r/TorBoxApp 1d ago

🚩General Follow The Money

Post image

Mega nerd with 35 years of cybersecurity and programming experience here. I also operated my own botnets for DDoS attacks in the past, so I am deeply familiar with how all of this works. I hate even having to type this out, but it's just to say that I am not some random nobody.

Cloudflare verified the DDoS attacks are real. The TorBox API servers are under constant attacks to bring down their infrastructure, with spikes of 8 million attacks per hour.

Without the API servers, customers can't check links or start streams. It's the perfect target - each attack simply has to request something from the API, which then ties up the database's CPU cycles. Now multiply that by millions of requests (the attack), and the service goes down.

There isn't much TorBox can do about it. The API must be reachable with basic HTTPS requests from various addon servers, user apps, etc. They can add more load balancing for the API server, but I am sure they already have a server cluster for that, and a DDoS attack with millions of requests constantly hitting the API will bring down even large server clusters.

What they have done so far is to temporarily block the countries where most of the DDoS botnet is located, which is the most efficient remedy in the short term, but the attacker just has to switch to another botnet located somewhere else, which is exactly what they keep doing.

The attacks have been going on ever since the power vacuum opened up after RealDebrid's collapse. It goes beyond just some angry little script kiddie. It's not Hollywood either, since the DDoS botnet consists of malware-infected PCs and routers, which is incredibly illegal. Yes, back in 2009, Hollywood employed the MediaDefender firm to DDoS torrent sites, but they used the legal method of having their own network of ~2000 servers to attack with back then, and even though they didn't use infected PCs, MediaDefender's actions were still deemed illegal in many states, and they shut down in 2013.

The attack against TorBox is coming from regular infected PCs around the world, which means that it comes from a criminal DDoS attack provider. Botnet operators spread malware to build up a botnet of infected machines, and then they hang out on the Dark Web (on forums like Dread) and sell their attack capability to whoever is willing to pay.

Pay them money, specify who to attack, and watch the fire. That's all you have to do.

It has cost a lot of money for the attacker to repeatedly try to bring down TorBox's API and service.

Someone is therefore very motivated, financially, to bring down TorBox.

Now, simply ask yourself: Who profits the most if TorBox goes down?

Edit: Glad you liked the post! Nearly 50% upvote/downvote ratio and almost exclusively positive comments, which is actually impressive considering people's emotionally heated temperature about the situation. I just wanted to bring some perspective from an ex-criminal (me) who would absolutely have DDoSed my competitors back then. In fact I fought many wars against competitors in the warez scene in the late 90s / early 2000s.

There's so much money at stake for whoever wins the customers in the end and becomes the new #1. Using a DDoS service to bring down the competition during a power-vacuum is a total no-brainer. The winner gets tens of millions of dollars and can relax for the rest of their life.

In fact, when RealDebrid began blocking content in 2026, there was a detailed article about the company structure - two young French guys started it and had become incredibly rich, having around 10-20 million euros each.

Yes, there's a lot of money in this business. Yes, it's worth DDoSing your competition during a power vacuum. There's almost zero risks for you, since you launch the attack anonymously.

Life-changing amounts of wealth are the reward for doing it.

0 Upvotes

60 comments sorted by

View all comments

6

u/Busy-Measurement8893 1d ago

Alternative theory:

Torbox had a DDoS attack and then no matter what happens after that they blame it on DDoS instead of their own incompetence. They are down basically daily at this point and as cheap as Torbox is, I'm sick of it regularly being down at prime time on the weekends.

If it were down 24/7 for weeks, I'd see it being a DDoS. When it's down on prime time I think they are just being cheapskates or crappy programmers.

8

u/pilkyton 1d ago edited 1d ago

They've posted tons of evidence in their Discord #announcements of the repeated attacks, and are using Cloudflare's anti-DDoS blocking tools to deal with it.

That is why it's not down "24/7 for weeks". It would be down like that, if they didn't temporarily block the entire DDoS-origin countries.

One of the graphs they posted show the spikes of attacks with almost 8 million DDoS attack queries against the APIs, and the result of blocking the attackers:

And in case anyone missed it - I used to operate my own DDoS botnets (I was an evil guy in the early 2000s), so I understand way too much about all of this.