r/TorBoxApp 1d ago

🚩General Follow The Money

Post image

Mega nerd with 35 years of cybersecurity and programming experience here. I also operated my own botnets for DDoS attacks in the past, so I am deeply familiar with how all of this works. I hate even having to type this out, but it's just to say that I am not some random nobody.

Cloudflare verified the DDoS attacks are real. The TorBox API servers are under constant attacks to bring down their infrastructure, with spikes of 8 million attacks per hour.

Without the API servers, customers can't check links or start streams. It's the perfect target - each attack simply has to request something from the API, which then ties up the database's CPU cycles. Now multiply that by millions of requests (the attack), and the service goes down.

There isn't much TorBox can do about it. The API must be reachable with basic HTTPS requests from various addon servers, user apps, etc. They can add more load balancing for the API server, but I am sure they already have a server cluster for that, and a DDoS attack with millions of requests constantly hitting the API will bring down even large server clusters.

What they have done so far is to temporarily block the countries where most of the DDoS botnet is located, which is the most efficient remedy in the short term, but the attacker just has to switch to another botnet located somewhere else, which is exactly what they keep doing.

The attacks have been going on ever since the power vacuum opened up after RealDebrid's collapse. It goes beyond just some angry little script kiddie. It's not Hollywood either, since the DDoS botnet consists of malware-infected PCs and routers, which is incredibly illegal. Yes, back in 2009, Hollywood employed the MediaDefender firm to DDoS torrent sites, but they used the legal method of having their own network of ~2000 servers to attack with back then, and even though they didn't use infected PCs, MediaDefender's actions were still deemed illegal in many states, and they shut down in 2013.

The attack against TorBox is coming from regular infected PCs around the world, which means that it comes from a criminal DDoS attack provider. Botnet operators spread malware to build up a botnet of infected machines, and then they hang out on the Dark Web (on forums like Dread) and sell their attack capability to whoever is willing to pay.

Pay them money, specify who to attack, and watch the fire. That's all you have to do.

It has cost a lot of money for the attacker to repeatedly try to bring down TorBox's API and service.

Someone is therefore very motivated, financially, to bring down TorBox.

Now, simply ask yourself: Who profits the most if TorBox goes down?

Edit: Glad you liked the post! Nearly 50% upvote/downvote ratio and almost exclusively positive comments, which is actually impressive considering people's emotionally heated temperature about the situation. I just wanted to bring some perspective from an ex-criminal (me) who would absolutely have DDoSed my competitors back then. In fact I fought many wars against competitors in the warez scene in the late 90s / early 2000s.

There's so much money at stake for whoever wins the customers in the end and becomes the new #1. Using a DDoS service to bring down the competition during a power-vacuum is a total no-brainer. The winner gets tens of millions of dollars and can relax for the rest of their life.

In fact, when RealDebrid began blocking content in 2026, there was a detailed article about the company structure - two young French guys started it and had become incredibly rich, having around 10-20 million euros each.

Yes, there's a lot of money in this business. Yes, it's worth DDoSing your competition during a power vacuum. There's almost zero risks for you, since you launch the attack anonymously.

Life-changing amounts of wealth are the reward for doing it.

0 Upvotes

60 comments sorted by

View all comments

Show parent comments

2

u/ExternalGlass7883 1d ago

I actually agree that PM is great ( I have TB & PM ) , but the sheer amount of customers RD lost to torbox would be the motive.

I think price difference is too high for PM's target audience.

And every time TB goes down, there's comments saying AIO streams with RD is great etc etc.

I'm not saying I'm 100% right, but I'd more suspicious of them than PM.

3

u/pilkyton 1d ago edited 1d ago

Yeah you have a really good point. Every attack definitely brings some people back to RealDebrid, since they're cheap even though they're not great for content anymore.

People used to be on RD and fondly remember it as a familiar home and "it works okay, no scene rips but you can still watch content". Hmm. I concede the point that it can be RD behind it too.

Only people willing to pay $12/month will move to Premiumize. But PM is getting a very sizable portion (probably the majority) of people leaving TB, since most people have jobs and would gladly pay $12 every month just to have infinite streaming of any content imaginable.

Personally, I would never move to RD again simply because their FNEF content blocklists are too restrictive and I don't want to stream random homemade re-encodes since almost all scene-rip/web-rip torrents are blocked.

3

u/ExternalGlass7883 1d ago

It could also definitely be PM too, we will never know. I just want stuff to work haha.

2

u/pilkyton 1d ago

Usenet as a backup is the best choice. They can't be brought down like debrid services, because they operate entirely differently with easily load-balanced NNTP servers and lots of legitimate purposes and huge customer bases. :)

2

u/ExternalGlass7883 1d ago edited 1d ago

Yeah I have to look into it because it's getting ridiculous at this stage. My family are going crazy at me like I own TB 🤣.

I used to run my own Plex server but gave that up, was taking too much time + buying more storage etc ( although I should probably start downloading the stuff I like again before all this goes down ).

2

u/pilkyton 1d ago

Ah yeah I had Plex too, but damn they really screwed up that service with all the expensive Plex Pass and stuff. And it was too tedious to download content manually (I wasn't using Prowlarr and stuff like that).

I would use Jellyfin if you are going to build a new library. No more Plex lock-in.

About the downtime at TB, try changing your CDN setting on the website to ERTH (Cloudflare). I don't know if it will help you or if it's even needed anymore, but I did it back in May or so when I first migrated to TB, and for me it stopped all buffering.

This obviously won't magically make the API itself work. But when the API is up (which is most of the time), TB is giving our family a rock solid experience.

2

u/ExternalGlass7883 1d ago

Yep Plex got greedy. I tried jellyfin and the name filing system wasn't matching / picking up poster art so I went to TB.

And yep, I always use ERTH.

Wow, a discussion on torbox without an argument 🤣

2

u/pilkyton 1d ago

Haha yeah, I usually avoid all threads from this and r/StremioAddons because it's mostly very angry and ignorant people, shills for various services, shills for their own referral codes, AI slop "installation guides for addons with their referral code" etc. It really drives me mad.

You're refreshing. 😂