How hackers steal your data | Lex Fridman Podcast
The speaker, associated with VLC media player, describes real-world cyberattack vectors including Chinese hackers hijacking VLC's signed DLL, a long-running fake VLC installer in Germany distributing spyware, and phishing emails impersonating security updates. The conversation highlights how search engines like Google fail to address known malicious fake software sites. The key takeaway is that users must be vigilant about downloading software only from official sources.
Summary
The speaker recounts how Chinese hackers targeting Indian users exploited VLC's legitimately signed DLL file — they didn't distribute VLC itself, but extracted the signed DLL and used it within a malicious program that called a fake version of the library (libVLC), making detection difficult. The speaker acknowledges there is little developers can do to prevent this type of attack.
A significant portion of the discussion focuses on a fake VLC website in Germany that has been operating for over 12 years. Despite being reported repeatedly, Google has declined to take action, citing that the binary is too large for their virus analyzer to process. The fake site uses dark SEO tactics to rank highly in German search results and presents a localized German-language experience to attract users. Critically, the malware embedded in the fake installer deliberately lies dormant for three weeks before activating, a tactic specifically designed to evade behavior-based detection systems. After three weeks, a background service wakes up and begins downloading spyware and adware, including software that replaces ads within the victim's browser or machine.
The conversation also touches on phishing psychology, with the interviewer noting how convincingly crafted emails — such as fake Twitter/X account hack warnings — are effective at getting users to at least click, even when they know better. The speaker then describes a specific phishing scenario where users receive emails claiming there is a critical security update for VLC, directing them to a convincing fake website where they unknowingly download a malicious version. The victim remains unaware for potentially months, becoming part of a botnet. The conversation concludes with a strong recommendation to always verify the legitimacy of software download sources.
Key Insights
- Chinese hackers targeting Indian users did not distribute a fake version of VLC itself — they extracted only the legitimately signed DLL and used it within a separate malicious program that redirected calls to a fake libVLC, making the attack harder to attribute and detect.
- A fake VLC website in Germany has been actively distributing malware for over 12 years, and Google has knowingly declined to act because the malicious binary is too large for their virus analysis tools to process.
- The fake VLC installer in Germany is deliberately engineered to remain completely inactive for three weeks after installation, a specific strategy to defeat behavior-based malware detection systems before deploying spyware and adware.
- One of the payloads delivered by the fake VLC malware replaces ads inside the victim's machine, suggesting a financially motivated operation beyond simple data theft.
- A phishing campaign specifically impersonates VLC security update notifications, directing users to convincing fake websites where they unknowingly install a malicious version, leaving them as part of a botnet with no awareness of the compromise.
Topics
Transcript
[0:02] We had exactly the same problem with Chinese hackers that were targeting Indian people and that got VC banned from India until I had to to fight in courts in India, the Indian government to unban VC. They didn't use VC. They took just one DLL because we signed the DLL correctly. Um and they use that DLL to do another program. Uh so you had a VC.exe and was calling lib VLC but it [0:33] was calling it into a fake one and they use that to to target. Um there is not much we can do actually to to to block those type of hacks. >> Yeah. And I think people should for all open source software…
Full transcript available for MurmurCast members
Sign Up to AccessMore from Lex Clips
Mental illness in women vs men | Andrew Scull and Lex Fridman
Andrew Scull discusses how psychiatric treatments like ECT, lobotomy, and forced treatments were disproportionately applied to women rather than men throughout the 20th century, while men received different diagnoses like personality disorders. He notes that cultural representations, particularly films, significantly influenced public perception and clinical adoption of these treatments.
What causes mental illness? | Andrew Scull and Lex Fridman
Andrew Scull discusses how psychiatry has shifted from a psychologically-focused field to one dominated by neurobiology and brain disease models since the 1990s, resulting in lost insights despite scientific gains. He argues this oversimplification misses the complexity of mental illness, which involves brain biology, psychology, social factors, and environmental influences all interacting together.
John Nash's schizophrenia (A Beautiful Mind) - failed horrific treatments | Andrew Scull
Andrew Scull discusses the history of failed psychiatric treatments for schizophrenia in the 20th century, including insulin coma therapy, Cardiazol-induced seizures, and the path toward electroconvulsive therapy. He uses John Nash as a case example and explains how these brutal treatments were widely adopted despite lacking scientific validation and causing significant harm.
Fraud in psychiatry - The Rosenhan Experiment | Andrew Scull and Lex Fridman
Andrew Scull discusses how the Rosenhan experiment exposed unreliability in psychiatric diagnosis, leading to the DSM-III's symptom-checklist approach. While this created diagnostic consistency, it remained based only on symptoms rather than underlying biological causes, and despite $20 billion in research funding, treatment outcomes for the mentally ill have not improved.
Does electroshock therapy (ECT) actually work? | Andrew Scull and Lex Fridman
Andrew Scull discusses the controversial history and modern evidence for electroconvulsive therapy (ECT), acknowledging both its documented abuses in the mid-20th century and credible contemporary reports of life-saving outcomes for treatment-resistant depression. He emphasizes that while ECT's mechanism remains unknown, recent controlled trials provide sufficient evidence that it cannot be simply dismissed as a failed treatment.