Monday, October 5, 2020

TorrentFreak's Latest News

 

US Criminal Prosecution Casts Doubt Over Team-Xecuter's Future
Ernesto Van der Sar, 05 Oct 09:50 PM

team xecuterHacking group Team-Xecuter has long been a thorn in the side of major gaming companies.

The group offers hardware and software solutions that allow people to install and play unofficial games – including pirated copies – on various consoles, including the popular Nintendo Switch.

Team-Xecuter often defended its work by pointing out that their products are not necessarily pirate tools. They are supporters of the 'right to repair' movement and back people who want to play homebrew games on their devices for personal use.

The affected game companies disagree, with Nintendo in front. The Japanese game company has been chasing down Team-Xecuter for years and a few months ago the company took several online stores to court for selling Team-Xecuter products. Last week, these enforcement efforts reached a new level when the US Government launched a criminal prosecution of three of the group's members.

Team-Xecuter's Future

Despite the criminal prosecution, Team-Xecuter's website remains online. Other services, which are allegedly operated by members of the same conspiracy, are up and running as well, including Axiogame.com and Maxconsole.com.

This doesn't mean that there are no issues at all. In recent days several people reported problems while activating their Team-Xecuter licenses. However, this problem appeared to be just temporary.

xecuter license

Following the news about the criminal prosecution, some third-party vendors removed associated products from their stores. That said, these remain available elsewhere and installation support is still available as well.

To find out more about their future plans, we reached out to Team-Xecuter over email. This message wasn't delivered due to a technical problem, suggesting that not everything is running completely smoothly at the moment.

What we do know is that there are more people involved in the group than just the three who were indicted. The others may be able to continue business as usual, or not. Since we can only speculate at the moment, we decided to focus on the US Government's allegations.

The Defendants

Over the past several days, we've combed through the legal paperwork of which we will provide an overview below. It has to be stressed that, at this point, all claims against the defendants have yet to be proven.

Max Louarn (48, France) aka MAXiMiLiEN, aka Julien Ambroise

The first defendant is Max Louarn, a 48-year-old French national who was arrested in Canada where he is being held in custody. Louarn is seen as the leader of Team-Xecuter. He made important business decisions, arranged investors and financing, and oversaw product development and the wholesale distribution chains.

Louarn is a familiar name in the game hacking scene and describes himself as an "officially retired hacking pioneer." His work reportedly dates back well into the last century when he was linked to the warez group PARADOX. In 1993 he was arrested in a Nintendo piracy case, after which he fled to Spain.

That was not his only run-in with the law. Two years later he was arrested in Washington for his involvement in a credit card fraud and was accused of reselling 3,000 stolen credit cards. This eventually led to a sentence of five years and eight months for the then 23-year-old.

In 2005, Louarn's name showed up again in federal court records, with Sony accusing him of operating Divineo, a company through which he sold modified Playstation devices and modchips. Sony eventually secured a judgment of more than $5 million in statutory damages against Lourn and Diveneo.

Yuanning Chen (35, China) aka Yuan Ning Chen, aka Velison Chen, aka 100+1, aka Jingui Chen

35-year-old Yuanning Chen from China is the only defendant who's still at large. According to the indictment, Chen was involved in the management of a manufacturing and distribution company where Team-Xecuter's hardware was made.

The company, "China Distribution," was labeled as the official wholesale distributor of several circumvention devices. In addition, Chen was also operating the Axiogame.com store, which remains online today.

Gary Bowser (51, Canada) aka GaryOPA

The third defendant, Gary Bowser, was arrested in the Dominican Republic last month and he has since been deported to the US. Bowser is allegedly responsible for the development of circumvention devices. He was also in regular contact with resellers.

Bowser is best known through his nickname GaryOPA, the supposed operator and a frequent writer on the website "MaxConsole," which regularly reviewed Team-Xecuter hardware and other hacking tools.

Team-Xecuter's "Fragmented Approach"

The indictment sees the Team-Xecuter conspiracy as a broad enterprise that included many sites, products, and organizations that are not publicly associated with the group. This is less efficient to manage but was used to isolate all parts from enforcement threats.

"The enterprise used this fragmented approach to protect the overall enterprise in the event that one device or brand were to be targeted by gaming companies, financial institutions, and law enforcement," the indictment reads.

This fragmented setup involved, among other things, various third-party developers and hackers, operating the distribution chain through a Chinese company, facilitating sales through Axiogames.com, and promoting the products through Maxconsole.com.

garyopa

To hide the identities of the people involved Team-Xecuter relied on reverse proxies and bulletproof hosting providers. In addition, communication channels were mostly encrypted, using PGP and apps such as Signal and Telegram for sensitive messages.

The indictment stresses that the success of the business relied on the availability of pirated games. To make sure that this was in order, they allegedly "created" and "supported" ROM sites, which were then highlighted on MaxConsole.

"Accordingly, the enterprise undertook efforts to create and support online ROM libraries that could be used by the enterprise's customers. The enterprise directed users to ROM libraries through the enterprise's website, maxconsole.com," the indictment reads.

Tapped Communications

Several claims in the indictment are backed up by internal communications from and between the defendants. How the US Government obtained this isn't clear, but it seems to confirm the various connections. For example, Louarn sent the following note to an alleged co-conspirator.

"You are always panicky about things and not taking time to analyze and see the big picture to make real money. First, obviously we know how to host. Just for sites you know we own, we have Maxconsole, Team-xecuter etc. which are 1000 times more traffic than your site ever had.

"Second, of course[,] Axiogame will be back up, it is already back but we have some issues which I am trying to understand. Axlogame has over 200 orders per day…"

Another email, sent by Louarn to Chen, goes into detail about payments requested by chip developers, asking Chen if it's possible to put up some pre-orders or pay them in another way.

Bowser, for his part, sent an email to a business partner detailing how he was responding to enforcement efforts by Nintendo.

"They have been trying hard to crack down on everything, removing 'roms' from various sites which devices like Classic2Magic need, but we have [a] plan in the works to have secure links to these retro rompacks on [a] protected server, so it will not be a problem."

Investigators Purchased Devices

The investigation into Team-Xecuter started years ago. The indictment mentions several occasions where investigators from the Western District of Washington bought devices that were trafficked by members of the conspiracy.

This includes the Team-Xecuter branded SX Lite, SX Core and SX Pro, all jailbreaking solutions for the Nintendo Switch. Investigators bought an SX Pro kit from an 'authorized' seller in July 2018, and several others later on, which they installed on separate Switch consoles.

Other devices, allegedly trafficked by the conspiracy, include the "Gateway 3DS" and the "Stargate" for the Nintendo 3DS, the "TrueBlue Mini" for the Playstation Classic, and the Classic2Magic, for Nintendo's SNES. Copies of these devices were all bought by investigators.

According to the allegations, the defendants were aware of the illegality of the devices. In order to frustrate enforcement efforts, they would use false merchandise descriptions, tariff classifications, and value descriptions.

For example, defendant Louarn advised his co-conspirator Chen to declare a shipment of circumvention devices as memory card adaptors, with a value of $0.20 each.

The Charges

While not all individual claims would be seen as criminal necessarily, the indictment argues that taken together, it clearly is a criminal conspiracy.

In total, the three defendants each face 11 felony counts, including conspiracy to commit wire fraud, wire fraud, conspiracy to circumvent technological measures and to traffic in circumvention devices, trafficking in circumvention devices, and conspiracy to commit money laundering.

If proven, these can lead to lengthy prison sentences. For now, however, all defendants are presumed innocent, until the opposite is proven in court.

A copy of the indictment, as released by the US Department of Justice, is available here (pdf)

From: TF, for the latest news on copyright battles, piracy and more.

Trump's Mar-a-Lago Website Linked to Pirate Site Offering Mulan
Andy Maxwell, 05 Oct 10:26 AM

In common with most weeks since his inauguration in January 2017, President Trump has been the subject of thousands of headlines this week but for reasons he would've preferred to avoid.

With the coronavirus pandemic continuing to grip the world, the President himself tested positive for COVID-19, sparking huge speculation over not just his personal health but what it might mean for the upcoming election, the United States, and the wider world.

The Mar-a-Lago Resort and Link to Notorious Pirate Site

Trump is well known for his business activities, including the Mar-a-Lago resort in Florida, which he bought back in 1985 for around $10m. Given the headlines this week, the website of the landmark has received additional attention, including from a Reddit user who goes by the name 'btodalee'.

He told TorrentFreak that after seeing Trump's latest "at-work" pictures, he decided to check out the official Mar-a-Lago website on Sunday but was surprised at what he found. On the very first page among all the gloss, he found a link to a site operating under one of the most notorious pirate streaming brands – 123Movies.

Mar-a-Lago

"Immediately I noticed what looked like a physical misprint on the left-middle area of the page, and upon hovering, realized it was a text hyperlink to a proxy site for 123 Movies," he told TF.

"After having a little chuckle, I went back to the website for more sleuthing. What I noticed next were the double text dividers used below the welcome text, a blatant design mistake, only the first text divider made up of microscopic dots was yet another text hyperlink to the same proxy site."

Without the eagle eyes of 'btodalee' this unusual addition to one of Trump's web assets would've probably gone unnoticed for some time. Indeed, one needs good eyesight to even spot it all. With that in mind, the image below does the work, zoomed in on the offending link in gold capital letters.

Mar-a-Lago 123movies

The inclusion of a link to a 123movies-branded portal on such a high-profile site connected to the President is bizarre, not to say somewhat of a mystery. So why was it there and what was its purpose?

Theories and Speculation

After posting his discovery on Reddit, btodalee says that a number of users chimed in with their theories and thoughts on what may have happened.

As confirmed by an archive copy of the Mar-a-Lago site on the Wayback Machine, for example, the link was not present on September 2020. That means that someone embedded the link during the last couple of weeks.

"Many others have speculated that this was likely an innocent copy-paste mistake by one website designer using a CMS (visual website editor) like Wix or Squarespace. Other more suspicious Redditors suggested this was an act of vandalism by 123 Movies themselves or an automated crawler targeting an SQL-injection vulnerability to raise traffic or bump up SEO ranking," btodalee told TF, summarizing the discussions.

123-Trump

The embarrassing nature of the blunder can't be understated. The 123movies brand has been around for some time but most notably a site using the same name was described as the world's most popular pirate site by the MPAA in 2018. It later shut down following a criminal investigation.

Since then, faceless third-parties have been happy to trade on the name with their own site variants but the aim is always the same – draw traffic to pirated copies of movies. Indeed, if any would-be customers of Mar-a-Lago had clicked on the link embedded in the resort's site, that's exactly what the would've found.

Along with hundreds and thousands of others, this 123movies variant offers the latest pirated content, including Disney's latest hit Mulan, for example.

Mulan 123movies

But even if some visitors did enjoy the unexpected treat of first-run movies following their virtual trip to Mar-a-Lago this weekend, they won't be enjoying them again if they return.

After checking just a few moments ago, the site is now back to its former glory, selling expensive dreams to the lucky few but minus the link to one of the world's most notorious pirate brands. Another thing off the President's mind, no doubt.

From: TF, for the latest news on copyright battles, piracy and more.

Top 10 Most Torrented Movies of The Week – 10/05/20
Ernesto Van der Sar, 05 Oct 09:14 AM

mulan movieThe data for our weekly download chart is estimated by TorrentFreak, and is for informational and educational reference only.

These torrent download statistics are meant to provide further insight into the piracy trends. All data are gathered from public resources.

This week we have four new entries in the list. Mulan regains the top spot as the most downloaded film this week. The Disney exclusive was released last month and surfaced on pirate sites soon after.

The most torrented movies for the week ending on October 05 are:

Movie Rank Rank last week Movie name IMDb Rating / Trailer
Most downloaded movies via torrent sites
1 (2) Mulan 5.7 / trailer
2 (1) Enola Holmes 6.7 / trailer
3 (…) 2067 4.7 / trailer
4 (…) American Pie Presents: Girls' Rules ?.? / trailer
5 (4) Ava 5.4 / trailer
6 (…) The Doorman ?.? / trailer
7 (3) Antebellum 5.5 / trailer
8 (7) Bill & Ted Face the Music 6.5 / trailer
9 (…) 12 Hour Shift 5.5 / trailer
10 (5) The Devil All The Time 7.2 / trailer

Note: We also publish an updating archive of all the list of weekly most torrented movies lists.

From: TF, for the latest news on copyright battles, piracy and more.

 
 
Powered by Mad Mimi®A GoDaddy® company

Sunday, October 4, 2020

TorrentFreak's Latest News

 

ACE TV, Firestick Plusman Repo, and Other Domains Seized By ACE / MPA
Andy Maxwell, 04 Oct 09:28 PM

ACE logoGlobal anti-piracy coalition Alliance for Creativity and Entertainment is forging ahead with its mission to sue, shut down, disrupt or otherwise hinder a broad range of unlicensed content providers or those who facilitate access.

For years, mass shutdowns and domain seizures were relatively uncommon but the Alliance, which is compromised of some of the most powerful entertainment companies in the world, is setting records as it goes, albeit largely in the shadows.

Closures and Domain 'Seizures'

Rather than taking the more expensive option of suing alleged copyright infringers, ACE regularly deploys its considerable muscle to intimidate opponents into submission. The tactic isn't popular with pirates but ACE picks its targets carefully and in the vast majority of cases, could easily win a court battle should it choose to pursue one.

Instead, pirate players of all shapes and sizes are given the option to settle with ACE, which can simply mean a promise to shut down or could involve additional elements such as handing over domains and/or paying a settlement sum. In the past few days and weeks, there has been no shortage of new domains being taken over.

Firestick Plusman / ACE TV

The Firestick Plusman (FSPM) name is well known in the piracy community, with connections to various Kodi add-ons, IPTV, Android APKs, and for providing storage facilities so they can be accessed and installed by users.

Earlier this year, disruption was apparent when Fspmkodi.com, a repository of software associated with various forms of streaming-related piracy (Kodi add-on 'Fantastic', for example), suddenly went down, taking access to some of the software listed below with it.

FSPMKodi

Aside from the usual rumors that the shutdown was forced, no official confirmation was available to the wider public at the time. This week, however, the domain utilized by the popular repository was transferred into the hands of the MPA. This usually happens when a domain/service owner receives a cease-and-desist settlement offer from ACE members and takes the option to shut up shop rather than face a lawsuit.

At the same time, three other domains connected to FSPM also suffered the same fate. Acetv.online, acehostingservice.com, and acetvpremium.com, which were all connected to the provision of pirate IPTV services, are now operated by the MPA and currently divert to the ACE anti-piracy portal when accessed by visitors.

Sundry Other Domains Also Diverting to ACE

As reported by TF in September, ACE also managed to close down IPTV provider Streams For Us, apparently taking other IPTV brands with it, including one called Nue Media.

We can now confirm that Nue Media was one of the targets as its domain neumediatv.net is now in the hands of the MPA and also diverts to the ACE anti-piracy portal. The same goes for loveyour.tv, a domain previously used by Streams For Us.

Also confirmed last month were the problems being faced by IPTV provider The Players Klub (TPK). We managed to identify several domains that had been seized by ACE, including MintPanel.net, MintPanel.co and MintPanel.digital.

We can now add several other TPK domains to the list including thepk.co, tkotv.stream, and tpkshield.net, all of which display the now-familiar anti-piracy warning.

Finally, we don't know much about Elitestreamtv.com or Cosmostv.ca, other than they were involved in the supply of unlicensed IPTV services. What we can be sure of, however, is that ACE members got to their operators and forced them to hand over their domains to the MPA, thus adding to the growing list of platforms that disappear into the night following threats from the world's largest entertainment companies.

From: TF, for the latest news on copyright battles, piracy and more.

EU Allows Accused 'Pirate' Sites to Rebut Copyright Holder Claims
Ernesto Van der Sar, 04 Oct 12:46 PM

EU CopyrightFollowing the example of the United States, the EU started publishing its very own piracy watchlist two years ago.

The annual 'Counterfeit and Piracy Watch List' is put together by the European Commission. As in the US, it is based on reports from copyright holder groups that report several problematic sites and services.

For example, the first watch list included 'non-EU' targets such as The Pirate Bay, Torrentz2, Rapidgator, Uploaded, Sci-Hub, and H2converter. In addition, some third-party intermediaries such as Cloudflare were called out as well.

EU's 2020 Piracy Watchlist

The European Commission is currently working on its 2020 watchlist and has already completed the public consultation. This resulted in a list of sites and services which are now being vetted for publication.

"This list will again identify and describe the most problematic marketplaces […] in order to encourage their operators and owners as well as the responsible local authorities and governments to take the necessary actions and measures to reduce the availability of IPR infringing goods or services," the Commission writes.

A common critique with this type of watchlist is that they are often based on one-sided input. The 'piracy' and 'copyright infringement' claims come from copyright holders and are often repeated before hearing from the accused party.

EU Commission Consults Accused Sites

The European Commission breaks with this tradition. It has recently contacted several accused parties, allowing them to have their say. TorrentFreak spoke to the operator of a torrent site who, on the condition of anonymity, agreed to share the letter he received from the Commission.

"We contact you because the website you operate was one of the reported marketplaces," the letter starts.

"According to the stakeholders, [redacted] is reportedly a popular BitTorrent website hosted in [redacted] facilitating access to a wide range of content, including music, films, TV programmes, software and videogames."

The Commission acknowledges that the targeted site responds to takedown notices, but copyright holders report that infringing material is usually quickly reposted. In addition, the site reportedly generates income from ad revenue and pay-per-install links that could link to malware.

Based on these third-party reports, the EU Commission is inclined to add the site to the forthcoming piracy watch list. However, it allows the site operator to have his say as well.

"Based on the public consultation, we are considering including the name of the site you operate in the next edition of the Watch List. We would like to give you the opportunity to express your views concerning the above-mentioned allegations reported by stakeholders and to send us your comments."

Proper Verification is Welcome

The site operator we spoke with isn't sure whether he is going to reply. However, it is laudable that targeted sites are allowed to chime in before the list is published.

It's not entirely clear what constitutes a 'pirate' site in the eyes of the EU Commission. The letter suggests that simply taking down reported files isn't good enough as they will simply reappear. However, that same logic applies to many sites and services, including YouTube.

When the European Commission announced its most recent consultation earlier this year it said that all information received will be thoroughly verified. This is crucial, as its first report wasn't free of errors, and included a perfectly legitimate site.

From: TF, for the latest news on copyright battles, piracy and more.

 
 
Powered by Mad Mimi®A GoDaddy® company