
Ryan McFarlane
FBI cybersecurity agent and TrustedSec Incident Response Practice Lead; led investigation of the Bayrob Romanian cybercrime group.
1
APPEARANCES
1
PODCASTS
012
DEC 30
JAN 6
JAN 13
JAN 20
JAN 27
FEB 3
FEB 10
FEB 17
FEB 24
MAR 3
MAR 10
MAR 17
MAR 24
MAR 31
APR 7
APR 14
APR 21
APR 28
MAY 5
MAY 12
MAY 19
MAY 26
JUN 2
JUN 9
JUN 16
JUN 23
JUN 30
JUL 7
JUL 14
JUL 21
JUL 28
AUG 4
AUG 11
AUG 18
AUG 25
SEP 1
SEP 8
SEP 15
SEP 22
SEP 29
OCT 6
OCT 13
OCT 20
OCT 27
NOV 3
NOV 10
NOV 17
NOV 24
DEC 1
DEC 8
DEC 15
DEC 22
DEC 29
JAN 5
JAN 12
JAN 19
JAN 26
FEB 2
FEB 9
FEB 16
FEB 23
MAR 2
MAR 9
MAR 16
MAR 23
MAR 30
APR 6
APR 13
APR 20
APR 27
MAY 4
MAY 11
MAY 18
MAY 25
JUN 1
JUN 8
JUN 15
JUN 22
JUN 29
JUL 6
JUL 13
JUL 20
JUL 27
AUG 3
AUG 10
AUG 17
AUG 24
AUG 31
SEP 7
SEP 14
SEP 21
Jun 2, 2026
Bayrob
34:29
34:33
34:51
35:07
35:15
Jack RhysiderHOST
So at this point, we're going on year seven or eight of this FBI investigation.

Ryan McFarlaneGUEST
Right around this time, uh, you know, we're in pursuit mode, right? So we're trying to get as much visibility into their infrastructure, and around this time, we get a, a data intercept on their systems that are controlling all their malware.

Ryan McFarlaneGUEST
So they had a, a multilayer command and control infrastructure where all the malware was reporting up to the first layer, and then that layer was forwarding on to a couple of servers that were hosted in different places.

Ryan McFarlaneGUEST
And we were able to, as a team, figure out where those servers were located.

Ryan McFarlaneGUEST
We, we got a data intercept on a couple of these top level command and control servers, and we were able to see the communications for all the botnet, which meant that we got to see when they updated their malware, what some of their campaigns looked like, how they were loading additional plug-ins.
42 MINS LATER
B
77:26Brian LevineGUEST
Um, so you know, he was off the charts compared to what we see, even at CSIPS, where it's all very advanced.