
SubSeven
The complete history of Sub7, the remote access trojan that shaped early 2000s hacker culture. From a Romanian teenager teaching himself Delphi in Win
// Listen
// Concept
View Concept
The complete history of Sub7, the remote access trojan that shaped early 2000s hacker culture. From a Romanian teenager teaching himself Delphi in Windsor, Ontario, to the tool that powered a generation of script kiddies, to the mysterious disappearance of its creator - and the imposter who claimed credit for over a decade.
This is a story about identity, anonymity, and truth. The real Mobman stayed hidden while Greg from Tampa built a career on the lie. It took years of investigation and a three-way phone call to finally expose the fraud and give credit to the quiet Romanian kid who just wanted to code.
Sonically inspired by B.U.G. Mafia - the Bucharest Underground Mafia - the Romanian gangsta rap group that the real Mobman was a fan of. Their quotes appeared in Sub7’s About screens. This album honors that connection.
Structure:
Act 1: Origin (Tracks 1-3) The real Mobman’s story - immigration, learning to code, creating something that took on a life of its own.
Act 2: Phenomenon (Tracks 4-5) What Sub7 became - the script kiddie explosion and the dark side of webcam access and privacy violation.
Act 3: The Void (Track 6) Mobman disappears. The anonymous creator stays anonymous.
Act 4: The Lie (Tracks 7-8) Greg claims the throne. The lie goes mainstream on Darknet Diaries.
Act 5: The Reckoning (Tracks 9-11) Ill Will investigates. The confrontation. The truth finally emerges from Craiova.
Themes:
- Identity and anonymity in hacker culture
- The price of creation (fear of prosecution)
- Stolen valor / identity theft of an anonymous person
- Romanian immigrant experience
- The democratization of hacking (for better and worse)
- Truth eventually surfacing
// Tracklist
Windsor, Ontario
Born in Craiova, October eighty Soviet blocks, concrete and hazy Seventeen years under gray skies Then ninety-seven, time to fly Family packed up, crossed the ocean Windsor, Ontario, frozen New world, new tongue, new start But the same code beating in my heart
Windsor, Ontario Right across from Detroit Where a kid from Romania Found his voice in the void Teaching myself to build What the world never saw coming Windsor, Ontario Where the story starts running
Canadian winter, cold as static Bedroom coder, self-taught addict Dell-fy language on the CRT Building something they would never see B.U.G. Mafia bumping through the speakers Bucharest Underground, street preachers Took the name that had the ring Mobman rising, silent king
Windsor, Ontario Right across from Detroit Where a kid from Romania Found his voice in the void Teaching myself to build What the world never saw coming Windsor, Ontario Where the story starts running
From the blocks to the border From the east to the water Just a kid with a dream And a screen that would matter
Krah-yo-vah to Ontario De cartier, frate, here we go The credits read “From Windsor” And that’s the truth they’ll never know
v1.0
February twenty-eighth, ninety-nine Dropped the code, crossed the line NetBus backwards, flip the script Swap the ten out, seven hits S-U-B-7 on the screen Purple interface, you know what I mean One-thirteen features out the gate Windsor, Ontario in the credits, set it straight
February twenty-eighth Nineteen ninety-nine The day I changed the game And left my mark in time Birthday in the password Romanian in the code B.U.G. Mafia quotes Only real ones know
Bucharest Underground in the About box Homage to the streets where my mind unlocks Tataee and Caddy bumping through the night Turned their words to Easter eggs hidden in plain sight Master password holding secrets deep My birthday buried where the digits sleep October fifteenth, nineteen-eighty Signed my soul in code, that’s what made me
February twenty-eighth Nineteen ninety-nine The day I changed the game And left my mark in time Birthday in the password Romanian in the code B.U.G. Mafia quotes Only real ones know
From Windsor with love Signed it in the source A kid from Craiova Setting the course They’ll argue for years About who made this thing But the code never lies And the truth has a ring
Sub-Seven, Sub-Seven Dropped in ninety-nine The password tells the story If you read between the lines
The FeaturesE
One-thirteen features in the first release Fun Manager got your system on its knees Pop the CD tray just to watch you freak Flip your screen around, now you looking weak Text-to-speech, make your computer talk “I’m watching you” while you sit there in shock Swap your mouse buttons, left is right Hide your taskbar, kill your desktop sight
The features, the features One click and I own ya The features, the features Sub7 took you over Webcam watching, keystrokes logged Every password that you got The features made it legendary Point and click, obituary
ICQ takeover, steal your whole account Message interception, every word that counts Screen capture thumbnail, I see what you see Microphone recording, hear you breathe for me Email notifications when your IP switch IRC control, make your box my bitch Port scanner, redirector, TCP Tunnel through your firewall, you can’t stop me
The features, the features One click and I own ya The features, the features Sub7 took you over Webcam watching, keystrokes logged Every password that you got The features made it legendary Point and click, obituary
They kept emailing, asking for more Every request opened another door Version after version, the power grew A hundred-thirteen became two hundred new User-friendly evil in purple and blue
Monitor off, monitor on Control-Alt-Delete? Nah, that’s gone Registry open, processes dead The features put you to bed
Script KiddiesE
Script kiddies worldwide, no code required Point and click power, whole globe got wired A-O-L chatrooms spreading the infection Every IP range showed a new connection China to India, bedrooms to basements Teenagers with power they couldn’t explain yet “You got sub7’d” was the phrase of the day Dialup mo-dems, we were learning to play
Script kiddies, script kiddies We didn’t write a single line Script kiddies, script kiddies But we owned you every time No skills needed, just download and run The democratization had begun Script kiddies changed the game And nothing was ever the same
Me and my boy, one summer night Two exe files, about to ignite Flipped a coin to see who’d be the host Server or client, who’d become the ghost He caught tails, ran that server.exe I got the client, now he belonged to me Months of torture, CD tray popping wide Flipped his screen while he tried to hide Changed his background to some dumb shit He couldn’t stop me, I was loving it
Script kiddies, script kiddies We didn’t write a single line Script kiddies, script kiddies But we owned you every time No skills needed, just download and run The democratization had begun Script kiddies changed the game And nothing was ever the same
But I wanted more than just the pranks So I cracked the books, joined different ranks Taught myself Dell-fy, wrote my own RAT Never released it, just wanted to see where it’s at That’s how Sub7 made careers Curiosity conquered fears Some of us became the ones defending The same systems we were once bending
From script kiddie to the other side Sub7 was the spark, can’t deny A generation learned to hack Some grew up and never looked back
Port 27374
Two-seven-three-seven-four That’s the number to your door Port scan running through the night Found you open, killed the light Webcam blinking, you don’t know Someone’s watching through the glow In your bedroom, in your space A stranger staring at your face
Port twenty-seven-three-seven-four Open wide, I’m walking through your door You never knew, you never saw The eyes behind your screen Port twenty-seven-three-seven-four This ain’t a game, not anymore The dark side of the dream
Reading through your private files Divorce journals, tears for miles Financial docs and family letters Secrets that should have stayed better Downloaded your MP3s Slowed your connection to its knees You blamed your ISP, your modem Never knew a ghost was with them
Port twenty-seven-three-seven-four Open wide, I’m walking through your door You never knew, you never saw The eyes behind your screen Port twenty-seven-three-seven-four This ain’t a game, not anymore The dark side of the dream
Not everyone was pranking friends Some had darker means to ends Real people, real lives invaded Trust forever degraded The nostalgia hides the truth We stole more than just our youth
Two-seven-three-seven-four Knocked on every single door Scan the range, find the prey That’s the price the victims pay Port open, soul exposed And nobody ever knows
The Disappearing
Two thousand four, I logged off for good Left the scene like I knew I should They were locking people up just for building tools Not for using them, changed the rules Made a thing and you could face the cage Didn’t matter if you turned the page So I stepped back, let the silence grow Better hidden than the world would know
The disappearing No goodbye, no final post The disappearing Now I’m just a ghost Let somebody else stand in the light I’ll keep my source code out of sight The disappearing Into the night
Sub7 Legends was the last release Twenty-oh-three, then I found my peace IRC went quiet, no more pings Empty channels, nobody listening Someone else would claim the throne Let them have it, leave me alone Why would I even care who lies When the truth could mean my demise
The disappearing No goodbye, no final post The disappearing Now I’m just a ghost Let somebody else stand in the light I’ll keep my source code out of sight The disappearing Into the night
They wanted glory, wanted fame I just wanted to avoid the blame Let the imposter take the heat While I stay hidden, stay discreet The credits say Windsor, Ontario But nobody knows where I go
Fading out, fading away Nothing left for me to say The silence speaks louder than words Let the lies become what they heard The disappearing act was clean Now watch what fills the space between
@GregTampa
Greg-Tampa, Florida man Stepped into the void with a master plan Grabbed the domains when they expired Built a whole persona, self-admired DEFCON stages, conference halls “I’m the one who built it all” Rolling Stone put him in print American hacker, no hint That the real one’s still in Canada Watching this fraud climb the ladder up
Greg from Tampa, selling dreams Nothing is ever what it seems Stole the crown from someone silent Built a kingdom on a lie, went From nobody to the spotlight Fake Mobman, Mr. Midnight Social engineering, that’s his game Wearing someone else’s name
Job interviews at Capital One Facebook next, look what he’s done “I created Sub7, hire me” Using stolen legacy The conferences ate it up Couldn’t fill a Dell-fy cup Never been to Windsor town Where the credits were put down But nobody checked the facts The real one covered his tracks
Greg from Tampa, selling dreams Nothing is ever what it seems Stole the crown from someone silent Built a kingdom on a lie, went From nobody to the spotlight Fake Mobman, Mr. Midnight Social engineering, that’s his game Wearing someone else’s name
It’s quite obvious who made it Some Greg guy from Florida faked it The password holds the birthday But his don’t match the data October twenty-seventh? Nice try October fifteenth in the source, goodbye
Greg-Tampa, living large Fake credentials, real in charge For years the lie went unchallenged Until somebody got unbalanced The truth was always in the code Romanian fingerprints, the load He never wrote a single line But wore the credit like it’s fine
Episode 20
Episode twenty, mic is on Darknet Diaries, tell your con “I built Sub7 for a game” Ultima Online, steal the fame “Nine hundred dollar phone bill dispute” Wardialing AT&T, follow suit “Crashed the west coast switching grid” The story of the things he did
Episode twenty The lie goes live Episode twenty Watch it thrive Thousands of listeners take it in Nobody questions where it’s been Episode twenty Now it’s canon The false flag’s flying, no one’s banning
“SWAT team came to my girl’s place” Third-degree felony, built the case “Five months in jail, did my time” Then the story gets more sublime “Sold a company to McAfee” Settled down where no one could see Disappeared into a quiet life The perfect end to the perfect lie
Episode twenty The lie goes live Episode twenty Watch it thrive Thousands of listeners take it in Nobody questions where it’s been Episode twenty Now it’s canon The false flag’s flying, no one’s banning
Jack asked the questions, Greg replied Nobody knew what was inside The real creator in Windsor still Watching this faker get his fill A hundred thirty episodes later The truth would come, a correction major
Episode twenty made him real A fairy tale, a perfect deal But somewhere in Canada, watching close The actual author never spoke The lie was running, running strong But nothing ever lasts this long One hundred fifty coming soon The reckoning, a different tune
Ill Will
Ill Will on the case, something wasn’t right Episode twenty keeping me up at night I was in the Crew back in the day I knew the real story, knew the way This Florida man with his fairy tales His timeline didn’t match, the logic fails So I started digging, five years deep OSINT research, no time for sleep
Ill Will, Ill Will The truth won’t stay still Digging through the archives late at night Something’s wrong and I’ma make it right Ill Will, Ill Will Got the detective skill Five years hunting for the smoking gun Won’t stop searching ’til the job is done
Old forums, cached pages, Wayback Machine Romanian phrases hidden in the scene The source code told the story clear B.U.G. Mafia quotes right here Windsor, Ontario in the credits typed This ain’t no Florida hype Traced the emails, crossed the wires Through the digital spires Found him in Canada, still in the spot Right across from Detroit, that’s what he got
Ill Will, Ill Will The truth won’t stay still Digging through the archives late at night Something’s wrong and I’ma make it right Ill Will, Ill Will Got the detective skill Five years hunting for the smoking gun Won’t stop searching ’til the job is done
Encrypted zip, password protected Photo of his car, got him detected “I know who you are, respond to me” He opened up, the real O.G. The source code released on GitLab fresh BSides Connecticut, put it to rest “Finding Mobman” - that’s the talk Five years of work in a single walk
Ill Will brought the receipts Made the story complete The real Mobman verified true Now it’s time for the interview One fifty coming, three-way call Watch the house of cards fall
The Call
Darknet Diaries, one-fifty on the line Three voices in the call, it’s confession time Jack brought the question everybody needs to know “What’s your birthday, Greg?” - watch the panic grow Twenty-seventh, October - that’s what Greg said But the master password puts that lie to bed October fifteenth, nineteen-eighty in the code The real Mobman’s birthday, now the truth explodes
The call, the call Watch the lies dissolve The call, the call Watch the story fall Three voices on the line, the truth revealed Years of fabrication finally unsealed The call exposed it all
Ask about Dell-fy, silence on the wire Never wrote a function, never lit the fire “Where’s Windsor, Ontario?” - never been there The first five versions had the credits square “Show us the source code” - couldn’t produce Every excuse just tightened the noose The real one from Canada, quiet and cold Dropped the facts that dismantled the gold
The call, the call Watch the lies dissolve The call, the call Watch the story fall Three voices on the line, the truth revealed Years of fabrication finally unsealed The call exposed it all
The real Mobman spoke his truth that night “It’s obvious the author isn’t you, alright? The code is Romanian, the facts don’t lie Some Greg from Florida? Nice try” The imposter couldn’t hide anymore Called it social engineering, walked out the door Said he’d stop claiming what was never his The house of cards collapsed, that’s what it is
The call lasted longer than the lies could hold A decade of deception finally told Jack had the courage to correct the record The truth was always there, just neglected One-fifty set it straight The real Mobman reclaimed his fate
Craiova
Krah-yo-vah, that’s where it began October eighty, Romania, a young man NES console, his mother smashed it down He took it apart just to see how it sounds Circuit boards and wires on the floor Curiosity opened every door Then the family crossed the ocean wide Windsor, Ontario, new life, new ride
Craiova to Canada, the story told Twenty-five years before the truth unfolds The code was always Romanian The fingerprints never American From the blocks to the border, de cartier The real Mobman finally has his day Craiova, Craiova The truth came home today
Bucharest Underground bumping on the speakers B.U.G. Mafia, those street preachers Put their words right in the About screen Easter eggs showing where he’d been “Mobman” - he said it had a ring Just a handle, just a little thing Detroit right across the water there Still in Windsor, still somewhere Never wanted glory, never wanted fame Just a kid who fell in love with the game
Craiova to Canada, the story told Twenty-five years before the truth unfolds The code was always Romanian The fingerprints never American From the blocks to the border, de cartier The real Mobman finally has his day Craiova, Craiova The truth came home today
Kept the source code all these years Through the silence, through the fears Let the imposter run his mouth While the truth stayed in the south But Ill Will wouldn’t let it rest Found the real one, passed the test Now the story’s finally straight The creator reclaimed his fate
Frate, pe bune, this is how it ends From Craiova to Windsor, making amends The code speaks louder than the lies Romanian fingerprints never die Sub7 was written by a kid Who just wanted to know how things work, and did From the concrete blocks to Canadian snow The real Mobman - now the whole world knows
What You BuiltE
Downloaded you from a warez site Fourteen years old, late at night Didn’t know what I had in my hands The keys to a thousand lands First time I saw through someone’s screen Understood what “remote access” means The internet was wild back then No rules, no cops, just us and them
What you built changed everything A tool, a toy, a master key What you built made us who we are Script kiddies reaching for the stars From bedroom hackers to the other side Defending networks worldwide You probably never knew the gift you gave What you built, the lyves you shaped
We hunted predators in chat rooms Turned your RAT into a broom Swept the filth out where we could Kids turned vigilante for good Yeah we did some shit we shouldn’t have Opened doors, had a laugh But we were learning something real How systems break, how networks feel
What you built changed everything A tool, a toy, a master key What you built made us who we are Script kiddies reaching for the stars From bedroom hackers to the other side Defending networks worldwide You probably never knew the gift you gave What you built, the lyves you shaped
Now we’re the ones behind the firewalls The ones who answer incident calls Penetration testers, red team leads Growing from those scattered seeds You gave us curiosity The tools to see what we could be A Romanian kid in Ontario Started something he’ll never know
Thank you, Mobman, for the start You put the hacker in our hearts What you built livs on today In every kid who found their way From Craiova to the world Your purple interface unfurled A generation learned to see Through the screens - and now we’re free
// Sources & Research
View Sources
Sub7 - Deep Research & Source Documentation
This document provides comprehensive research for the album “Sub7.” Every name, quote, date, technical detail, and event referenced is documented here with authoritative sources.
Purpose: Documentary accuracy and deep reference material. This album depicts real events, real people, and the true story of Sub7’s creation and the identity controversy surrounding its creator.
Last Updated: December 2024
Table of Contents
- The Real Mobman
- Sub7: Technical Deep Dive
- The Master Password Decoded
- B.U.G. Mafia: The Musical Connection
- The Sub7 Crew
- The Identity Controversy
- Greg’s False Claims (Episode 20)
- The Investigation (Ill Will)
- The Confrontation (Episode 150)
- Timeline of Events
- Primary Sources
- Verified Quotes
- Areas of Creative License
The Real Mobman
Identity
| Attribute | Detail | Source |
|---|---|---|
| Handle | Mobman, Mobmanden | Ep 150 |
| Birthdate | October 15, 1980 | Ep 150 |
| Birthplace | Craiova, Romania | Ep 150 |
| Immigration | Moved to Windsor, Ontario, Canada in 1997 | Ep 150 |
| Current Location | Windsor, Ontario (“right across from Detroit”) | Ep 150 |
| Programming | Self-taught Delphi | Ep 150 |
| ICQ Number | 14438136 | Ep 150, embedded in master password |
Background & Childhood
In Romania (pre-1997):
- Born in Craiova, a city in southwestern Romania (population ~300,000)
- Craiova is the capital of Dolj County, located in the historical region of Oltenia
- Growing up in post-communist Romania (Ceaușescu’s regime ended 1989)
- Taught himself programming at a young age: “I taught myself to program when I was very little”
- Created “a whole bunch of little games” in Romania before immigrating
- Had a NES console that his mother destroyed - he took it apart to understand how it worked: “his mother smashed it down, he took it apart just to see how it sounds” (paraphrased from Ep 150)
Immigration (1997):
- Family moved from Romania to Canada in 1997
- Settled in Windsor, Ontario - directly across the Detroit River from Detroit, Michigan
- Windsor is the southernmost city in Canada (further south than parts of California)
- The move brought him to North America at age 16-17
Learning Delphi:
- Discovered Delphi programming language after arriving in Canada
- “I wanted to start learning Delphi”
- “I learned Delphi by working on Sub7. It was my very first project”
- Sub7 was both his learning project AND his masterpiece
Handle Origin: The B.U.G. Mafia Connection
The handle “Mobman” came from B.U.G. Mafia (Bucharest Underground Mafia), a Romanian gangsta rap group:
“It comes from a rap band, a Romanian rap band, called B.U.G. Mafia. Bucharest Underground Mafia; that’s their name. I’m a big fan of them.” — Real Mobman, Darknet Diaries Ep 150
He adopted the nickname in 1999, the same year Sub7 was released.
Key evidence of Romanian authorship:
- B.U.G. Mafia lyrics (in Romanian) appeared in Sub7’s About screens across ALL versions
- “Every single version that was released, into the credits screen, and under Programmer, there’s only one name ever”
- “B.U.G. Mafia didn’t even have any songs online, man. I brought tapes with me from Romania. You could not have heard of them on the internet in 1999 when this was put in the About credits.”
This is crucial evidence - an American imposter in 1999 would have no way to know about B.U.G. Mafia or include their Romanian lyrics.
Why He Disappeared (~2004)
Reasons (from Ep 150):
- Fear of prosecution: “People started getting in trouble for making tools like that”
- Heard about malicious use: “People using it for malicious purposes”
- Wanted to move on: “I wanted to get into something else”
- Maintained anonymity: “Nobody knew my name, even the people that were closest to me”
Law Enforcement Contact:
- Never arrested or contacted by authorities
- “No, no, I did not [get heat from law enforcement]”
On letting Greg claim credit:
- “I just let it go… I thought ‘why would I even care’”
- Let the imposter take heat while staying safely anonymous
Sub7: Technical Deep Dive
Basic Information
| Attribute | Detail | Source |
|---|---|---|
| Full Name | Sub7, SubSeven, Sub7Server | Wikipedia |
| Type | Remote Access Trojan (RAT) | Wikipedia |
| Language | Borland Delphi | Multiple |
| First Release | February 28, 1999 | Wikipedia |
| Final Mobman Release | v2.1.5 “SubSeven Legends” (2003) | Wikipedia |
| Default Port | 27374 (starting v2.2) | HandWiki |
| OS Support | Windows 9x through Windows 8.1 | HandWiki |
Name Origin
The name “Sub7” is a wordplay derived from NetBus, an earlier RAT:
- Spell “NetBus” backwards → “suBteN”
- Swap “ten” for “seven” → “Sub7” / “SubSeven”
This naming referenced Sub7’s roots while establishing its own identity as the successor/competitor to NetBus.
Architecture (Three Components)
| Component | Filename | Purpose |
|---|---|---|
| Client | SubSeven.exe | GUI used to connect to and control infected machines |
| Server | server.exe | The backdoor/trojan installed on victim machines |
| EditServer | EditServer.exe | Configuration tool to customize server before deployment |
Security Expert Quote:
“With these features, Sub7 allows a hacker to take ‘virtually complete control’ over a computer. Sub7 is so invasive that anyone with it on their computer ‘might as well have the hacker standing right next to them’ while using their computer.” — Steve Gibson, computer security expert
Version History
Version 1.x Series (1999)
| Version | Date | Notes |
|---|---|---|
| 1.0 | Feb 28, 1999 | First release. 113 capabilities. Red-themed visual style. |
| 1.1-1.4 | 1999 | Continued red theme. Single-window interface. |
| 1.5 | 1999 | Introduced iconic blue/purple “Sub7 Fatsie” design |
| 1.9 | 1999 | Master password: predatox |
| 1.9 Apocalypse | 1999 | Experimental redesign |
Version 2.x Series (1999-2003)
| Version | Date | Key Features | Master Password |
|---|---|---|---|
| 2.1 | 1999 | IRC control, ICQ takeover, webcam | 14438136782715101980 |
| 2.1.2 “Muie” | April 2000 | “Muie” = Romanian profanity | Same |
| 2.1.3 BONUS | 2000 | HDDKiller batch file added | Same |
| 2.2 | 2001 | Modular plugin architecture (short-lived) | Same |
| 2.1.5 “SubSeven Legends” | 2003 | FINAL Mobman release | Same |
| DEFCON8 2.1 | Unknown | Special DEFCON edition | acidphreak |
Note on v2.1.2 “Muie”: The version name “Muie” is Romanian vulgar slang (roughly meaning “blowjob” or used as “fuck you”). This naming choice:
- Further proves Romanian authorship
- Reflects the rebellious/underground hacker culture
- Would be an extremely unlikely choice for a non-Romanian speaker
The Failed v2.2 Branch
The v2.2x branch attempted a modular approach with plugins and custom features. However, it failed because users lacked either the skills or motivation to create extensions. Mobman returned to the 2.1.x branch, culminating in the final “Legends” release.
Comprehensive Feature List
Sub7’s initial version (v1.0) had 113 capabilities organized into categories:
Surveillance & Monitoring
| Feature | Description | Version |
|---|---|---|
| Screen Capture | Full screen or thumbnail | v1.0+ |
| Webcam Capture | View through victim’s webcam | v2.1+ |
| Microphone Recording | Audio surveillance | v2.1+ |
| Keystroke Logging | Record all keystrokes since boot | v1.0+ |
| ICQ Spy | Intercept ICQ messages | v2.1+ |
| Clipboard Manager | View/modify clipboard contents | v1.0+ |
Password & Credential Theft
| Feature | Description |
|---|---|
| Screen Saver Passwords | Retrieve Windows screensaver password |
| Cached Passwords | Extract cached Windows passwords |
| RAS Passwords | Dial-up connection credentials |
| ICQ Credentials | ICQ account information |
| ICQ Account Takeover | Full control of victim’s ICQ (v2.1+) |
Prank/Disruption Features (“Fun Manager”)
| Feature | Description |
|---|---|
| CD-ROM Tray | Open/close at will |
| Screen Flip | Flip screen upside down or sideways (“Matrix effect”) |
| Wallpaper | Change desktop wallpaper |
| Colors/Resolution | Modify display settings |
| Hide Taskbar | Make taskbar invisible |
| Hide Desktop Icons | Remove all desktop icons |
| Swap Mouse Buttons | Left becomes right |
| Monitor Control | Turn monitor on/off |
| Disable Ctrl+Alt+Del | Prevent task manager access |
| Text-to-Speech | Make computer “talk” via voice synthesizer |
| Popup Alerts | Display custom message boxes |
| Play Sounds | Play audio files remotely |
System Control
| Feature | Description |
|---|---|
| Mouse Control | Full remote mouse control |
| Keyboard Input | Send keystrokes remotely |
| File Manager | Browse, upload, download, delete files |
| Registry Editor | User-friendly registry access |
| Process Manager | View/kill running processes |
| Force Reboot | Restart victim’s computer |
| Print Manager | Access printer functions |
Network Features
| Feature | Description | Version |
|---|---|---|
| Port Scanner | Scan for open ports | v1.0+ |
| Port Redirector | Redirect network traffic | v1.0+ |
| TCP Tunnel | Create network tunnels | v1.0+ |
| IP Notifications | Alert via email, ICQ, or IRC when victim comes online | v2.1+ |
| IRC Control | Control infected machines via IRC channel | v2.1+ |
| FTP Server | Built-in FTP for file transfers | v1.0+ |
| Network Sniffer | Capture network traffic | v2.1+ |
The IRC Control Innovation (v2.1): Starting with version 2.1, Sub7 could be controlled via IRC (Internet Relay Chat). As one security book noted:
“This set the stage for all malicious botnets to come.”
This was a pivotal innovation that influenced all future botnet development.
Why Sub7 Succeeded Where Others Failed
- User-Friendly Interface: Unlike command-line tools, Sub7 had a polished GUI
- “Fun” Features: The prank features made it appealing to curious teenagers
- Constant Updates: Mobman actively developed it for 4+ years
- Community Requests: He added features based on user emails
- Free Distribution: Available on warez sites and hacking forums
- Documentation: Came with help files and was easy to understand
“It was all fun. At the beginning and for the first many versions, it was all just fun. Having fun with people, playing tricks on them; pranks and things like that.” — Real Mobman, Ep 150
Distribution & Spread
- Uploaded to hacking sites and warez forums
- “I packaged it up and uploaded it to a hacking site. That started picking up steam”
- “People started sending me e-mails, contacting me; oh, can you add this?”
- Spread globally: particularly popular in China and India
- “Nearly every IP range I scanned would find at least 1 computer [infected]”
W32/Leaves Worm & Port 27374 Security Impact (2001)
In 2001, Sub7’s prevalence created an unexpected secondary threat: the W32/Leaves worm specifically targeted Sub7-infected machines.
How It Worked:
- Scan for computers with open port 27374
- Connect using Sub7 protocol
- Upload and execute its own payload
Sources:
June 2001 Port 27374 Surge:
“In June 2001, an increase of scanning activity was detected for TCP port 27374, the default administration port for the Trojan known as Sub7. The dramatic rise in scanning activity indicated that a new tool had been released, potentially an auto-rooter or a worm.” — GIAC Security Paper
Scale of Infection:
“Many attackers…simply scanned the Internet for systems already infected with the Sub7 Trojan. This saved the attackers the work of having to compromise a system. By focusing on targets already compromised, attackers could easily gain control of hundreds, if not thousands, of systems.” — GIAC Security Paper
Steve Gibson Quote (Security Expert):
“With these features, Sub7 allows a hacker to take ‘virtually complete control’ over a computer. Sub7 is so invasive that anyone with it on their computer ‘might as well have the hacker standing right next to them’ while using their computer.”
Modern Status: Over time, variants of Sub7 introduced evasion techniques including polymorphic code and encryption of traffic. However, modern antivirus solutions and Windows security enhancements have reduced the effectiveness of classic Sub7 strains. Port 27374 continues to be probed by attackers looking for old infections.
This demonstrated both Sub7’s massive prevalence and how it created a secondary attack surface - infected machines became targets for other malware.
The Master Password Decoded
One of Sub7’s most controversial features was a hardcoded master password that allowed the author to connect to ANY Sub7 server, regardless of the password set by the user who deployed it.
The Discovery
Security researchers reverse-engineering Sub7 discovered:
“SubSeven’s author has secretly included a hardcoded master password for all of his Trojans! The Trojan itself has been Trojaned.”
Password by Version
| Version | Master Password |
|---|---|
| v1.9 | predatox |
| v2.1 through v2.2b | 14438136782715101980 |
| DEFCON8 2.1 | acidphreak |
Decoding “14438136782715101980”
The real Mobman explained the password’s meaning in Episode 150:
| Segment | Value | Meaning |
|---|---|---|
| 14438136 | Mobman’s ICQ number | His personal ICQ account (also default in EditServer) |
| 7827 | License plate digits | From an old license plate he had in Romania |
| 15101980 | Birthday | October 15, 1980 (European format: DD/MM/YYYY) |
Full explanation from Mobman:
“The first part is my old ICQ number: 14438136. This was the default number in the EditServer, so it’s pretty obvious. The next 4 digits are from an old license plate I had back in Romania. The last 8 are my birthday: 15–10–1980.”
Why This Matters
The master password became key evidence in the identity controversy:
- Real Mobman’s birthday: October 15, 1980 → matches the password
- Greg’s claimed birthday: October 27 → does NOT match
When confronted, Greg could not explain why the master password contained a different birthday than his.
B.U.G. Mafia: The Musical Connection
B.U.G. Mafia (Bucharest Underground Mafia) is a Romanian hip hop group that directly inspired the real Mobman’s handle and whose lyrics appeared in Sub7’s code.
Group Overview
| Attribute | Detail |
|---|---|
| Full Name | Bucharest Underground Mafia |
| Founded | 1993 (as “Black Underground”) |
| Origin | Pantelimon neighborhood, Bucharest, Romania |
| Genre | Gangsta rap, G-funk, boom bap, hardcore hip-hop |
| Significance | Pioneers of gangsta rap in Europe |
Members
| Stage Name | Real Name | Role |
|---|---|---|
| Tataee | Vlad Irimia | Producer, rapper (founding member) |
| Caddillac (Caddy) | Dragoș Vlad-Neagu | Rapper (founding member) |
| Uzzi | Alin Demeter | Rapper (joined 1995) |
Original members (departed 1993): D.D. and Mr.Nobody
Musical Style & Significance
B.U.G. Mafia were:
“The pioneers of the gangsta rap scene in Europe, being the first major group to fuse the raw, West Coast-inspired sound of 90s gangsta rap with the social and political struggles of post-communist Romania, shaping the foundation of Romanian rap.”
Musical characteristics:
- Heavy “boom bap” drums
- G-funk synthesizers and keyboards
- Dark, raw, unpolished production
- Preference for live instrumentation over sampling
- Themes: poverty, crime, police hostility, post-communist housing projects
Discography (1995-1999)
| Year | Album | Notes |
|---|---|---|
| 1995 | Mafia | Debut album. Birth of Romanian gangsta rap. |
| 1996 | Născut și crescut în Pantelimon | “Born and Raised in Pantelimon” - neighborhood homage |
| 1997 | IV: Deasupra tuturor | “IV: Above Everybody” - 55,000 units sold |
| 1998 | De Cartier | “From the Hood” - 130,000+ copies, major controversy |
| 1999 | (singles) | Leading up to next album |
“De Cartier” (1998) - Key Album
Released September 20, 1998 - just 5 months before Sub7 dropped.
| Track # | Title (Romanian) | English Translation |
|---|---|---|
| 1 | Intro | Intro |
| 2 | Ghici cine s-a-ntors | Guess Who’s Back |
| 3 | Pentru ‘98 | For ‘98 |
| 4 | Când te lovești de realitate | When You Hit Reality |
| 5 | Viața-i doar un drum spre moarte | Life Is Just a Road to Death |
| 6 | Raid mafiot | Mafia Raid |
| 7 | N-ai fost acolo | You Weren’t There |
| 8 | Hai sa fim HIGH | Let’s Get High |
| 9 | Poveste fără sfârșit | Never-ending Story |
| 10 | Sânge latin | Latin Blood |
| 11 | 1, 2, 3 | 1, 2, 3 |
| 12 | De cartier | From the Hood |
| 13 | La vorbitor | At the Payphone |
| 14 | Ai grijă de șmenaru’ tău | Look After Your Hustler |
| 15 | Limbaj de cartier | Hood Language |
Album significance:
“Although rough, the album’s tracks provided a more introspective and passionate outlook of working-class life in Romania… the album paved B.U.G. Mafia’s way to superstardom in Romania.”
Sales: 130,000+ copies - massive for Romania
The Connection to Sub7
Why this matters:
- Real Mobman was a B.U.G. Mafia fan who brought tapes from Romania
- B.U.G. Mafia lyrics appeared in Sub7’s About screens across ALL versions
- His handle “Mobman” came from “Bucharest Underground Mafia”
- “B.U.G. Mafia didn’t even have any songs online, man. I brought tapes with me from Romania.”
- An American imposter in 1999 would have no way to know about B.U.G. Mafia
This is irrefutable evidence of Romanian authorship.
Controversy
In 1997, B.U.G. Mafia members were taken into police custody after a concert in Turnu-Severin due to profanity laws:
“Profanity in public performances had an unclear legal status at the time. The charges were dropped the following morning, but the incident became a turning point in the history of Romanian hip hop.”
The Sub7 Crew
The Sub7 Crew was Mobman’s inner circle - close associates who helped test, refine, and distribute Sub7.
Known Members
| Handle | Role | Notes |
|---|---|---|
| Mobman | Creator & Lead Developer | From Craiova, Romania |
| IllWill | Crew Member, Later Investigator | Found real Mobman, released source code |
| Read101 | Australian Developer | Created “LanFiltrator”, co-founded “Fearless Crew” |
| FC | Developer | Involved in 2010 revival attempt |
| DarkCoderSc | Developer | Possesses unreleased v2.2 source |
Source Code Possession
As of 2024, the following versions are accounted for:
| Version | Possessors |
|---|---|
| v2.1.2/3 | Released publicly by IllWill (with Mobman’s blessing) |
| v2.2 | Mobman, Read101, FC, DarkCoderSc (NOT publicly released) |
The 2010 Revival (Failed)
Around 2010, former crew members FC and Read101 attempted to revive Sub7:
- Based on official v2.2 source code shared by Mobman
- Failed because FC was “more interested in monetizing the new version than enhancing its quality”
- Never gained traction
IllWill’s Unique Position
IllWill was uniquely positioned to investigate the identity controversy because:
- He was a former Sub7 Crew member from the 1990s-2000s
- He knew the real community and history
- Something about Greg’s Episode 20 story “didn’t sit right”
- He spent years doing OSINT research to find the truth
The Identity Controversy
For over a decade, two people claimed to be “Mobman,” the creator of Sub7.
The Two Claimants
| Attribute | Real Mobman | Greg (@GregTampa) |
|---|---|---|
| Origin | Craiova, Romania | Florida, USA |
| Location | Windsor, Ontario, Canada | Tampa, Florida |
| Birthday | October 15, 1980 | October 27 |
| Programming | Self-taught Delphi | Could not answer Delphi questions |
| Windsor connection | Lives there, credited in early versions | Never been to Canada |
| Source code | Possessed until released | Could not produce |
| B.U.G. Mafia | Lifelong fan, brought tapes from Romania | Could not explain |
How Greg’s Lie Began
After Mobman disappeared (~2004), Greg stepped into the void:
- Acquired expired domain names (sub7crew.com, etc.) - he didn’t own them originally
- Claimed creator status at DEFCON and other security conferences
- Got featured in Rolling Stone (2013) as an American hacker
- Used credentials for job interviews at Capital One and Facebook
- Appeared on Darknet Diaries Episode 20 (2018) telling his fabricated story
Why Nobody Questioned It
- Real Mobman had been silent for nearly a decade
- Greg controlled the domain names
- The hacker community values anonymity - hard to verify
- Greg’s story was detailed and confident
- Nobody did deep forensic investigation until Ill Will
The Rolling Stone Article (September 2013)
The peak of Greg’s false identity was a feature in Rolling Stone magazine, written by David Kushner.
| Attribute | Detail | Source |
|---|---|---|
| Title | “The Geeks on the Front Lines” | Rolling Stone |
| Author | David Kushner | Rolling Stone |
| Date | September 2013 | Rolling Stone |
| Subject | “Gregory ‘Mobman’ Hanis” | Rolling Stone |
Claims Made in the Article:
| Claim | Detail | Status |
|---|---|---|
| Name | “Gregory ‘Mobman’ Hanis” | Unverified - contradicts Romanian origin |
| Age | 32 years old (in 2013) | Would make him born ~1980/1981 |
| Background | “Son of a U.S. Marshall mother and an absentee father” | Unverified |
| Education | “Got A’s in schoolwork but F’s in conduct” | Unverified |
| Sub7 Purpose | Created to cheat in Ultima Online by stealing virtual weapons | False - no UO references in code |
| AT&T Incident | “accidentally took down the entire AT&T network in California and Nevada for almost two days” | Unverified - AT&T spokesperson refused confirmation |
| Legal Outcome | Pled to “modification of intellectual property” | Unverified |
| Jail Time | Seven months awaiting trial | Unverified |
| Probation | Five years | Unverified |
| Aftermath | “lived on the streets after his mother refused him housing” | Unverified |
| Current Job | Network admin for online-poker company | Unverified |
Why This Matters:
- Rolling Stone is a major publication with editorial standards
- This article gave Greg mainstream credibility
- It was cited as “proof” of his identity for years
- The article’s claims were never independently verified
- All claims came solely from Greg’s own statements
Note: AT&T spokesperson explicitly refused to confirm the alleged network outage. The article published Greg’s claims without independent verification.
Greg’s False Claims (Episode 20)
In 2018, Greg appeared on Darknet Diaries Episode 20 and told an elaborate false story. This section documents what he claimed for the record.
⚠️ NOTE: These are Greg’s claims. They were later proven false in Episode 150.
The Ultima Online Story
Greg claimed he created Sub7 to steal Ultima Online credentials:
“It’s a remote-access tool. It was a Trojan horse virus.”
He claimed he and friends discovered in-game vulnerabilities, stole items through exploits, and built websites showcasing their loot.
Problem: No Ultima Online references appear anywhere in Sub7’s code or documentation.
The AT&T Story
Greg claimed:
- Received a $900 phone bill for calls he didn’t make (to Kansas and Arkansas)
- AT&T refused to remove charges
- He became determined: “I made this Sub7. I fucking own everything in Ultima Online… They think they’re smarter and better than me?”
- He wardialed AT&T systems
- Gained unauthorized access to unprotected PBX systems
- A command he entered “crashed west coast telephone infrastructure”
- Called AT&T, disclosed his access, gave his real name and phone number
- Demanded the bill be fixed in exchange for explaining the breach
Status: Unverified. No evidence supports any of this.
The SWAT Arrest Story
Greg claimed:
- FBI investigated for weeks
- He arranged to surrender at girlfriend’s apartment
- Encountered a SWAT team with weapons instead
- Spent five months in jail
- Public defender pressured him to plead guilty to third-degree felony
- At restitution hearing, AT&T lawyers didn’t show up
- Judge dismissed restitution requirements
Status: Unverified. Records show his birthday as October 27, and he cannot enter Canada (“They don’t want me to go to Canada” / “I know they don’t, ‘cause you have a record” - Real Mobman).
The McAfee Story
Greg claimed:
- After release, worked day labor
- Joined a poker software company as IT support
- Attended college
- Obtained multiple Microsoft certifications
- Started a cybersecurity company
- Sold it to John McAfee
- Settled in Huntsville, Alabama
Status: Unverified. No evidence of a McAfee acquisition.
Why The Story Seemed Believable
- Detailed and specific
- Included verifiable elements (DEFCON, conferences)
- Matched hacker mythology
- Darknet Diaries is a respected podcast
- No one from the real Sub7 history came forward to dispute
The Investigation (Ill Will)
IllWill, a former Sub7 Crew member, spent years investigating the true authorship.
Why He Investigated
- Something about Episode 20 “didn’t sit right”
- As a former crew member, he knew the real history
- “A lot of people have made their start with this, and it’s not right to have somebody else take the credit”
Methods
- OSINT Research: Years of hunting through old forums, cached pages, Wayback Machine
- Code Analysis: Romanian phrases in source code
- Archive Research: Original credits (“From Windsor, Ontario”)
- Network Tracing: Tracking down email addresses
Finding Mobman
IllWill eventually found a potential email address and devised a clever verification method:
- Created a password-protected zip file
- Put personal details about Mobman inside (including a photo of his car)
- Set the password to Mobman’s full legal name
- Sent it to the email address
The Logic:
- If it’s really Mobman, he knows his own name → he can open the file
- When he opens it, he sees “I found you” (photo of car, personal details)
- This proves both that IllWill found the right person AND that the person is who they claim
Mobman’s Response
From Episode 150:
“He sent me a little zip file with a couple of details about me. He had a picture of my car. He was like, the password for the zip file is your full name. So, if it’s really you, then you should be able to open it.”
“I replied; I said, well, you’re right. You can be 100% sure now.”
Initial Hesitation
Mobman was initially reluctant:
“This was a long time ago. I don’t know if I really want to get back into any of that.”
IllWill convinced him by explaining that people’s careers were built on Sub7, and it wasn’t right for someone else to take credit.
Source Code Release
- September 30, 2023: IllWill presents “Finding Mobman” at BSides CT
- Announces release of official Sub7 2.1.2/3 source code
- Released on GitLab with Mobman’s blessing: gitlab.com/illwill/sub7
- First official source code release ever
Additional Technical Evidence (IllMob Investigation)
Ill Will’s investigation, documented at illmob.org/notmymobman/, uncovered additional technical evidence:
Timeline Inconsistencies:
| Greg’s Claim | Problem | Source |
|---|---|---|
| “Wrote Sub7 at age 15 to hack Ultima Online” | Greg born 10/27/1980 → would be 1995 | IllMob |
| Sub7 v1.0 released | February 28, 1999 | Wikipedia |
| Ultima Online launch | September 1997 | Public record |
| Conclusion | If Greg wrote it at 15, it would predate Ultima Online AND Sub7’s actual release by years | IllMob analysis |
ICQ Number Evidence:
| Detail | Value | Significance |
|---|---|---|
| Master password | 14438136782715101980 | Contains ICQ number prefix |
| Real Mobman’s ICQ | 14438136 | Matches first 8 digits |
| Greg’s ICQ | 14204407 | Does NOT match |
| Greg’s explanation time | Nearly 2 hours to devise | Suggests fabrication |
Geographic Contradictions:
| Detail | Real Mobman | Greg |
|---|---|---|
| Origin | Romania | Claims never left US |
| 2003 announcement | Relocating to Montreal | Claims never left US |
| Sub7 credits | “From Windsor, Ontario” | Never been to Windsor |
| Language in code | Romanian B.U.G. Mafia quotes | No Romanian connection |
Source Code Evidence:
When asked to prove authorship, Greg provided:
- A password-protected file
- Password was “mobman”
- Contents: Only compiled binaries, no source code
- No proof of authorship - anyone could have renamed a downloaded file
This is critical: The real author would have source code. Greg never produced any.
Evidence IllWill Compiled
From the real Mobman:
- Multiple backup CDs with different development stages
- Original hoodie merchandise from when he sold Sub7 materials (with photographs)
- Handwritten development notes spanning ~4 years
- Complete source code (never released until IllWill’s GitLab)
The Confrontation (Episode 150)
On October 1, 2024, Darknet Diaries released Episode 150: “mobman 2” - featuring a three-way phone call between Jack Rhysider, Greg, and the real Mobman.
The Setup
Jack Rhysider (host) arranged the call after:
- IllWill’s investigation
- BSides CT presentation
- Verification of real Mobman’s identity
- Contacting both claimants
Key Exchanges
The Birthday Question
Jack asks Greg his birthday:
- Greg’s answer: October 27
- Master password contains: October 15, 1980
- Real Mobman’s birthday: October 15, 1980
Real Mobman: “I highly doubt that you’re born on October 15, 1980.”
The Windsor Question
Real Mobman: “The first five or six versions, the first thing that the About credits said was ‘From Windsor, Ontario’. Were you ever in Windsor, Ontario?”
Greg: “No. I haven’t been to Canada. They don’t…”
Real Mobman: “I know they don’t, ‘cause you have a record.”
The Delphi Question
Real Mobman challenged Greg on basic programming:
- “What does a Delphi function start and end with?”
- Greg struggled with basic terminology
- Real Mobman: “I doubt this guy even touched Delphi.”
The B.U.G. Mafia Question
Real Mobman: “How do you explain B.U.G. Mafia in the credits? Can you answer the question?”
Greg deflected: “Let me pull up the videos.”
The Source Code Question
Greg claimed to have source code but couldn’t produce it.
Real Mobman: “That [source code] has never left my hands until it was released by Ill Will on GitHub. Never.”
The Famous Quote
Real Mobman’s definitive statement:
“It’s quite obvious that the author is fucking Romanian, not some Greg guy from Florida.”
Greg’s Confession
When pressed with evidence:
- “I have a lot of that stuff, too.” (initially)
- “I’m not — I don’t have any proof. I’m gonna let it… let it go.” (when challenged)
- “I don’t claim it in person anymore to anybody.” (admission)
Greg characterized his actions as “social engineering” when confronted.
Aftermath
- Greg agreed to stop claiming to be the creator
- Episode 150 set the record straight
- Real Mobman acknowledged but remains relatively private
- Jack Rhysider acknowledged the credibility damage but noted the story’s value
Timeline of Events
1980s-1990s: Origins
| Date | Event | Source |
|---|---|---|
| 1980-10-15 | Real Mobman born in Craiova, Romania | Ep 150 |
| 1993 | B.U.G. Mafia founded as “Black Underground” in Bucharest | Wikipedia |
| 1995 | B.U.G. Mafia releases debut album “Mafia” | Wikipedia |
| 1997 | Real Mobman’s family immigrates to Windsor, Ontario | Ep 150 |
| 1998-03 | NetBus released by Carl-Fredrik Neikter (Sweden) | Wikipedia |
| 1998-08-01 | Back Orifice released at DEFCON 6 by cDc | Wikipedia |
| 1998-09-20 | B.U.G. Mafia releases “De Cartier” album | Wikipedia |
1999-2003: Sub7 Era
| Date | Event | Source |
|---|---|---|
| 1999 | Real Mobman adopts “Mobman” handle (B.U.G. Mafia inspired) | Ep 150 |
| 1999-02-28 | Sub7 v1.0 released | Wikipedia |
| 1999 | Sub7 v2.1 - IRC control, ICQ takeover, webcam | Wikipedia |
| 2000-04 | Sub7 v2.1.2 “Muie” released | GitLab |
| 2001 | W32/Leaves worm targets Sub7-infected machines | HandWiki |
| 2003 | Sub7 v2.1.5 “SubSeven Legends” - FINAL Mobman release | Wikipedia |
2004-2017: The Void
| Date | Event | Source |
|---|---|---|
| ~2004 | Real Mobman disappears from online presence | Ep 150 |
| ~2004+ | Greg begins claiming Mobman identity | Ep 150 |
| ~2010 | Failed Sub7 revival attempt by FC and Read101 | Medium |
| 2013 | Rolling Stone article identifies “mobman” as American (Greg) | Wikipedia |
2018-2024: Exposure
| Date | Event | Source |
|---|---|---|
| 2018 | Darknet Diaries Episode 20 - Greg’s false interview airs | Darknet Diaries |
| 2018-2023 | Ill Will investigates true identity | Ep 150 |
| 2023-07-09 | Sub7 source code posted to GitLab | GitLab |
| 2023-09-30 | Ill Will presents “Finding Mobman” at BSides CT | BSides CT |
| 2024-10-01 | Darknet Diaries Episode 150 - Real Mobman found, Greg exposed | Darknet Diaries |
Primary Sources
Darknet Diaries Episodes
| Episode | Title | Date | Content | URLs |
|---|---|---|---|---|
| 20 | “mobman” | 2018 | Greg’s false interview | Audio / Transcript |
| 150 | “mobman 2” | 2024-10-01 | Real Mobman found, confrontation | Audio / Transcript |
Technical Sources
| Source | URL | Notes |
|---|---|---|
| Wikipedia: Sub7 | Link | General history |
| HandWiki: Sub7 | Link | Technical specifications |
| GitLab Source Code | Link | Official v2.1.2/3 release |
| GitHub Mirror | Link | Mirror of GitLab |
| IllMob Article | Link | Investigation details |
Conference Presentations
| Event | Title | Date | Speaker |
|---|---|---|---|
| BSides CT 2023 | “Finding Mobman” | 2023-09-30 | IllWill |
Journalism & Media
| Source | Publication | Date | URL | Notes |
|---|---|---|---|---|
| “The Geeks on the Front Lines” | Rolling Stone | Sept 2013 | Link | David Kushner feature with Greg’s false claims |
| Sub7 Retrospective | Medium (Phrozen) | 2023 | Link | Technical retrospective |
| Port 27374 Documentation | SpeedGuide | Ongoing | Link | Port database entry |
Security Research
| Source | Organization | URL | Notes |
|---|---|---|---|
| “Sub7 Risk to Internet Security” | GIAC/SANS | Link | Academic security paper |
| W32/Leaves Worm Analysis | GIAC/SANS | Link | Related worm analysis |
| Honeypots Tracking Hackers | SANS | Link | Port monitoring context |
Cultural Sources
| Source | URL | Notes |
|---|---|---|
| Wikipedia: B.U.G. Mafia | Link | Romanian hip-hop group |
| Discogs: De Cartier | Link | 1998 album details |
Verified Quotes
All quotes from Darknet Diaries Episode 150 unless otherwise noted.
Real Mobman
| Quote | Context |
|---|---|
| “I’m still in Windsor, Ontario… If you’re ever around Detroit, it’s right across the road.” | Confirming location |
| “It just had a nice ring to it. Mobman, you know?” | On choosing handle |
| “It comes from a rap band, a Romanian rap band, called B.U.G. Mafia. Bucharest Underground Mafia; that’s their name. I’m a big fan of them.” | Handle origin |
| “I taught myself to program when I was very little.” | Programming background |
| “I learned Delphi by working on Sub7. It was my very first project.” | Learning Delphi |
| “I packaged it up and uploaded it to a hacking site. That started picking up steam.” | Distribution |
| “People started sending me e-mails, contacting me; oh, can you add this?” | Feature requests |
| “It was all fun. At the beginning and for the first many versions, it was all just fun.” | Motivation |
| “B.U.G. Mafia didn’t even have any songs online, man. I brought tapes with me from Romania.” | Evidence of Romanian origin |
| “The first five or six versions, the first thing that the About credits said was ‘From Windsor, Ontario’.” | Early version credits |
| “It’s quite obvious that the author is fucking Romanian, not some Greg guy from Florida.” | During confrontation |
| “I highly doubt that you’re born on October 15, 1980.” | Challenging Greg |
| “That [source code] has never left my hands until it was released by Ill Will on GitHub. Never.” | Source code possession |
Mobman on the Master Password
| Quote | Context |
|---|---|
| “The first part is my old ICQ number: 14438136.” | Password breakdown |
| “This was the default number in the EditServer, so it’s pretty obvious.” | ICQ connection |
| “The next 4 digits are from an old license plate I had back in Romania.” | License plate |
| “The last 8 are my birthday: 15–10–1980.” | Birthday encoding |
Greg’s Admissions (Episode 150)
| Statement | Context |
|---|---|
| Birthday is October 27 | Does not match master password |
| Never been to Windsor, Ontario | Contradicts early version credits |
| “I’m not — I don’t have any proof. I’m gonna let it… let it go.” | When challenged |
| “I don’t claim it in person anymore to anybody.” | Admission |
| Characterized actions as “social engineering” | When confronted |
Verification Exchange
| Speaker | Quote |
|---|---|
| Mobman | “He sent me a little zip file with a couple of details about me. He had a picture of my car.” |
| Mobman | “He was like, the password for the zip file is your full name. So, if it’s really you, then you should be able to open it.” |
| Mobman | “I replied; I said, well, you’re right. You can be 100% sure now.” |
Areas of Creative License
The following elements in the album are creative interpretation or dramatization, not direct documentary claims:
| Element | Type | Notes |
|---|---|---|
| Internal monologue | Dramatization | Any thoughts attributed to characters are interpretive |
| Emotional states | Interpretation | Feelings not directly stated in sources |
| Specific dialogue (unless quoted) | Dramatization | Based on documented conversations but not verbatim |
| Visual imagery in lyrics | Creative | Atmospheric details for storytelling |
| First-person perspective in some tracks | Narrative device | For emotional impact, not impersonation |
| Victim experiences (Track 05) | Composite | Based on documented capabilities and era accounts |
| Musical style choices | Creative | B.U.G. Mafia inspiration, not direct sampling |
What IS Documentary
| Element | Status |
|---|---|
| All dates | Verified |
| All names | Verified |
| Technical specifications | Verified |
| Quote attributions | Verified from transcripts |
| Geographic locations | Verified |
| Master password breakdown | Verified from Mobman |
| B.U.G. Mafia connection | Verified from Mobman |
| Investigation methods | Verified from Ep 150 |
| Confrontation events | Verified from recorded episode |
Legal Notes
Public Figures
Both primary subjects are limited-purpose public figures:
- Real Mobman: Created globally distributed software, participated in public podcast
- Greg: Actively sought publicity at DEFCON, Rolling Stone, Darknet Diaries, job interviews
Source Authority
All primary sources are:
- Publicly available - Anyone can verify
- On the record - Subjects spoke willingly to journalists
- Recorded - Audio evidence exists (Darknet Diaries)
- Transcribed - Written transcripts available
- Self-incriminating - Greg’s admissions are his own words
Truth as Defense
Every factual claim about Greg comes from:
- His own public statements (Episode 20)
- His own admissions under confrontation (Episode 150)
- Published journalism he participated in (Rolling Stone)
Research compiled December 2024. Primary source: Darknet Diaries Episodes 20 & 150.