vDOS▊
For four years, if a website you cared about suddenly could not stay online, there was roughly a coin-flip's chance the flood came through two teenagers in Israel. vDOS was the biggest attack-for-hire service on the planet — more than 150,000 attacks coordinated, over $618,000 booked, 8.81 years of attack traffic crammed into a single four-month stretch — run out of a bedroom by a pair who thought they were untouchable because they were smart enough to blacklist their own country. Then someone did to vDOS exactly what vDOS sold: they broke in. The whole customer database landed in Brian Krebs's inbox, the pair were arrested within hours, and the service's parting gift was to knock Krebs's own site off the internet with a 140-gigabit tantrum spelled out, packet by packet, as an insult. It was the flood that finally pushed Krebs into the path of Mirai.
Every single IP that’s hosted in israel is blacklisted for safety reason.
A vDOS support-ticket reply signed “AppleJ4ck,” from the leaked vDOS database — the operators sold the rest of the world outages while quietly walling off their own country, “so as to not attract unwanted attention… from Israeli authorities.” KrebsOnSecurity, September 2016
- WHO
- vDOS — a DDoS-for-hire (“booter”/“stresser”) service, Sept 2012–mid-2016; by the leaked records, the largest and longest-running such service on earth FACT
- OPERATORS
- Yarden “applej4ck” Bidani and Itay “p1st” Huri (also “P1st0,” “M30w”) — two Israelis, 18 at arrest, marketing on Hackforums; support from several young hackers in the U.S. FACT
- THE DRAMA
- A $618,000+ empire, 150,000+ coordinated attacks (2M+ over four years), hacked itself via a sister service, its customer database handed to Brian Krebs — arrests within hours, then a ~140 Gbps retaliation strike on KrebsOnSecurity
- RECORD
- Charged in Israel, Aug 2017; sentenced June 2020 to six months’ community service each, plus 25,000 NIS fines and probation. Roughly $600,000 seized. Lightest available sentence — they were minors during most of it FACT
- STATUS
- SEIZED — the service dead, the money gone, the operators cautionary tales; the retaliation attack a footnote in the story of Mirai
This file is not an accusation; the accusations were made by the FBI and Israeli prosecutors, and the central ones stuck. It is a record of what a booter empire actually was underneath the “stress-testing” sales copy: a subscription business that put point-and-click outages in the hands of anyone with a PayPal account, that laundered its own proceeds through round-robin accounts because it knew what it was, and that walled off Israeli targets so its home country would have no victim with standing to complain. The through-line is the gap between the self-image — teenage kingpins, untouchable, providing a legitimate service — and the paperwork: a leaked database, an arrest within hours, and a petty flood aimed at the reporter who published it.
the drama timeline
ACT I — THE EMPIRE (SEPT 2012–JULY 2016)
Two teenagers build the biggest attack-for-hire service on the internet, run it like a real company with a real support desk, and make one telling exception to their price list.
-
SEPT 2012
The service comes online
vDOS launches and, over the next four years, grows into what leaked records show is the longest-running and most profitable booter advertised on Hackforums. Customers buy subscriptions priced by attack duration and simultaneity — tiers from $20 to $200 a month. By effect, the product is simple: point it at a website you want offline, and it goes offline. Krebs's later verdict on the scale: in just four months of 2016 the service launched 277 million seconds of attack time — about 8.81 years' worth.
-
2014–16
$618,000, and a laundry
Leaked payment logs document more than $618,000 booked since July 2014 via Bitcoin and PayPal — likely north of $1 million counting the pre-2014 years the operators erased. To keep PayPal from shuttering their accounts, they recruited Hackforums members to launder the take. “The paypals that the money are sent from are not verified,” AppleJ4ck wrote in one recruitment thread. “Most of the payments will be 200$-300$ each and I’ll do around 2-3 payments per day.” A business that goes to that length to hide its cash flow, one researcher noted, is not confused about what it is.
-
2015
The home-turf exemption
Customers kept filing support tickets complaining they couldn't attack Israeli sites. The answers, preserved in the leak, gave the operators away years before their names did: “All Israeli IP ranges have been blacklisted due to security reasons.” “I’m actually from Israel, and decided to blacklist all of them. It’s my home country, and don’t want something to happen to them.” A global outage machine with a conscientious objection to its own postcode.
ACT II — THE HACK (JULY 2016)
The service that sold breaking things gets broken. Not by a rival — by a researcher pulling one loose thread on a sister service.
-
JULY 2016
One thread, the whole sweater
A source poking at a vulnerability in a similar service, PoodleStresser, found its attack servers pointed back at vDOS — because PoodleStresser and a crowd of other booters were quietly running on vDOS's firepower. From there the source exploited a deeper hole in vDOS itself and dumped all of the service's databases and configuration files: customer records, attack logs, the SMS and email keys, and the true address of the rented Bulgarian servers hidden behind Cloudflare. The whole empire, in a download. Krebs obtained the database at the end of July 2016.
-
JULY 2016
The paper trail home
The leak read like a confession. vDOS admins used email accounts on v-email[dot]org, a domain registered to an Itay Huri with an Israeli phone number. Support requests blasted SMS alerts via Nexmo to six admin phones; two were Israeli — one Huri's, the other belonging to Yarden Bidani. Bidani's own Facebook messages discussed DDoS work under the handle AppleJ4ck. The pair had even co-authored a DDoS technical paper for an Israeli security journal that August — Huri under his real name, noting his coming army draft.
ACT III — THE EXPOSÉ AND THE RETALIATION (SEPT 2016)
The story goes up, the handcuffs come out the same day, and vDOS's answer is to point its firepower at the man who published — the flood that pushed Krebs into the Mirai chapter.
-
SEPT 8, 2016
Story up, kingpins down
Krebs published the exposé; around the same time, acting on an FBI investigation, Israeli authorities arrested Itay Huri and Yarden Bidani, both 18. Released the next day on roughly $10,000 bond each, they had their passports seized, were put under ten days' house arrest, and were banned from the internet and telecoms for 30 days. The untouchables lasted one news cycle.
-
SEPT 9, 2016
“freeapplej4ck”
The day after the arrests, KrebsOnSecurity was hit with a nearly 140 Gbps DDoS — the message spelled out in the attack packets themselves as an insult, and later floods carrying the string “freeapplej4ck.” The service exposed for selling revenge outages had just aimed one, personally, at the reporter. Akamai's Prolexic protection, provided pro bono, held — for now.
-
SEPT 20–25, 2016
620 Gbps, and off the map
Within days the attacks escalated into a then-record ~620 Gbps flood — powered not by rented servers but by a botnet of hacked IoT devices, routers and cameras and DVRs. It was too big to absorb for free: Akamai gave Krebs about two hours to get off their network before it threatened paying customers. The site went dark, then came back under Google's Project Shield. The botnet behind the record flood soon had a name the whole industry would learn: Mirai — the same IoT swarm that, weeks later, would help take down Dyn and a chunk of the American internet. (The story of Mirai's own teenage authors — Paras Jha and the booter wars that spawned it — is its own file.)
ACT IV — THE BILL (2017–2020)
The largest booter on earth, its two owners, and the sentence the record actually produced.
-
AUG 2017
Formally charged
Israeli prosecutors formally charged Bidani and Huri, then 19, with conspiracy to commit a felony, prohibited activities, disrupting a computer, and disseminating false information. Prosecutors said vDOS had facilitated more than two million DDoS attacks over its four years and, at its mid-2015 peak, pulled $42,000 a month. The defense line: vDOS was a legitimate “stresser” for companies testing their own resilience — the same argument the leaked customer logs, full of third-party business targets, did not support.
-
JUNE 2020
Six months of community service
An Israeli court handed each man six months' community service, a 25,000 NIS fine, and probation — the lightest sentence available against a two-year maximum, because both were minors during the bulk of the offenses. Police kept the roughly $600,000 seized at arrest. The court noted Huri had shown remorse; Bidani had skipped the therapy sessions it previously ordered. The biggest attack service the internet had seen closed its books with no one going to prison.
both sides, on the record
The case: vDOS was, by its own leaked records, the largest attack-for-hire service on the internet — 150,000+ coordinated attacks, two million over four years, $618,000+ booked. It sold outages to anyone with a PayPal account, ran on rented Bulgarian firepower behind Cloudflare, and laundered its proceeds through round-robin accounts because, as one researcher put it, its methods were “practically indistinguishable from those employed by organized cybercrime gangs.” The operators blacklisted Israeli targets specifically to avoid trouble at home — conduct that shows they knew exactly what the rest of the world was buying. An Israeli court agreed enough to convict.
The retaliation removes any doubt: whatever the “stress-testing” sales pitch claimed, the service's response to being exposed was to point 140 Gbps at the reporter and spell his humiliation into the packets. That is not a security research tool. That is a weapon, used as one, in real time, for spite.
The defense, as argued: their lawyers maintained vDOS was a legitimate stresser — a service companies could use to test the resilience of their own sites — and that booters occupy a genuine legal grey area their operators didn't invent. It is true the “stress-testing” framing is the whole industry's standard cover, and true that the line between authorized load-testing and unauthorized attack is a real one in law.
They were children, and the court said so: the Israeli court found the pair were minors during the bulk of the offenses and sentenced accordingly — the lightest option on the books. One of them showed remorse. Whatever vDOS was, it was built by teenagers who, on the record, faced a justice system that treated their age as the deciding fact.
YOU DECIDE
Strip the branding and vDOS was a rented flood with a support desk, sold to whoever paid, run by two kids who believed being clever about their own IP ranges made them safe. The grey-area defense is real in the abstract and collapses against the specifics — the laundering, the erased logs, the customer roster full of other people's businesses, and above all the 140-gigabit answer to being written about. What the record actually produced was six months of community service and a seized bank account, which is either proportionate mercy to a pair of former minors or the clearest possible demonstration of why the next generation of booter kids figured the downside was survivable. The archive notes only that the flood vDOS aimed at its exposer was the one that pushed Brian Krebs into the path of Mirai.
The archive does not deify. It keeps the leaked customer database — and the word spelled out in the attack packets.
evidence locker
PRIMARY / REPORTING ON THE LEAK
KrebsOnSecurity — “Israeli Online Attack Service ‘vDOS’ Earned $600,000 in Two Years” FACT — the foundational report on the leaked vDOS database: the $618,000+ revenue, the 150,000+ attacks and 277M seconds of attack time, the July 2016 breach via PoodleStresser, the Bulgarian servers, the Israel-blacklist support tickets (quoted), the identification of AppleJ4ck and P1st, and the PayPal-laundering recruitment quote.
krebsonsecurity.com/2016/09/israeli-online-attack-service-vdos-earned-600000-in-two-years/
KrebsOnSecurity — “Alleged vDOS Proprietors Arrested in Israel” FACT — the September 8, 2016 arrests of Huri and Bidani (both 18) on an FBI investigation, the ~$10,000 bonds, seized passports, house arrest and 30-day internet ban, and the ~140 Gbps retaliatory attack on KrebsOnSecurity.
krebsonsecurity.com/2016/09/alleged-vdos-proprietors-arrested-in-israel/
THE RETALIATION & WHAT IT LED TO
KrebsOnSecurity — “The Democratization of Censorship” FACT — the record ~620 Gbps IoT-botnet attack that followed the vDOS story, Akamai/Prolexic dropping the pro-bono protection under load, the site going dark, and the move to Google's Project Shield.
krebsonsecurity.com/2016/09/the-democratization-of-censorship/
CONTEXT & CROSS-LINKS
troll.fan — Lizard Squad CROSS-LINK — the booter-crew sibling: LizardStresser, the same rent-a-flood business model, and the same self-inflicted breach of the operators' own product.
troll.fan/dossiers/lizard-squad.html
troll.fan — Crew Rivalries CROSS-LINK — the booter-wars culture of hacking the rival's stresser that vDOS's own breach fits into.
troll.fan/crew-rivalries.html
The standard. vDOS is a documented, adjudicated public matter: the service, its $618,000+ revenue and 2M+ attacks, the July 2016 breach, the September 2016 arrests, the retaliatory DDoS against KrebsOnSecurity, and the 2017 charges plus June 2020 sentence are stated as fact per KrebsOnSecurity's reporting on the leaked database and the Israeli court record. The two operators are named because that reporting identified them and an Israeli court convicted them; first-party quotes are reproduced from the leaked support tickets and Hackforums posts, attributed to the alias that signed them. Both were minors during the bulk of the offenses; the court's juvenile finding is reported as the court made it, without moralizing. The defense's “stresser” argument is given in its lawyers' terms, attributed, not adopted. No customer PII is reproduced and this page describes no methods — a booter is documented by its effect, not its mechanics. If a line here couldn't survive scrutiny, it wouldn't be on the page.