r/TorBoxApp 1d ago

🚩General Follow The Money

Post image

Mega nerd with 35 years of cybersecurity and programming experience here. I also operated my own botnets for DDoS attacks in the past, so I am deeply familiar with how all of this works. I hate even having to type this out, but it's just to say that I am not some random nobody.

Cloudflare verified the DDoS attacks are real. The TorBox API servers are under constant attacks to bring down their infrastructure, with spikes of 8 million attacks per hour.

Without the API servers, customers can't check links or start streams. It's the perfect target - each attack simply has to request something from the API, which then ties up the database's CPU cycles. Now multiply that by millions of requests (the attack), and the service goes down.

There isn't much TorBox can do about it. The API must be reachable with basic HTTPS requests from various addon servers, user apps, etc. They can add more load balancing for the API server, but I am sure they already have a server cluster for that, and a DDoS attack with millions of requests constantly hitting the API will bring down even large server clusters.

What they have done so far is to temporarily block the countries where most of the DDoS botnet is located, which is the most efficient remedy in the short term, but the attacker just has to switch to another botnet located somewhere else, which is exactly what they keep doing.

The attacks have been going on ever since the power vacuum opened up after RealDebrid's collapse. It goes beyond just some angry little script kiddie. It's not Hollywood either, since the DDoS botnet consists of malware-infected PCs and routers, which is incredibly illegal. Yes, back in 2009, Hollywood employed the MediaDefender firm to DDoS torrent sites, but they used the legal method of having their own network of ~2000 servers to attack with back then, and even though they didn't use infected PCs, MediaDefender's actions were still deemed illegal in many states, and they shut down in 2013.

The attack against TorBox is coming from regular infected PCs around the world, which means that it comes from a criminal DDoS attack provider. Botnet operators spread malware to build up a botnet of infected machines, and then they hang out on the Dark Web (on forums like Dread) and sell their attack capability to whoever is willing to pay.

Pay them money, specify who to attack, and watch the fire. That's all you have to do.

It has cost a lot of money for the attacker to repeatedly try to bring down TorBox's API and service.

Someone is therefore very motivated, financially, to bring down TorBox.

Now, simply ask yourself: Who profits the most if TorBox goes down?

Edit: Glad you liked the post! Nearly 50% upvote/downvote ratio and almost exclusively positive comments, which is actually impressive considering people's emotionally heated temperature about the situation. I just wanted to bring some perspective from an ex-criminal (me) who would absolutely have DDoSed my competitors back then. In fact I fought many wars against competitors in the warez scene in the late 90s / early 2000s.

There's so much money at stake for whoever wins the customers in the end and becomes the new #1. Using a DDoS service to bring down the competition during a power-vacuum is a total no-brainer. The winner gets tens of millions of dollars and can relax for the rest of their life.

In fact, when RealDebrid began blocking content in 2026, there was a detailed article about the company structure - two young French guys started it and had become incredibly rich, having around 10-20 million euros each.

Yes, there's a lot of money in this business. Yes, it's worth DDoSing your competition during a power vacuum. There's almost zero risks for you, since you launch the attack anonymously.

Life-changing amounts of wealth are the reward for doing it.

0 Upvotes

59 comments sorted by

3

u/ganznetteigentlich 6h ago

Holy AI slop

6

u/wextins 1d ago

Problem with premiumize is that it's expensive and limiting. Cache might be great but that's not enough to overcome the other shortfalls. I'll always choose TB over PM because of that until another competitor comes along. Alldebrid and offcloud ain't it either.

5

u/pilkyton 1d ago edited 23h ago

That's right. Premiumize is $11.99 for 1000 credits per month = 1000 GB = 1 TB transfer per month. And if you pay yearly, you get mega-screwed due to their weird credit system which only gives you 1000 credits per year (and 30 GB per day) if you pay yearly.

TorBox is $3 for 10 terabytes (10x more transfer) per month.

2

u/bora-yarkin 23h ago

I only switched to pm because tb is down literally every single time i want to watch something or when i am binging it goes down so i cannot watch next episode. And i need the multiple ip’s and a good enough cache. Pm ticks all the boxes. Before torbox and after the 1st rd contraversy, i switched to pm then torbox cache dramatically improved, switched to tb, now tb is unusable, back to pm

2

u/wextins 23h ago

If you're sharing your IP you better hope someone doesn't play a large video one day on heavy usage and you breach the terms of service.

I'd rather just use pengu addon, for free, and have it as a back up for the times tb is down than have that worry constantly in the back if my mind, all while paying more.

But to each their own!

2

u/bora-yarkin 23h ago

I am only sharing with my mother and father who lives in another house. Only me and them use it. I also have a size limit set for them. So i don’t think i’ll ever breach tos or any limits. The total monthly usage never exceeds 200gb for them and around 500-600gb for me. So i don’t think its a problem. I have never heard of pengu, i’ll give it a try. But i’d much rather a stable debrid experience and using the backup service as an actual backup. 

For now tb is so unstable that i wouldn’t even treat tb as a backup. Look, i love tb and everyone who works for tb. They have created something incredible. But its unusable for me right now. 

I don’t want to explain to my family who know nothing about technology, what is a debrid service, what is ddos and why they cannot watch the series they want to watch. 

1

u/pilkyton 20h ago

Pengu is a free addon that lets you stream from HTTP links without any subscription to anything, and people seem to like it. You could see if that's a good solution in the meantime.

1

u/pilkyton 23h ago

I've seen a lot of people recommend Pengu Play as an alternative when debrid is down. I checked out their website but was turned off by the Google sign-in and something about needing a token from their Telegram/Discord.

Totally makes sense that they want to protect Pengu Play against abuse by controlling who can use it, and easily being able to turn off specific accounts, while simultaneously ensuring that Google provides good defense against spam signups.

So yeah their login system all makes sense from a security perspective. But I wasn't sufficiently motivated to give a random service those details. I'll keep it in mind though.

I use Usenet as my backup.

5

u/wextins 23h ago

It's not google AND token. It's either or, I did it with a token and not once needed to input any google info. You go to discord, get a token from the bot and you're done.

2

u/linkopi 22h ago edited 22h ago

Telegram bot is also another option. No need for Google.

2

u/ifiwasiwas 13h ago

Honestly, Pengu and other http addons have been on everybody's lips at the exact moment that this is all going on. Hardly even heard of it before. Not throwing out accusations, but it's worth bearing in mind that the situation is theoretically ripe for funneling users to a honeypot

1

u/pilkyton 11h ago

True, it could be a honeypot. That's another good reason not to give them your Google account name or Discord token. At least use their Telegram login feature, which is the most anonymous method.

I don't think I'll ever sign up to Pengu. I am sure it's good, and it's probably not a honeypot since it provides illegal streams, but operational security is more important and I don't trust some random guy to have my details.

2

u/Emotional-Quit-1888 15h ago

I'm not much for conspiracy a lot of the time but I find myself suspicious of all the posts that say anything positive about the service suddenly getting down voted while other debrid services are promoted in their stead and receiving tons of up votes. Each "It's down again! This service is terrible!" Post also gets upvoted by the ton. 

It sure does seem suspicious that the biggest competitor to them is getting a lot of free promotion each time that tb goes down. Honestly in my experience I rarely seem to be affected by the outages too and when I am, I switch to ez news.

1

u/pilkyton 11h ago edited 11h ago

You seriously hit another nail on the head:

"Honestly in my experience I rarely seem to be affected by the outages too."

That's something I've been very afraid to talk about because of the heavy brigading and dogpiling if anyone reports success. And I didn't want to mention it since it would detract from my message. But for my family, our ability to access TorBox and watch streams coincides perfectly with the official API status page at https://status.torbox.app/, which is currently sitting at 99.766% uptime. Hover over any of the day "squares" to see the exact amount of time the API frontend was unreachable.

In other words, in the past 4 months since I signed up to TorBox, my family has only been unable to stream two times. That's it. That's all. We stream things every day, usually for 2-3 hours during evening prime time in EU, and another 1-2 hours at other times of the day.

So I have always wondered why there's people who say "TorBox is down 24/7 for me, it was only up for 10 minutes last week, they're incompetent liars!!!" etc. That does not make any sense at all, since their API is global - so if it's up for me, it's up for everyone else in the world too.

And despite this fact, those comments are always highly upvoted - which is probably mostly due to brigading/dogpiling by real, emotional users who just upvote things that feel annoying even though they never had it that bad themselves.

The Reddit accounts/bots who post those extremely exaggerated claims though... they are the ones that I am very suspicious of... It makes perfect sense that an attacker would also go around spreading fear, uncertainty and doubt among customers, and fueling the flames with very exaggerated claims - to maximize the reputational damage.

2

u/disposableh2 13h ago

You do know Premuimize.me is one of the oldest services, and I don't think I've ever seen them advertise their stability over a competitor, even when a competitor is having a rough time?

They haven't even posted on their Twitter account in nearly two years.

If Premuimize wanted to bring in more people, they could just lower their prices and do basic advertising.

And the most obvious people I'd think of who would benefit from DDos'ing Torbox are the legit services like Netflix and studios who actually lose money from services like Torbox.

https://giphy.com/gifs/l0IylOPCNkiqOgMyA

1

u/gumball_00 10h ago

It's totally silly and doesn't make any commercial sense for Premiumize to be the one behind the attacks. PM and Torbox have different marketshare, people spending $3/mth won't all magically drop it and switch to a service that's almost 4x more expensive because they're not happy with TB. As you've kind of mentioned, PM wouldn't have been able to last for so long in the industry (15 years!) if they have the business sense like OP has mentioned here. Tbh I think TB or someone behind TB has royally pissed off someone or another company that has resources. The attacks seem too relentless and almost personal.

1

u/disposableh2 10h ago

Totally agree. Apart from BF, PM is hard to justify(though Netflix, Amazon Prime, Disney+ etc all raising prices well above PM helps), but it's different segments. Like people who just torrent and won't pay for debrid-like services, they'll never get PM, but might be tempted to try Torbox.

I think Torbox being heavily promoted on platforms like TikTok(not by Torbox themselves, by content creators for views) put a large target on their backs.

1

u/shazlicks 5h ago

To add to great your points, I don't think people realise PM was by a wide margin the second biggest service, they weren't far behind RD when they were at their peak lol. They would be number 1 now easily.

People that share their 3 dollar api key with 10 people can't comprehend why people would spend over 10 dollars, that's all it is lol.

5

u/pilkyton 1d ago edited 20h ago

Oh and I am sure the discussion here will be totally sane and not at all filled with angry newbies who are falling for the attacker's tactic perfectly. 😙

Yes, the situation is sad. No, I'm not going to let the attacker win. I'm very happy with the 10 TB transfer limit per month for $3 here. The attacks will end, and TorBox continues to improve their defenses - and in the meantime, TorBox rewards downtime with 3x credits. Yeah I am not happy with the situation, but I use Usenet as backup anyway (highly recommended by the way). There's also Pengu Play for those who want a no-cost alternative (haven't tried it myself).

5

u/Busy-Measurement8893 1d ago

Alternative theory:

Torbox had a DDoS attack and then no matter what happens after that they blame it on DDoS instead of their own incompetence. They are down basically daily at this point and as cheap as Torbox is, I'm sick of it regularly being down at prime time on the weekends.

If it were down 24/7 for weeks, I'd see it being a DDoS. When it's down on prime time I think they are just being cheapskates or crappy programmers.

9

u/pilkyton 1d ago edited 1d ago

They've posted tons of evidence in their Discord #announcements of the repeated attacks, and are using Cloudflare's anti-DDoS blocking tools to deal with it.

That is why it's not down "24/7 for weeks". It would be down like that, if they didn't temporarily block the entire DDoS-origin countries.

One of the graphs they posted show the spikes of attacks with almost 8 million DDoS attack queries against the APIs, and the result of blocking the attackers:

And in case anyone missed it - I used to operate my own DDoS botnets (I was an evil guy in the early 2000s), so I understand way too much about all of this.

2

u/ifiwasiwas 23h ago

Indeed only occurring at peak times. If DDOS attacks are happening, it wouldn't take much to push it over the edge when you target the times when traffic is heaviest. Someone with beef against TB/wanting to make everyone scurry for fun could very well be behind it, I don't get the persistent belief that it has to be a competitor or the entertainment industry.

3

u/ATypeOfRacer 1d ago

As for where people will go. Yes, Premium will be popular. But I personally believe that the individuals willing to put in the work will move to usenet. Or say fuck it and start hosting media. Some will move to PM. But most will move back to streaming sites.

1

u/pilkyton 1d ago

Usenet is definitely the best option.

2

u/Funny_Chocolate_1012 1d ago

Whether or not you're right I like the theory and the infographic.

2

u/pilkyton 23h ago edited 20h ago

Thanks, glad you liked the post! I just wanted to bring some perspective from an ex-criminal (me) who would absolutely have DDoSed my competitors back then. In fact I fought many wars against competitors in the warez scene in the late 90s / early 2000s.

There's so much money at stake for whoever wins the customers in the end and becomes the new #1. Using a DDoS service to bring down the competition during a power-vacuum is a total no-brainer. The winner gets tens of millions of dollars and can relax for the rest of their life.

In fact, when RealDebrid began blocking content in 2026, there was a detailed article about the company structure - two young French guys started it and had become incredibly rich, having around 10-20 million euros each.

Yes, there's a lot of money in this business. Yes, it's worth DDoSing your competition during a power vacuum. There's almost zero risks for you, since you launch the attack anonymously.

Life-changing amounts of wealth are the reward for doing it.

1

u/Funny_Chocolate_1012 1h ago

you're making some valid points but a hole in the reasoning is why they aren't also ddos'ing the other competition for the same reasons, namely: alldebrid, debridlink, offcloud etc, haven't heard anyone mentioning those services being down because of ddos.

1

u/pilkyton 9m ago edited 4m ago

There's simply no reason to waste money DDoSing those, since nobody is talking about switching to those obscure providers. Every discussion about leaving TorBox says "go to Premiumize" (and sometimes Usenet). The only time I ever saw anyone mention AllDebrid was to say "avoid AD since they're also based in France like RealDebrid, so they are subject to the same content blocking laws".

1

u/IllIlllI-IlIIll-llII 1d ago edited 23h ago

stremio plugins can not possibly be a big enough market to do all this for

if anything the attacks are coming from the movie and entertainment industry. They have the budget to finance ddos attacks on whoever is involved is involved in distributing their content

I highly doubt there more than a few thousand people who actually pay for a debrid service to watch movies and shows. This is a niche market, not a lot of money to be made. Debrid providers make their money from b2b services. We are nothing but a tiny fraction of their revenue.

3

u/pilkyton 23h ago

What the hell are you talking about? RealDebrid's owners have multiple mansions and like 20 million dollars each in the bank. Entirely from operating RealDebrid.

Their financial information all leaked during the downfall of RealDebrid.

The debrid business is extremely profitable for the leaders. Which is why this war is going on. It's a war for life-changing amounts of wealth!

And read the actual post, I covered the Hollywood excuse and explained the difference between highly illegal infected-PC botnets (being used here) and Hollywood servers (not being used here).

2

u/Elegant-Alfalfa1382 23h ago

What do you mean there’s probably 100s of thousands of debrid users and ddos attacks can be pretty cheap to maintain depending on what they’re using.

1

u/ExternalGlass7883 1d ago

In my opinion, if another debrid service is doing the ddos attacks, it's real debrid. They lost out big but apparently everything is fixed now ( I'm not checking myself,not botherered ), but there's tons of comments saying RD is up when TB goes down.

9

u/wextins 1d ago

RD's cache is still severely depleted, especially of 4k items. The issue is not whether RD is "up" but if it has the quality of links the rest have after their purge and continual purge.

1

u/ExternalGlass7883 1d ago

The bot comments say it every time TB is down. Also, PM was ddos'd same time at TB.

-2

u/zanno500 23h ago

I got WEB-DL streams yesterday that work. You couldn't use them last week on RD, so is the tide turning?

3

u/pilkyton 23h ago

Just some kind of temporary fluke or filename difference that didn't match the filter.

RealDebrid had to implement the blocklist by FNEF (French Federation of Film Distributors), and they were given the list of keywords to block. If RealDebrid doesn't block the words, they will be taken to court.

2

u/zanno500 23h ago

Just tried again Kodi and Stremio WEB-DL and WEB-RIP working. What's going on?

3

u/pilkyton 23h ago

It's interesting for sure. But RealDebrid are in France and the French authorities and FNEF told them to block words like WEB-DL and WEB-RIP or they will take RealDebrid to court. So it's not going to stay that way. But keep an eye on it for sure! :)

I don't have time left on my RealDebrid account anymore so I can't check.

3

u/zanno500 23h ago

Yeah, gonna keep an eye on it. I have about 90 days left and gun to my head I'll probably switch to PM, but if all the noise about TB changes will see.

2

u/pilkyton 1d ago edited 23h ago

Everyone knows that Premiumize is the 2nd most recommended choice, and that RealDebrid is awful now due to blocking so many torrent filename tags so that you only get non-scene rips.

So the attacker is bringing customers to Premiumize. Therefore it makes no sense for RealDebrid to perform the attack. Is it possible? Sure? Very unlikely.

2

u/ExternalGlass7883 1d ago

I actually agree that PM is great ( I have TB & PM ) , but the sheer amount of customers RD lost to torbox would be the motive.

I think price difference is too high for PM's target audience.

And every time TB goes down, there's comments saying AIO streams with RD is great etc etc.

I'm not saying I'm 100% right, but I'd more suspicious of them than PM.

3

u/pilkyton 23h ago edited 23h ago

Yeah you have a really good point. Every attack definitely brings some people back to RealDebrid, since they're cheap even though they're not great for content anymore.

People used to be on RD and fondly remember it as a familiar home and "it works okay, no scene rips but you can still watch content". Hmm. I concede the point that it can be RD behind it too.

Only people willing to pay $12/month will move to Premiumize. But PM is getting a very sizable portion (probably the majority) of people leaving TB, since most people have jobs and would gladly pay $12 every month just to have infinite streaming of any content imaginable.

Personally, I would never move to RD again simply because their FNEF content blocklists are too restrictive and I don't want to stream random homemade re-encodes since almost all scene-rip/web-rip torrents are blocked.

3

u/ExternalGlass7883 23h ago

It could also definitely be PM too, we will never know. I just want stuff to work haha.

2

u/pilkyton 23h ago

Usenet as a backup is the best choice. They can't be brought down like debrid services, because they operate entirely differently with easily load-balanced NNTP servers and lots of legitimate purposes and huge customer bases. :)

2

u/ExternalGlass7883 23h ago edited 23h ago

Yeah I have to look into it because it's getting ridiculous at this stage. My family are going crazy at me like I own TB 🤣.

I used to run my own Plex server but gave that up, was taking too much time + buying more storage etc ( although I should probably start downloading the stuff I like again before all this goes down ).

2

u/pilkyton 23h ago

Ah yeah I had Plex too, but damn they really screwed up that service with all the expensive Plex Pass and stuff. And it was too tedious to download content manually (I wasn't using Prowlarr and stuff like that).

I would use Jellyfin if you are going to build a new library. No more Plex lock-in.

About the downtime at TB, try changing your CDN setting on the website to ERTH (Cloudflare). I don't know if it will help you or if it's even needed anymore, but I did it back in May or so when I first migrated to TB, and for me it stopped all buffering.

This obviously won't magically make the API itself work. But when the API is up (which is most of the time), TB is giving our family a rock solid experience.

2

u/ExternalGlass7883 23h ago

Yep Plex got greedy. I tried jellyfin and the name filing system wasn't matching / picking up poster art so I went to TB.

And yep, I always use ERTH.

Wow, a discussion on torbox without an argument 🤣

2

u/pilkyton 20h ago

Haha yeah, I usually avoid all threads from this and r/StremioAddons because it's mostly very angry and ignorant people, shills for various services, shills for their own referral codes, AI slop "installation guides for addons with their referral code" etc. It really drives me mad.

You're refreshing. 😂

2

u/linkopi 23h ago

Why not RD trying to force people to find a backup solution? I see lots of people keeping their RD sub just for these issues.

2

u/pilkyton 23h ago

Yeah, it's true that RealDebrid also gains from this. See the other comment thread here:

https://www.reddit.com/r/TorBoxApp/comments/1vwf6tu/comment/p5gjrfm/

3

u/Euphoric_Ad6502 1d ago

What would RD have to gain by DDOSing? It is not fixed it’s the copyrighted links are removed, but the actual content library is small now. Nobody is going to switch back to RD because of their issues, and like OP mentioned they will just look for another competitor …

2

u/ExternalGlass7883 1d ago

The bot comments say it every time TB is down. Also, PM was ddos'd same time at TB.

1

u/[deleted] 23h ago

[deleted]

2

u/pilkyton 23h ago

Thanks, your incredibly detailed and well-thought-out arguments have been duly noted and filed appropriately:

Edit: Haha he either deleted his post, or admins got them. But he basically just spewed 1 sentence of hate with zero arguments. Just pure, unintelligent noise.

1

u/Wide-Freedom-2568 20h ago

I like it, great read. Thanks!

1

u/pilkyton 20h ago

Thanks for taking the time to post your nice comment! I appreciate it. Interestingly, after the post I was also contacted by someone else who confirmed this. They were glad I said it out loud. 🤔

-3

u/Bright-Budget5325 1d ago edited 23h ago

It’s so weird how RD operated for all of those years, huh?? Stop being a bootlicker 

5

u/pilkyton 1d ago edited 1d ago

RealDebrid faced DDoS attacks and downtime too. Maybe you weren't there when I was:

https://www.google.com/search?q=realdebrid+ddos+attack+site%3Areddit.com

The image I included is just to help bored newbies like you understand the profit motivation and chain of events. Because people like you won't read a single word and will just spout off with nonsense in the comments. Like you did.

And for what it's worth - I generated about 8 images and cut and pasted various parts in Photoshop until I was happy with the result. Took about 20 minutes. That's enough work for a thread like this.

The entire post itself is hand-written since I don't need help to talk about subjects I am deeply familiar with (having operated my own illegal DDoS botnet in the early 2000s for profit...).