teenage challenges together: pronouns, AWOL bodies, not to mention snogging. A long-distance relationship with an alien named Iuvenis is the least of their troubles. (Amazon) Keep This Off The Record by Arden Joy (Rising Action, 31 Jan 2024): A romance: Abigail Meyer and Freya Jonsson can't stand one another. But could their severe hatred be masking something else entirely? (Amazon; Bookshop) The Long Hallway by Richard Scott Larson (University of Wisconsin Press, 16 Apr 2024): Growing up queer, closeted, and afraid, Richard Scott Larson found expression for his interior life in horror films, especially John Carpenter's 1978 classic, Halloween. He developed an intense childhood identification with Michael Myers, Carpenter's inscrutable masked villain, as well as Michael's potential victims. Larson scrutinizes this identification, meditating on horror as a metaphor for the torments of the closet. (Amazon; Bookshop) Love, Leda by Mark Hyatt (Nightboat Books, 24 Sept 2024): This portrait of queer, working class London drifts from coffee shop to house party, in search of the next tryst. (Amazon; Bookshop) Lush Lives by J. Vanessa Lyon (Grove Atlantic/Roxane Gay Books, 20 Aug 2024): With beguiling wit and undeniable passion, Lush Lives is a deliciously queer and sexy novel about bold, brilliant women unafraid to take risks and fight for what they love (Amazon; Bookshop) Medusa of the Roses by Navid Sinaki (Grove Atlantic, 13 Aug 2024): Sex, vengeance, and betrayal in modern day Tehran—Navid Sinaki's bold and cinematic debut is a queer literary noir following Anjir, a morbid romantic and petty thief whose boyfriend disappears just as they're planning to leave their hometown for good. (Amazon; Bookshop) Portrait of a Body by Julie Delporte (Drawn & Quarterly, 16 Jan 2024): As she examines her life experience and traumas with great care, Delporte faces the questions about gender and sexuality that both haunt and entice her. Deeply informed by her personal relationships as much as queer art and theory, Portrait of a Body is both a joyous and at times hard meditation on embodiment—a journey to be reunited with the self in an attempt to heal pain and live more authentically. (Amazon; Bookshop) Power to Yield and Other Stories by Bogi Takács (Broken Eye Books, 6 Feb 2024): An AI child discovers Jewish mysticism. A student can give no more blood to their semi-sentient apartment and plans their escape. A candidate is rigorously evaluated for their ability to be a liaison to alien newcomers. A young magician gains perspective from her time as a plant. A neurodivergent woman tries to survive on a planetoid where thoughts shape reality... (Amazon; Bookshop) So Long Sad Love by Mirion Malle, trans. Aleshia Jensen (Drawn & Quarterly, 23 Apr 2024): This graphic novel swaps out the wobbly transition of weaving a new existence into being post-heartbreak for the surprising effortlessness and simplicity of a life already rebuilt. Cleo not only rediscovers her identity as an artist but uncovers her capacity to find love where she has always been most at home: with other women. Mirion Malle dares to tell a story with a happier ending in a stunning, full-color follow-up to the multi-award nominated This is How I Disappear. (Amazon; Bookshop) Sons, Daughters by Ivana Bodrožić, trans. Ellen Elias-Bursać (Seven Stories Press, 30 Apr 2024): This novel tells a story of being locked in: socially, domestically and intimately. Here the Croatian poet and writer depicts a wrenching love between a transgender man and a woman as well as a demanding love between a mother and a daughter in a narrative about breaking through and liberation of the mind, family, and society. (Amazon; Bookshop) Vantage Points: On Media as Trans Memoir by Chase Joynt (Arsenal Pulp, 17 Sep 2024): Following the death of the family patriarch, a box of newly procured family documents reveals writer-filmmaker Chase Joynt's previously unknown connection to Canadian media maverick Marshall McLuhan. Vantage Points takes up the surprising appearance of McLuhan in Joynt's family archive as a way to think about legacies of childhood sexual abuse and how we might process and represent them. (Amazon; Bookshop) You Can't Go Home Again by Jeanette Bears (Bold Strokes Books, 13 Aug 2024): Contemporary romance. Raegan Holcolm thought all they wanted was a proud military career, and that's what they had. But a sudden injury sends them back to their hometown with a wealth of pain, both physical and emotional, insecurities, and the reality that the career they'd chosen above all else has rejected them. The first time they fell in love, Rae left Jules behind. For love to have a second chance, they'll need to realize all along that home might have been a person just as much as a place. (Amazon; Bookshop) Previous roundups 1, 2, and 3 also included Bad Seed by Gabriel Carle, trans. Heather Houde (Feminist Press), The Default World by Naomi Kanakia (Feminist Press), Disobedience by Daniel Sarah Karasik (Book*hug), Indian Winter by Kazim Ali (Coach House), Love the World Or Get Killed Trying by Alvina Chamberland (Noemi), My Body Is Paper by Gil Cuadros (City Lights), These Letters End In Tears by Musih Tedji Xaviere (Catapult), and, finally, How We Named the Stars by Andrés N. Ordorica (Tin House) which Bookshop included in its Pride Month 15% off sale with code PRIDE24. The Bookshop sale also includes these small press titles that I haven't previously listed:
  • All-Night Pharmacy (Ruth Madievsky, Catapult, Winner of the National Jewish Book Award for Debut Fiction)
  • Birthright (George Abraham, Button Poetry, "every pronoun is a Free Palestine," Bisexual Poetry Finalist in the 2021 Lambda Literary Awards; Button Poetry also has a 3 for $36 Pride Month deal going on, including Birthright and poetry by Blythe Baird, Sierra DeMulder, Andrea Gibson, Ebony Stewart, and more)
  • Boulder (Eva Baltasar, trans. Julia Sanches, And Other Stories, a queer couple struggles with motherhood, shortlisted for the 2023 International Booker Prize)
  • Brown Neon: Essays (Raquel Gutiérrez, Coffee House Press, "part butch memoir, part ekphrastic travel diary, part queer family tree")
  • Cecilia (K-Ming Chang, Coffee House Press, an "erotic, surreal novella")
  • Corey Fah Does Social Mobility (Isabel Waidner, Graywolf, "A novel that celebrates radical queer survival and gleefully takes a hammer to false notions of success")
  • A Dream of a Woman (Casey Plett, Arsenal Pulp Press, short stories by the author of the Lambda Literary Award-winning Little Fish)
  • Everything for Everyone: An Oral History of the New York Commune, 2052-2072 (Eman Abdelhadi & M. E. O'Brien, Common Notions, speculative fiction)
  • Feed (Tommy Pico, Tin House Books, fourth book in Teebs tetralogy, "an epistolary recipe for the main character, a poem of nourishment, and a jaunty walk through New York's High Line park, with the lines, stanzas, paragraphs, dialogue, and registers approximating the park's cultivated gardens of wildness")
  • Females (Andrea Long Chu, Verso, provocative genre-defying investigation into femaleness)
  • The Free People's Village (Sim Kern, Levine Querido, a novel of "eat-the-rich climate fiction")
  • The Future Is Disabled: Prophecies, Love Notes and Mourning Songs (Lambda Literary Award-winning Leah Lakshmi Piepzna-Samarasinha, Arsenal Pulp Press, disability justice, care and mutual aid)
  • Her Body and Other Parties: Stories (Carmen Maria Machado, Graywolf Press, "blithely demolishes the arbitrary borders between psychological realism and science fiction... to shape startling narratives that map the realities of women's lives and the violence visited upon their bodies")
  • High-Risk Homosexual: A Memoir (Edgar Gomez, Soft Skull, "a touching and often hilarious spiralic path to embracing a gay, Latinx identity against a culture of machismo")
  • Homie: Poems (Danez Smith, Graywolf Press, finalist for the National Book Critics Circle Award for Poetry and the NAACP Image Award for Poetry)
  • How to Fuck Like a Girl (Vera Blossom, Dopamine/Semiotext(e), a how-to guide)
  • I Love This Part (Tillie Walden, Avery Hill Publishing, graphic novel of teen queer love)
  • It Came from the Closet: Queer Reflections on Horror (ed. Joe Vallese, Feminist Press, essays by Carmen Maria Machado, Bruce Owens Grimm, Richard Scott Larson)
  • Love Is an Ex-Country: A Memoir (Randa Jarrar, Catapult, "Queer. Muslim. Arab American. A proudly Fat femme.")
  • Mrs. S (K. Patrick, Europa Editions, a butch English boarding school matron begins an illicit affair with the headmaster's wife)
  • Outwrite: The Speeches That Shaped LGBTQ Literary Culture (eds. Julie R. Enszer, Elena Gross, Rutgers UP, 27 of the most memorable speeches from the OutWrite conference)
  • Playboy (Constance Debre, trans. Holly James, Semiotext(e), the first volume of the renowned trilogy on the author's decision to abandon her bourgeois Parisian life to become a lesbian and writer)
  • Sluts: Anthology (ed. Michelle Tea, Dopamine Books, anthology of essays and stories on sexual promiscuity in contemporary American culture)
  • Stone Fruit (Lee Lai, Fantagraphics Books, a queer couple opens up to their families in this 2022 Lambda Literary Award winner for Comics)
  • Survival Takes a Wild Imagination: Poems (Fariha Róisín, Andrews McMeel Publishing, "Who is my family? My father? How do I love a mother no longer here? Can I see myself? What does it mean to be Bangladeshi? What is a border?")
  • Time Is the Thing a Body Moves Through (T. Fleischmann, Coffee House Press, "an autobiographical narrative of embodiment, visual art, history, and loss")
  • Thunder Song: Essays (Sasha Lapointe, Counterpoint LLC, what it means to be a proudly queer indigenous woman in the USA)
  • The Tradition (Jericho Brown, Copper Canyon Press, Pulitzer Prize-winning poetry that examines black bodies, desire, privilege and resistance)
  • When We Were Sisters (Fatimah Asghar, One World, "traces the intense bond of three orphaned siblings," longlisted for the National Book Award)
  • You Exist Too Much (Zaina Arafat, Catapult: Palestinian American queer coming-of-age novel)
  • Your Emergency Contact Has Experienced an Emergency (Chen Chen, BOA Editions, "What happens when everything falls away, when those you call on in times of need are themselves calling out for rescue?")
With management's blessing, I set up a MeFi affiliate membership with Bookshop, so the links above will benefit MetaFilter.

How Electric Car Batteries Might Aid the Grid (and Win Over Drivers)

5 June 2024 at 11:36
Automakers are exploring energy storage as a way to help utilities and save customers money, turning an expensive component into an industry asset.

© Laetitia Vancon for The New York Times

A Mobility House customer using the company’s electric vehicle charging system in Munich.

The Very Slow Restart of G.M.’s Cruise Driverless Car Business

By: Yiwen Lu
30 May 2024 at 05:02
An incident that seriously injured a pedestrian in San Francisco led Cruise to take all of its cars off the road. The question now is when they will return.

© Jason Henry for The New York Times

A Cruise driverless car in San Francisco in 2022. Cruise paused operations late last year after it was criticized for neglecting safety.

Elon Musk’s xAI Raises $6 Billion

27 May 2024 at 14:11
Elon Musk, who founded xAI last year, has said the business “still has a lot of catching up to do” as it looks to compete with well-funded companies like OpenAI.

© Nina Westervelt for The New York Times

Elon Musk in New York last month.

Ampla, a Lender to Consumer Brands, Faces Financial Struggles

24 May 2024 at 05:02
Ampla, which lent money to smaller businesses that sold clothing, home furnishings and other items directly to consumers, is struggling financially and seeking a buyer.

© Kim Raff for The New York Times

Ben Perkins, the founder of &Collar, a men’s dress shirt company, was told by an Ampla representative last month that his business’s credit line had been frozen.

Stark Industries Solutions: An Iron Hammer in the Cloud

23 May 2024 at 19:32

The homepage of Stark Industries Solutions.

Two weeks before Russia invaded Ukraine in February 2022, a large, mysterious new Internet hosting firm called Stark Industries Solutions materialized and quickly became the epicenter of massive distributed denial-of-service (DDoS) attacks on government and commercial targets in Ukraine and Europe. An investigation into Stark Industries reveals it is being used as a global proxy network that conceals the true source of cyberattacks and disinformation campaigns against enemies of Russia.

At least a dozen patriotic Russian hacking groups have been launching DDoS attacks since the start of the war at a variety of targets seen as opposed to Moscow. But by all accounts, few attacks from those gangs have come close to the amount of firepower wielded by a pro-Russia group calling itself “NoName057(16).”

This graphic comes from a recent report from NETSCOUT about DDoS attacks from Russian hacktivist groups.

As detailed by researchers at Radware, NoName has effectively gamified DDoS attacks, recruiting hacktivists via its Telegram channel and offering to pay people who agree to install a piece of software called DDoSia. That program allows NoName to commandeer the host computers and their Internet connections in coordinated DDoS campaigns, and DDoSia users with the most attacks can win cash prizes.

The NoName DDoS group advertising on Telegram. Image: SentinelOne.com.

A report from the security firm Team Cymru found the DDoS attack infrastructure used in NoName campaigns is assigned to two interlinked hosting providers: MIRhosting and Stark Industries. MIRhosting is a hosting provider founded in The Netherlands in 2004. But Stark Industries Solutions Ltd was incorporated on February 10, 2022, just two weeks before the Russian invasion of Ukraine.

PROXY WARS

Security experts say that not long after the war started, Stark began hosting dozens of proxy services and free virtual private networking (VPN) services, which are designed to help users shield their Internet usage and location from prying eyes.

Proxy providers allow users to route their Internet and Web browsing traffic through someone else’s computer. From a website’s perspective, the traffic from a proxy network user appears to originate from the rented IP address, not from the proxy service customer.

These services can be used in a legitimate manner for several business purposes — such as price comparisons or sales intelligence — but they are also massively abused for hiding cybercrime activity because they can make it difficult to trace malicious traffic to its original source.

What’s more, many proxy services do not disclose how they obtain access to the proxies they are renting out, and in many cases the access is obtained through the dissemination of malicious software that turns the infected system into a traffic relay — usually unbeknownst to the legitimate owner of the Internet connection. Other proxy services will allow users to make money by renting out their Internet connection to anyone.

Spur.us is a company that tracks VPNs and proxy services worldwide. Spur finds that Stark Industries (AS44477) currently is home to at least 74 VPN services, and 40 different proxy services. As we’ll see in the final section of this story, just one of those proxy networks has over a million Internet addresses available for rent across the globe.

Raymond Dijkxhoorn operates a hosting firm in The Netherlands called Prolocation. He also co-runs SURBL, an anti-abuse service that flags domains and Internet address ranges that are strongly associated with spam and cybercrime activity, including DDoS.

Dijkxhoorn said last year SURBL heard from multiple people who said they operated VPN services whose web resources were included in SURBL’s block lists.

“We had people doing delistings at SURBL for domain names that were suspended by the registrars,” Dijkhoorn told KrebsOnSecurity. “And at least two of them explained that Stark offered them free VPN services that they were reselling.”

Dijkxhoorn added that Stark Industries also sponsored activist groups from Ukraine.

“How valuable would it be for Russia to know the real IPs from Ukraine’s tech warriors?” he observed.

CLOUDY WITH A CHANCE OF BULLETS

Richard Hummel is threat intelligence lead at NETSCOUT. Hummel said when he considers the worst of all the hosting providers out there today, Stark Industries is consistently near or at the top of that list.

“The reason is we’ve had at least a dozen service providers come to us saying, ‘There’s this network out there inundating us with traffic,'” Hummel said. “And it wasn’t even DDoS attacks. [The systems] on Stark were just scanning these providers so fast it was crashing some of their services.”

Hummel said NoName will typically launch their attacks using a mix of resources rented from major, legitimate cloud services, and those from so-called “bulletproof” hosting providers like Stark. Bulletproof providers are so named when they earn or cultivate a reputation for ignoring any abuse complaints or police reports about activity on their networks.

Combining bulletproof providers with legitimate cloud hosting, Hummel said, likely makes NoName’s DDoS campaigns more resilient because many network operators will hesitate to be too aggressive in blocking Internet addresses associated with the major cloud services.

“What we typically see here is a distribution of cloud hosting providers and bulletproof hosting providers in DDoS attacks,” he said. “They’re using public cloud hosting providers because a lot of times that’s your first layer of network defense, and because [many companies are wary of] over-blocking access to legitimate cloud resources.”

But even if the cloud provider detects abuse coming from the customer, the provider is probably not going to shut the customer down immediately, Hummel said.

“There is usually a grace period, and even if that’s only an hour or two, you can still launch a large number of attacks in that time,” he said. “And then they just keep coming back and opening new cloud accounts.”

MERCENARIES TEAM

Stark Industries is incorporated at a mail drop address in the United Kingdom. UK business records list an Ivan Vladimirovich Neculiti as the company’s secretary. Mr. Neculiti also is named as the CEO and founder of PQ Hosting Plus S.R.L. (aka Perfect Quality Hosting), a Moldovan company formed in 2019 that lists the same UK mail drop address as Stark Industries.

Ivan Neculiti, as pictured on LinkedIn.

Reached via LinkedIn, Mr. Neculiti said PQ Hosting established Stark Industries as a “white label” of its brand so that “resellers could distribute our services using our IP addresses and their clients would not have any affairs with PQ Hosting.”

“PQ Hosting is a company with over 1,000+ of [our] own physical servers in 38 countries and we have over 100,000 clients,” he said. “Though we are not as large as Hetzner, Amazon and OVH, nevertheless we are a fast growing company that provides services to tens of thousands of private customers and legal entities.”

Asked about the constant stream of DDoS attacks whose origins have traced back to Stark Industries over the past two years, Neculiti maintained Stark hasn’t received any official abuse reports about attacks coming from its networks.

“It was probably some kind of clever attack that we did not see, I do not rule out this fact, because we have a very large number of clients and our Internet channels are quite large,” he said. “But, in this situation, unfortunately, no one contacted us to report that there was an attack from our addresses; if someone had contacted us, we would have definitely blocked the network data.”

DomainTools.com finds Ivan V. Neculiti was the owner of war[.]md, a website launched in 2008 that chronicled the history of a 1990 armed conflict in Moldova known as the Transnistria War and the Moldo-Russian war.

An ad for war.md, circa 2009.

Transnistria is a breakaway pro-Russian region that declared itself a state in 1990, although it is not internationally recognized. The copyright on that website credits the “MercenarieS TeaM,” which was at one time a Moldovan IT firm. Mr. Neculiti confirmed personally registering this domain.

DON CHICHO & DFYZ

The data breach tracking service Constella Intelligence reports that an Ivan V. Neculiti registered multiple online accounts under the email address dfyz_bk@bk.ru. Cyber intelligence firm Intel 471 shows this email address is tied to the username “dfyz” on more than a half-dozen Russian language cybercrime forums since 2008. The user dfyz on Searchengines[.]ru in 2008 asked other forum members to review war.md, and said they were part of the MercenarieS TeaM.

Back then, dfyz was selling “bulletproof servers for any purpose,” meaning the hosting company would willfully ignore abuse complaints or police inquiries about the activity of its customers.

DomainTools reports there are at least 33 domain names registered to dfyz_bk@bk.ru. Several of these domains have Ivan Neculiti in their registration records, including tracker-free[.]cn, which was registered to an Ivan Neculiti at dfyz_bk@bk.ru and referenced the MercenarieS TeaM in its original registration records.

Dfyz also used the nickname DonChicho, who likewise sold bulletproof hosting services and access to hacked Internet servers. In 2014, a prominent member of the Russian language cybercrime community Antichat filed a complaint against DonChicho, saying this user scammed them and had used the email address dfyz_bk@bk.ru.

The complaint said DonChicho registered on Antichat from the Transnistria Internet address 84.234.55[.]29. Searching this address in Constella reveals it has been used to register just five accounts online that have been created over the years, including one at ask.ru, where the user registered with the email address neculitzy1@yandex.ru. Constella also returns for that email address a user by the name “Ivan” at memoraleak.com and 000webhost.com.

Constella finds that the password most frequently used by the email address dfyz_bk@bk.ru was “filecast,” and that there are more than 90 email addresses associated with this password. Among them are roughly two dozen addresses with the name “Neculiti” in them, as well as the address support@donservers[.]ru.

Intel 471 says DonChicho posted to several Russian cybercrime forums that support@donservers[.]ru was his address, and that he logged into cybercrime forums almost exclusively from Internet addresses in Tiraspol, the capital of Transnistria. A review of DonChicho’s posts shows this person was banned from several forums in 2014 for scamming other users.

Cached copies of DonChicho’s vanity domain (donchicho[.]ru) show that in 2009 he was a spammer who peddled knockoff prescription drugs via Rx-Promotion, once one of the largest pharmacy spam moneymaking programs for Russian-speaking affiliates.

Mr. Neculiti told KrebsOnSecurity he has never used the nickname DonChicho.

“I may assure you that I have no relation to DonChicho nor to his bulletproof servers,” he said.

Below is a mind map that shows the connections between the accounts mentioned above.

A mind map tracing the history of the user Dfyz. Click to enlarge.

Earlier this year, NoName began massively hitting government and industry websites in Moldova. A new report from Arbor Networks says the attacks began around March 6, when NoName alleged the government of Moldova was “craving for Russophobia.”

“Since early March, more than 50 websites have been targeted, according to posted ‘proof’ by the groups involved in attacking the country,” Arbor’s ASERT Team wrote. “While NoName seemingly initiated the ramp of attacks, a host of other DDoS hacktivists have joined the fray in claiming credit for attacks across more than 15 industries.”

CORRECTIV ACTION

The German independent news outlet Correctiv.org last week published a scathing investigative report on Stark Industries and MIRhosting, which notes that Ivan Neculiti operates his hosting companies with the help of his brother, Yuri.

Image credit: correctiv.org.

The report points out that Stark Industries continues to host a Russian disinformation news outlet called “Recent Reliable News” (RRN) that was sanctioned by the European Union in 2023 for spreading links to propaganda blogs and fake European media and government websites.

“The website was not running on computers in Moscow or St. Petersburg until recently, but in the middle of the EU, in the Netherlands, on the computers of the Neculiti brothers,” Correctiv reporters wrote.

“After a request from this editorial team, a well-known service was installed that hides the actual web host,” the report continues. “Ivan Neculiti announced that he had blocked the associated access and server following internal investigations. “We very much regret that we are only now finding out that one of our customers is a sanctioned portal,” said the company boss. However, RRN is still accessible via its servers.”

Correctiv also points to a January 2023 report from the Ukrainian government, which found servers from Stark Industries Solutions were used as part of a cyber attack on the Ukrainian news agency “Ukrinform”. Correctiv notes the notorious hacker group Sandworm — an advanced persistent threat (APT) group operated by a cyberwarfare unit of Russia’s military intelligence service — was identified by Ukrainian government authorities as responsible for that attack.

PEACE HOSTING?

Public records indicate MIRhosting is based in The Netherlands and is operated by 37-year old Andrey Nesterenko, whose personal website says he is an accomplished concert pianist who began performing publicly at a young age.

DomainTools says mirhosting[.]com is registered to Mr. Nesterenko and to Innovation IT Solutions Corp, which lists addresses in London and in Nesterenko’s stated hometown of Nizhny Novgorod, Russia.

This is interesting because according to the book Inside Cyber Warfare by Jeffrey Carr, Innovation IT Solutions Corp. was responsible for hosting StopGeorgia[.]ru, a hacktivist website for organizing cyberattacks against Georgia that appeared at the same time Russian forces invaded the former Soviet nation in 2008. That conflict was thought to be the first war ever fought in which a notable cyberattack and an actual military engagement happened simultaneously.

Responding to questions from KrebsOnSecurity, Mr. Nesterenko said he couldn’t say whether his network had ever hosted the StopGeorgia website back in 2008 because his company didn’t keep records going back that far. But he said Stark Industries Solutions is indeed one of MIRhsoting’s colocation customers.

“Our relationship is purely provider-customer,” Nesterenko said. “They also utilize multiple providers and data centers globally, so connecting them directly to MIRhosting overlooks their broader network.”

“We take any report of malicious activity seriously and are always open to information that can help us identify and prevent misuse of our infrastructure, whether involving Stark Industries or any other customer,” Nesterenko continued. “In cases where our services are exploited for malicious purposes, we collaborate fully with Dutch cyber police and other relevant authorities to investigate and take appropriate measures. However, we have yet to receive any actionable information beyond the article itself, which has not provided us with sufficient detail to identify or block malicious actors.”

In December 2022, security firm Recorded Future profiled the phishing and credential harvesting infrastructure used for Russia-aligned espionage operations by a group dubbed Blue Charlie (aka TAG-53), which has targeted email accounts of nongovernmental organizations and think tanks, journalists, and government and defense officials.

Recorded Future found that virtually all the Blue Charlie domains existed in just ten different ISPs, with a significant concentration located in two networks, one of which was MIRhosting. Both Microsoft and the UK government assess that Blue Charlie is linked to the Russian threat activity groups variously known as Callisto Group, COLDRIVER, and SEABORGIUM.

Mr. Nesterenko took exception to a story on that report from The Record, which is owned by Recorded Future.

“We’ve discussed its contents with our customer, Stark Industries,” he said. “We understand that they have initiated legal proceedings against the website in question, as they firmly believe that the claims made are inaccurate.”

Recorded Future said they updated their story with comments from Mr. Neculiti, but that they stand by their reporting.

Mr. Nesterenko’s LinkedIn profile says he was previously the foreign region sales manager at Serverius-as, a hosting company in The Netherlands that remains in the same data center as MIRhosting.

In February, the Dutch police took 13 servers offline that were used by the infamous LockBit ransomware group, which had originally bragged on its darknet website that its home base was in The Netherlands. Sources tell KrebsOnSecurity the servers seized by the Dutch police were located in Serverius’ data center in Dronten, which is also shared by MIRhosting.

Serverius-as did not respond to requests for comment. Nesterenko said MIRhosting does use one of Serverius’s data centers for its operations in the Netherlands, alongside two other data centers, but that the recent incident involving the seizure of servers has no connection to MIRhosting.

“We are legally prohibited by Dutch law and police regulations from sharing information with third parties regarding any communications we may have had,” he said.

A February 2024 report from security firm ESET found Serverius-as systems were involved in a series of targeted phishing attacks by Russia-aligned groups against Ukrainian entities throughout 2023. ESET observed that after the spearphishing domains were no longer active, they were converted to promoting rogue Internet pharmacy websites.

PEERING INTO THE VOID

A review of the Internet address ranges recently added to the network operated by Stark Industries Solutions offers some insight into its customer base, usage, and maybe even true origins. Here is a snapshot (PDF) of all Internet address ranges announced by Stark Industries so far in the month of May 2024 (this information was graciously collated by the network observability platform Kentik.com).

Those records indicate that the largest portion of the IP space used by Stark is in The Netherlands, followed by Germany and the United States. Stark says it is connected to roughly 4,600 Internet addresses that currently list their ownership as Comcast Cable Communications.

A review of those address ranges at spur.us shows all of them are connected to an entity called Proxyline, which is a sprawling proxy service based in Russia that currently says it has more than 1.6 million proxies globally that are available for rent.

Proxyline dot net.

Reached for comment, Comcast said the Internet address ranges never did belong to Comcast, so it is likely that Stark has been fudging the real location of its routing announcements in some cases.

Stark reports that it has more than 67,000 Internet addresses at Santa Clara, Calif.-based EGIhosting. Spur says the Stark addresses involving EGIhosting all map to Proxyline as well. EGIhosting did not respond to requests for comment.

EGIhosting manages Internet addresses for the Cyprus-based hosting firm ITHOSTLINE LTD (aka HOSTLINE-LTD), which is represented throughout Stark’s announced Internet ranges. Stark says it has more than 21,000 Internet addresses with HOSTLINE. Spur.us finds Proxyline addresses are especially concentrated in the Stark ranges labeled ITHOSTLINE LTD, HOSTLINE-LTD, and Proline IT.

Stark’s network list includes approximately 21,000 Internet addresses at Hockessin, De. based DediPath, which abruptly ceased operations without warning in August 2023. According to a phishing report released last year by Interisle Consulting, DediPath was the fourth most common source of phishing attacks in the year ending Oct. 2022. Spur.us likewise finds that virtually all of the Stark address ranges marked “DediPath LLC” are tied to Proxyline.

Image: Interisle Consulting.

A large number of the Internet address ranges announced by Stark in May originate in India, and the names that are self-assigned to many of these networks indicate they were previously used to send large volumes of spam for herbal medicinal products, with names like HerbalFarm, AdsChrome, Nutravo, Herbzoot and Herbalve.

The anti-spam organization SpamHaus reports that many of the Indian IP address ranges are associated with known “snowshoe spam,” a form of abuse that involves mass email campaigns spread across several domains and IP addresses to weaken reputation metrics and avoid spam filters.

It’s not clear how much of Stark’s network address space traces its origins to Russia, but big chunks of it recently belonged to some of the oldest entities on the Russian Internet (a.k.a. “Runet”).

For example, many Stark address ranges were most recently assigned to a Russian government entity whose full name is the “Federal State Autonomous Educational Establishment of Additional Professional Education Center of Realization of State Educational Policy and Informational Technologies.”

A review of Internet address ranges adjacent to this entity reveals a long list of Russian government organizations that are part of the Federal Guard Service of the Russian Federation. Wikipedia says the Federal Guard Service is a Russian federal government agency concerned with tasks related to protection of several high-ranking state officials, including the President of Russia, as well as certain federal properties. The agency traces its origins to the USSR’s Ninth Directorate of the KGB, and later the presidential security service.

Stark recently announced the address range 213.159.64.0/20 from April 27 to May 1, and this range was previously assigned to an ancient ISP in St. Petersburg, RU called the Computer Technologies Institute Ltd.

According to a post on the Russian language webmaster forum searchengines[.]ru, the domain for Computer Technologies Institute — ctinet[.]ruis the seventh-oldest domain in the entire history of the Runet.

Curiously, Stark also lists large tracts of Internet addresses (close to 48,000 in total) assigned to a small ISP in Kharkiv, Ukraine called NetAssist. Reached via email, the CEO of NetAssist Max Tulyev confirmed his company provides a number of services to PQ Hosting.

“We colocate their equipment in Warsaw, Madrid, Sofia and Thessaloniki, provide them IP transit and IPv4 addresses,” Tulyev said. “For their size, we receive relatively low number of complains to their networks. I never seen anything about their pro-Russian activity or support of Russian hackers. It is very interesting for me to see proofs of your accusations.”

Spur.us mapped the entire infrastructure of Proxyline, and found more than one million proxies across multiple providers, but by far the biggest concentration was at Stark Industries Solutions. The full list of Proxyline address ranges (.CSV) shows two other ISPs appear repeatedly throughout the list. One is Kharkiv, Ukraine based ITL LLC, also known as Information Technology Laboratories Group, and Integrated Technologies Laboratory.

The second is a related hosting company in Miami, called Green Floid LLC. Green Floid featured in a 2017 scoop by CNN, which profiled the company’s owner and quizzed him about Russian troll farms using proxy networks on Green Floid and its parent firm ITL to mask disinformation efforts tied to the Kremlin’s Internet Research Agency (IRA). At the time, the IRA was using Facebook and other social media networks to spread videos showing police brutality against African Americans in an effort to encourage protests across the United States.

Doug Madory, director of Internet analysis at Kentik, was able to see at a high level the top sources and destinations for traffic traversing Stark’s network.

“Based on our aggregate NetFlow, we see Iran as the top destination (35.1%) for traffic emanating from Stark (AS44477),” Madory said. “Specifically, the top destination is MTN Irancell, while the top source is Facebook. This data supports the theory that AS44477 houses proxy services as Facebook is blocked in Iran.”

On April 30, the security firm Malwarebytes explored an extensive malware operation that targets corporate Internet users with malicious ads. Among the sites used as lures in that campaign were fake Wall Street Journal and CNN websites that told visitors they were required to install a WSJ or CNN-branded browser extension (malware). Malwarebytes found a domain name central to that operation was hosted at Internet addresses owned by Stark Industries.

Image: threatdown.com

AI’s Black Boxes Just Got a Little Less Mysterious

21 May 2024 at 14:00
Researchers at the A.I. company Anthropic claim to have found clues about the inner workings of large language models, possibly helping to prevent their misuse and to curb their potential threats.

© Marissa Leshnov for The New York Times

Anthropic researchers found that turning certain features on or off in the company’s chatbot could change how the A.I. system behaved.

Tesla Pullback Puts Onus on Others to Build Electric Vehicle Chargers

The automaker led by Elon Musk is no longer planning to take the lead in expanding the number of places to fuel electric vehicles. It’s not clear how quickly other companies will fill the gap.

© Lauren Justice for The New York Times

Tesla’s change of direction is likely to delay construction of fast chargers, which are concentrated on the two coasts and in parts of Texas.

From Baby Talk to Baby A.I.

30 April 2024 at 15:09
Could a better understanding of how infants acquire language help us build smarter A.I. models?

© Hiroko Masuike/The New York Times

For an hour each week for the past 11 months, Brenden Lake, right, a psychologist at New York University, with his wife Tammy Kwan, has been attaching a camera to their daughter Luna and recording things from her point of view.

From Baby Talk to Baby A.I.

30 April 2024 at 12:38
Could a better understanding of how infants acquire language help us build smarter A.I. models?

© Hiroko Masuike/The New York Times

For an hour each week for the past 11 months, Brenden Lake, right, a psychologist at New York University, with his wife Tammy Kwan, has been attaching a camera to their daughter Luna and recording things from her point of view.

A.I. Start-Ups Face a Rough Financial Reality Check

The table stakes for small companies to compete with the likes of Microsoft and Google are in the billions of dollars. And even that may not be enough.

© Aaron Fernandez

Russian FSB Counterintelligence Chief Gets 9 Years in Cybercrime Bribery Scheme

22 April 2024 at 16:07

The head of counterintelligence for a division of the Russian Federal Security Service (FSB) was sentenced last week to nine years in a penal colony for accepting a USD $1.7 million bribe to ignore the activities of a prolific Russian cybercrime group that hacked thousands of e-commerce websites. The protection scheme was exposed in 2022 when Russian authorities arrested six members of the group, which sold millions of stolen payment cards at flashy online shops like Trump’s Dumps.

A now-defunct carding shop that sold stolen credit cards and invoked 45’s likeness and name.

As reported by The Record, a Russian court last week sentenced former FSB officer Grigory Tsaregorodtsev for taking a $1.7 million bribe from a cybercriminal group that was seeking a “roof,” a well-placed, corrupt law enforcement official who could be counted on to both disregard their illegal hacking activities and run interference with authorities in the event of their arrest.

Tsaregorodtsev was head of the counterintelligence department for a division of the FSB based in Perm, Russia. In February 2022, Russian authorities arrested six men in the Perm region accused of selling stolen payment card data. They also seized multiple carding shops run by the gang, including Ferum Shop, Sky-Fraud, and Trump’s Dumps, a popular fraud store that invoked the 45th president’s likeness and promised to “make credit card fraud great again.”

All of the domains seized in that raid were registered by an IT consulting company in Perm called Get-net LLC, which was owned in part by Artem Zaitsev — one of the six men arrested. Zaitsev reportedly was a well-known programmer whose company supplied services and leasing to the local FSB field office.

The message for Trump’s Dumps users left behind by Russian authorities that seized the domain in 2022.

Russian news sites report that Internal Affairs officials with the FSB grew suspicious when Tsaregorodtsev became a little too interested in the case following the hacking group’s arrests. The former FSB agent had reportedly assured the hackers he could have their case transferred and that they would soon be free.

But when that promised freedom didn’t materialize, four the of the defendants pulled the walls down on the scheme and brought down their own roof. The FSB arrested Tsaregorodtsev, and seized $154,000 in cash, 100 gold bars, real estate and expensive cars.

At Tsaregorodtsev’s trial, his lawyers argued that their client wasn’t guilty of bribery per se, but that he did admit to fraud because he was ultimately unable to fully perform the services for which he’d been hired.

The Russian news outlet Kommersant reports that all four of those who cooperated were released with probation or correctional labor. Zaitsev received a sentence of 3.5 years in prison, and defendant Alexander Kovalev got four years.

In 2017, KrebsOnSecurity profiled Trump’s Dumps, and found the contact address listed on the site was tied to an email address used to register more than a dozen domains that were made to look like legitimate Javascript calls many e-commerce sites routinely make to process transactions — such as “js-link[dot]su,” “js-stat[dot]su,” and “js-mod[dot]su.”

Searching on those malicious domains revealed a 2016 report from RiskIQ, which shows the domains featured prominently in a series of hacking campaigns against e-commerce websites. According to RiskIQ, the attacks targeted online stores running outdated and unpatched versions of shopping cart software from Magento, Powerfront and OpenCart.

Those shopping cart flaws allowed the crooks to install “web skimmers,” malicious Javascript used to steal credit card details and other information from payment forms on the checkout pages of vulnerable e-commerce sites. The stolen customer payment card details were then sold on sites like Trump’s Dumps and Sky-Fraud.

E-Crime Rapper ‘Punchmade Dev’ Debuts Card Shop

17 January 2024 at 12:00

The rapper and social media personality Punchmade Dev is perhaps best known for his flashy videos singing the praises of a cybercrime lifestyle. With memorable hits such as “Internet Swiping” and “Million Dollar Criminal” earning millions of views, Punchmade has leveraged his considerable following to peddle tutorials on how to commit financial crimes online. But until recently, there wasn’t much to support a conclusion that Punchmade was actually doing the cybercrime things he promotes in his songs.

Images from Punchmade Dev’s Twitter/X account show him displaying bags of cash and wearing a functional diamond-crusted payment card skimmer.

Punchmade Dev’s most controversial mix — a rap called “Wire Fraud Tutorial” — was taken down by Youtube last summer for violating the site’s rules. Punchmade shared on social media that the video’s removal was prompted by YouTube receiving a legal process request from law enforcement officials.

The 24-year-old rapper told reporters he wasn’t instructing people how to conduct wire fraud, but instead informing his fans on how to avoid being victims of wire fraud. However, this is difficult to discern from listening to the song, which sounds very much like a step-by-step tutorial on how to commit wire fraud.

“Listen up, I’m finna show y’all how to hit a bank,” Wire Fraud Tutorial begins. “Just pay attention, this is a quick way to jug in any state. First you wanna get a bank log from a trusted site. Do your research because the information must be right.”

And even though we’re talking about an individual who regularly appears in videos wearing a half-million dollars worth of custom jewelry draped around his arm and neck (including the functional diamond-encrusted payment card skimming device pictured above), there’s never been much evidence that Punchmade was actually involved in committing cybercrimes himself. Even his most vocal critics acknowledged that the whole persona could just be savvy marketing.

That changed recently when Punchmade’s various video and social media accounts began promoting a new web shop that is selling stolen payment cards and identity data, as well as hacked financial accounts and software for producing counterfeit checks.

Punchmade Dev's shop.

Punchmade Dev’s shop.

The official Punchmadedev account on Instagram links to many of the aforementioned rap videos and tutorials on cybercriming, as well as to Punchmadedev’s other profiles and websites. Among them is mainpage[.]me/punchmade, which includes the following information for “Punchmade Empire ®

-212,961 subscribers

#1 source on Telegram

Contact: @whopunchmade

24/7 shop: https://punchmade[.]atshop[.]io

Visiting that @whopunchmade Telegram channel shows this user is promoting punchmade[.]atshop[.]io, which is currently selling hacked bank accounts and payment cards with high balances.

Clicking “purchase” on the C@sh App offering, for example, shows that for $80 the buyer will receive logins to Cash App accounts with balances between $3,000 and $5,000. “If you buy this item you’ll get my full support on discord/telegram if there is a problem!,” the site promises. Purchases can be made in cryptocurrencies, and checking out prompts one to continue payment at Coinbase.com.

Another item for sale, “Fullz + Linkable CC,” promises “ID Front + Back, SSN with 700+ Credit Score, and Linkable CC” or credit card. That also can be had for $80 in crypto.

WHO IS PUNCHMADE DEV?

Punchmade has fashioned his public persona around a collection of custom-made, diamond-covered necklaces that are as outlandish and gaudy as they are revelatory. My favorite shot from one of Punchmade’s videos features at least three of these monstrosities: One appears to be a boring old diamond and gold covered bitcoin, but the other two necklaces tell us something about where Punchmade is from:

Notice the University of Kentucky logo, and the Lexington, Ky skyline.

One of them includes the logo and mascot of the University of Kentucky. The other, an enormous diamond studded skyline, appears to have been designed based on the skyline in Lexington, Ky:

The “About” page on Punchmade Dev’s Spotify profile describes him as “an American artist, rapper, musician, producer, director, entrepreneur, actor and investor.” “Punchmade Dev is best known for his creative ways to use technology, video gaming, and social media to build a fan base,” the profile continues.

The profile explains that he launched his own record label in 2021 called Punchmade Records, where he produces his own instrumentals and edits his own music videos.

A search on companies that include the name “punchmade” at the website of the Kentucky Secretary of State brings up just one record: OBN Group LLC, in Lexington, Ky. This November 2021 record includes a Certificate of Assumed Name, which shows that Punchmade LLC is the assumed name of OBN Group LLC.

The president of OBN Group LLC is listed as Devon Turner. A search on the Secretary of State website for other businesses tied to Devon Turner reveals just one other record: A now-defunct entity called DevTakeFlightBeats Inc.

The breach tracking service Constella Intelligence finds that Devon Turner from Lexington, Ky. used the email address obndevpayments@gmail.com. A lookup on this email at DomainTools.com shows it was used to register the domain foreverpunchmade[.]com, which is registered to a Devon Turner in Lexington, Ky. A copy of this site at archive.org indicates it once sold Punchmade Dev-branded t-shirts and other merchandise.

Mr. Turner did not respond to multiple requests for comment.

Searching online for Devon Turner and “Punchmade” brings up a video from @brainjuiceofficial, a YouTube channel that focuses on social media celebrities. @Brainjuiceofficial says Turner was born in October 2000, the oldest child of a single mother of five whose husband was not in the picture.

Devon Turner, a.k.a. “Punchmade Dev,” in an undated photo.

The video says the six-foot five Turner played basketball, track and football in high school, but that he gradually became obsessed with playing the video game NBA 2K17 and building a following of people watching him play the game competitively online.

According to this brief documentary, Turner previously streamed his NBA 2K17 videos on a YouTube channel called DevTakeFlight, although he originally went by the nickname OBN Dev.

“Things may eventually catch up to Devon if he isn’t careful,” @Brainjuiceofficial observed, noting that Turner has been shot at before, and also robbed at an ATM while flexing a bunch of cash for a picture and wearing $500k in jewelry. “Although you have a lot of people that are into what you do, there are a lot of people waiting for you to slip up.”

❌
❌