
About this episode
When North Korea targeted security researcher Alejandro Caceres, he did something Americans aren’t supposed to do: he struck back — and knocked the country’s entire internet offline. Now, a new Trump administration memo is raising the possibility that, under special circumstances, Americans could strike back at cybercriminals — legally.
Learn about your ad choices: dovetail.prx.org/ad-choicesGet every episode summarized
Each time Click Here publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
447 searchable segments. Every word is indexed and playable.
Full transcript
Click Here — He hacked back — and took down North Korea’s internet. Machine-transcribed; use the interactive transcript above to jump the player to any line.
From recorded future news and PRX, this is Click Here. Last month, President Donald Trump signed a memo that could change one of the basic rules of cybersecurity. For years, if someone hacked your company, you could defend yourself. You could call the FBI, but what you generally could not do was hack them back. Now the Trump administration wants to make that possible. President Trump has signed an National Security Agreement aimed at fighting cybercrime from overseas. The idea is that private companies can now go on the offensive against cybercrime gangs with the government's permission and with legal protection, which raises an interesting question. What if the people you're hacking aren't just criminals?
What if they're connected to another government? What if they are foreign government? A few years ago, one guy found himself in almost exactly that situation. Except he didn't exactly wait for permission. Today, we're going back to an episode we first aired in 2024 about what happened when one guy decided to hack back. And he did not make a listen. Everything got a little weird for Alejandro Casadez around three years ago. That's when a friend of his made an introduction to a guy who went by the name James Willie. I kind of knew that the whole James Willie name was fake. I mean, come on, James Willie, right? Then people in the cyber world used fake names all the time he told himself. So I didn't really think much of it.
Alejandro is 38, lives in Florida and is a cyber security guy. His online handle is PAX, which he spells P, the number four, and then the letter X. His specialty is writing exploits, the code that takes advantage of vulnerabilities and software. A few years ago, he decided to build his own cyber security business. And when you're starting out and building a client list, you tend to be less choosy. You just want to get customers in the door. Even if in retrospect, alarm bells are ringing everywhere. And of course, Ron, like the shadiest chat messenger that there is, we were telling him, but that's also not there. So Alejandro and this James Willie start trading messages, talking about their cyber experience, the types of projects they've worked on. He asked me, I have what is the start of what I think could be a really good exploit.
It is part of what we call a full chain exploit. And that's just where you are attacking a very complex program and it requires more than one vulnerability to really own the computer. James Willie appeared to have found the mother load. In this case, it was Google Chrome. Everyone uses Google Chrome, right? It's the vulnerability that hackers dream about because it could compromise so many computers. The problem James Willie said is that he couldn't quite get his exploit to work. Maybe Alejandro, with all his coding skills, could lend a hand. It was very like flattering, but not in an obvious way. Like, it was just like, I think you can do this. James sent him the exploit so Alejandro could take a look. Now Alejandro is in Naïe if he doesn't just double click on everything that comes to him. So he opened the exploit in an error gap computer that wasn't connected to his system.
And you guessed it. So it turns out that the project that he sent me was back doored and it was the downless back door I've ever been owned by. Alejandro had been hacked, at least technically, because he'd been careful about where he'd opened the exploit, he was able to contain the damage. At first he was mad, and then he was a little insulted. This was a super obvious fishing attack and a really basic back door that was super easy to find. I wish I could say it was some super hacker technique or something like that. But the frank truth of it is that he just knew the exact right character that he'd been going in front of me. And for months, Alejandro didn't give it much thought. Until one day he was reading a blog post by Google Tag, a threat analysis group. And one of their warnings caught his eye. Apparently North Korean hackers were targeting cyber security researchers. And then Alejandro gasped.
It gave aliases that they used. And the sure enough, one of them was James Willie. James Willie, just like the name of the guy he'd been chatting with on Telegram. What did you think when you read that? I mean, like, did your heart sink or did you like slap yourself on the side of the head? What was your reaction? I think my first reaction was just like shock, like holy shit. Like, like, I was just targeted by a nation state. From recorded future news and PRX, this is click here. The show about how technology is changing everything. I'm Dina Tamporascha. And today the story of Alejandro Cusodes, an American who got hacked by North Korea, and then responded by doing something no one was expected. He hacked them right back. What exactly did you take down? And the answer is everything.
Stay with us. Support for click here comes from ODO. Business software is expensive. And when you buy it from lots of different companies, it also gets confusing and slow and hard to integrate. ODO solves that because all their software is connected on a single affordable platform. So you can save money without missing out on the features you need. ODO has no hidden cost and no limit on features or data. It has over 60 apps available for any needs your business might have. Everything from websites to sales to inventory and accounting, all linked and talking to each other for no additional charge. Check out ODO at od.com. That's od. O.com. That's od. O.com. Support for click here comes from Nord security. Here's the challenge. IT teams need to see what's happening in browsers, but they can't slow anyone down or disrupt
their workflow. Nord layer browser solves this. It gives IT teams full visibility and control over browser activity while keeping everything familiar and fast for employees. Two products work together. Nord layer provides the Secure Network Foundation, then Nord layer browser extends that into the workflow, managing web apps, sessions and data. The payoff, every browser session becomes visible, controlled and secure. Company data stays protected, access to sensitive resources is managed. Accidental data leaks are prevented. And it works for all kinds of teams, remote workers, contractors, people using their own devices, all secured without the complex setup or device management. Go to nordlayer.com slash browsers slash click here and unlock your 10% discount on Nord layer browser with coupon code click here 10. That's nordlayer.com slash browsers slash click here and enter coupon code click here 10
at checkout. When our Alejandro Cusodes was a kid, his dad didn't just bring him home a personal computer. He actually built him one. I don't really smart guy. He is a PICU doctor, but somehow knows a lot about technology. He would build his own computers. And they weren't like the Commodore 64 computers that other kids had. They were just sort of Frankenstein's. And he just learned doing that. And I would use them and mess them up sometimes and just do stupid stuff with them. So that's kind of where my first computer came from. When Alejandro was around 13, he began logging onto that family computer, entering AOL chat rooms and doing wood budding hackers often do. I started to get into what we would call now denial of service attacks.
Deedless attacks. There was this little program, sir. You would flood people with messages or you would use some funky tricks. Funky tricks like adjusting the font size. Like for example, you increase the font a ridiculous amount. Not just 14 point type, but like a thousand point type. You send it and it kicks them offline immediately. So I just I enjoyed it and I don't I honestly cannot describe why besides the fact that I was just a little jerk. Or you could say like just about any other computer that we're a kid, he was trying to test the limits of the internet. So in those days, there was the tools like back or office, right? Those are they were basically like you send a Trojan. A Trojan is a type of malware disguised as legitimate software. It's kind of like a game or something like that.
And you could just send it to your target. Kind of the early version of what those North Korean hackers seem to do to him. My first proper hack is a friend of mine. I sent them this like really, really dumb game and I told them this game is amazing. You have to play it. And he opened it. And suddenly Alhandro had access to his friend's computer. But if you wanted to take actual control of it, he needed the IP address. In those days, when you sent an email, your IP address was actually right there. So I told him, Hey man, like I'm having some problems with my email. If you could please send me a test email, just I really want to make sure this is working. He sent me a test email and then I connected to his computer. Then Alhandro started to have a little more fun. Alhandro started sending his friend fake error messages and then randomly opening and closing the CD tray. Remember those? So did he think like his computer was possessed?
Yeah, that was kind of my goal. And you think that Alhandro kind of saw the writing on the wall back then that this computer stuff was his calling, but he didn't. Instead, he went to Duke and double majored in physics and math. I wanted to be a professor and just research and study and do physics for the rest of my life. And that might have been the end of it and we might never have met him. Had he not started working with supercomputers to finish his thesis? My thesis was on heavy ion collisions and simulations of them. So I got to work with like a supercomputer that they had there and that's where I kind of learned Linux. And also got an understanding of things like what is remote access? How do you use it? Why do you use it? How does it work? Something kind of clicked in my mind and I was like, oh, so there's remote protocols.
People set them up like idiots and then somebody breaks in and that would be a hack. It's like a light bulb moment. And it changed everything. I'm a hacker and that's how I always describe myself. His official title is more like offensive security researcher, which means he doesn't just sit back and defend networks. I don't focus on the security part. I'm like, I'm an offensive offensive researcher. An offensive offensive researcher. He's more interested in finding vulnerabilities that help you go on the attack. Which may explain why for the past decade or so, Alhandro has applied for and landed a bunch of contracts that he can't talk about with a roster of lettered agencies and places like the Department of Defense and DARPA, which means one of two things that hacker James Willie either had no idea who he was dealing with or knew exactly who he was dealing with.
What do you think they really wanted? They did hit a couple of other exploit writers. And so I know that they were looking for zero days. Zero days. Those are vulnerabilities and software that no one knows about. Was there a moment when you thought, hey, the North Korean shouldn't get away with this? Yeah, that's exactly right. And I saw that they were going to, they were, they absolutely were going to get away with that. And the weeks that followed, Alhandro talked to people he knew, FBI agents, Suther Ron Forson, to see if maybe they'd step in and help him. Certainly they didn't think it was okay for North Koreans to attack Americans, he thought. But as the week stretched into months, it was obvious that no one was going to step in. He was positive North Korea had hacked him and that they were hoping to steal exploits he had written. They actually put a back door on his computer and there'd be no consequences for that.
So was there sort of this moment where you went, that's it, I'm going to get back at him myself. Yeah, actually, that was kind of my first thought. Let's hack North Korea like the whole country. The thought of bringing down a country was not really, I never really planned much except for let's let's see what I can do. Stay with us. Support for Click Here comes from Serval. Your IT team could be building infrastructure, solving real problems. Instead, they're stuck resetting passwords and approving access requests, running the same support playbook over and over again. And that's not a capability problem, that's a work design problem. Serval fixes it. You simply describe what needs automating in plain English, no technical jargon needed and serval builds the automation for you.
No drag and drop builders to wrestle with, no consultant fees, eating your budget, no waiting months for implementation. The result, IT stops being a bottleneck and becomes the operational engine that moves the business forward. And Serval backs this up with a guarantee that half of your IT tickets will be fully automated. Test it for yourself. Learn more or start a free four week pilot at serval.com slash click here. That's S-E-R-V-A-L dot com slash click here. Serval.com slash click here. I'm Vrcladstone cohost of WNYC's on the media. Information doesn't trust inform us. It shapes how we see the world, what we fear and who we trust. That's where on the media comes in. Each week we investigate how information flows, who controls it and what that means for our democracy. It's not about the headlines, it's about the hidden structures behind them.
Don't be a passive consumer. Listen wherever you get your podcasts. His public life is a security researcher. Alhunter runs a cyber security company called Hyperion Gray. He's kind of infamous for creating a controversial scanning tool called punk spider. I'm also under the punk spider project. Did anybody hear her to the punk spider project? He unveiled it at the Defcon Hacker conference in 2021. Oh, sweet. More than like five people. It's more than expected. Awesome. So he's the kind of hacker who actually could launch a kind of revenge tour on North Korea. And he spent more than a year planning it and it began with James Willie. So you were really looking for him at first. That definitely was after that. You know, I kind of realized that's not really going to be fruitful. James Willie was a fake name and he probably wasn't online anyway.
So Alhunter decided he would go bigger to see what he could find in North Korea's networks that were worth hacking. That would send a message. I know there are guys extremely limited. She in terms of access. And when he says limited access, he means really limited. Of the 26 million people who live in North Korea, only a few thousand get to actually use the internet the rest of the world sees. You actually need special approval to even get on to the internet. And then minders sit next to people while they browse and have to approve their activities. There's an hour time limit to factor say. And then you have to apply again for permission to do more searches. So in other words, the odds that Alhunter's nemesis was online and searchable was pretty unlikely. And he started the way most hackers do by running some scans of their infrastructure. I knew that they weren't extremely sophisticated in their infrastructure.
Maybe I will do some port scans and do some manual analysis and find something to break into. So Alhunter thought maybe he could hack into some critical infrastructure in North Korea and send a message that way. But that wasn't working out very well either. It's not like I could find the IP range for whatever the dictatorial palaces over there. You can't find Kim's private computer. That's exactly right. Yeah, I mean, hopefully one day I'll be able to break in and it'll say like, you know, Kim Jong Un's personal computer. Maybe he has multiple like Kim Jong Un's personal Kim Jong Un's porn computer, Kim Jong Un's official. So maybe someday. And we should say here that Alejandro's hack as we're about to describe it was first reported by Andy Greenberg at Wired Magazine. We're Alejandro's first broadcast interview and we got a few new details.
At its most basic level, Alejandro decided to launch an attack that would just overwhelm their internet systems. The machine runs out of memory and they have like denial of service conditions, right? I found a bunch of vulnerabilities to those. And so I wrote a few little end days as they call them end days known vulnerabilities that no one's used yet. This was child's play Alejandro thought as he moved through their systems. Their internet infrastructure was pretty rickety. Wow, like they have. This is made out of like sticks and glue. Then he began to wonder whether there was a better internet buried somewhere else somewhere he couldn't see. So I thought, you know, I'll go rent a sort of room China. I don't care if they're watching. I will, you know, just do it completely anonymously. It's, you know, over ways. And I will do a scam from there. And I did a scam and it looked exactly the same.
And almost I'd wait, okay. And I was like, so it doesn't seem to be any kind of like special or routing or anything like that. And as he traced the North Korean infrastructure, he found this even crazier thing. I started to notice and like the same two IP addresses just kept going up and like wait a minute. That's interesting. Like usually when you grab an entire country, it's a ton of them. A ton of IP addresses. And he thought that couldn't be right. There must be more than two routers. He thought maybe there was an internet in North Korea that couldn't be accessed from the West. So basically made a big circle around North Korea. So I just rented like, I don't know, about 20, 30 servers and they're literally circling North Korea. And sure enough, since two routers, North Korea was running its connection to the rest
of the world's internet through just two machines, both of which Alhandro decided to hack. I was just like, that's incredible. I've never seen that. Let's see what I can do. And it turns out while the routers were bigger than something you might have at home, they weren't all that complicated. So he just did a kind of denial of service attack on those two vulnerable routers. And just like that, he literally took down the web in the Hermit Kingdom, everything from their government portal to the state news services to the booking site for North Korea's flagship airline, Eric Coru. And what would they have seen on their end? Yeah, on their end they see absolutely nothing, which is the best part. Are they getting like a 404 error message? Oh, oh yeah. In terms of when it actually went down, yeah. Some researchers all over the world who monitor that North Korean internet said they saw these mass scale attacks.
So this guy was able to run a script and as they were doing their own thing, their American computer was destroying the backbone infrastructure of North Korea's entire country. Literally all North Korean websites were under attack of which there aren't many by the way. And no one knew who was behind it. North Korea's internet was down for nine days before El Hondro decided to restore it. My goal was really just like do it for about a week. And the idea was I want this to be proportional. I don't think that I don't want it to be like their internet's down forever. Still, even the act of taking down a nation's internet for more than a week is pretty out there. And the US government had watched it happen and was a little curious about how El Hondro pulled it off. Some of his hacker friends who had links to the Pentagon put him in touch with some high level people.
And El Hondro says he went and talked to them about joining him in offensive, offensive cyber. I outlined the exact methodology that I used for North Korea and I outlined how it could easily be reproduced with a very, very small budget. Like compared to what they have, it's nothing. It's like a penny for that. El Hondro said that the people he met with were intrigued, but a little reticent. They didn't seem to want to engage in these kinds of aggressive offensive cyber operations. And El Hondro is like, hey, on this guy, I have real solutions to your problems. What I have is I have literally one program that can stop every single cyber attack that comes out of North Korea. El Hondro said they said, thanks, but no thank you. There are some valid reasons why the Pentagon or US cyber command weren't eager to adopt
El Hondro's aggressive stance on hacking back. Number one, his take down of the North Korean internet wasn't really a military target. It was a civilian one. And attacking something like that is usually considered a war crime. That's what Russia is dealing with now is it attacks Ukraine's civilian infrastructure. There was a lot of debate initially. This is Jackie Schneider. She's a fellow at the Hoover Institution at Stanford. And her research focuses on the intersection of technology and national security. Is this offensive cyber more like dropping a bomb or more like spine? Because those are actually different authorities spying versus dropping a bomb? Jackie says what he was essentially asking the Pentagon to do is an end run around these rules called authorities, which determine what the government can and can't do in cyber space. And it's complicated because not only is the US still trying to figure out when offensive cyber is appropriate, but it's also a completely different kind of weapon.
Unlike bombs, cyber weapons aren't something you can just stockpile and then pull out and use whenever you want. So at the beginning of cyber operations, we asked we thought about building cyber attacks like we would build those kinds of bombing plans, right? The problem is the network changes all the time. Cyber buildings get patched, etc, etc. Exactly. So you can't actually put a cyber attack on the cell. By the time that approval actually comes through, the vulnerabilities in the network that we're going to be used could be gone. Something that worked two hours ago might not work when you go to execute it. Right. Or you're sitting in the network and then all of a sudden the way you got in is no longer open. Exactly. Exactly. So is a hack a bomb or just spying? Jonathan McGrath, a former executive officer at the US Cyber National Mission Force, says Elhander is right. There need to be new rules about when it's appropriate to punch back in cyber space.
I know what international waters are. I know if we have a ship off the coast, you know, and it's 20 miles out at the end of the day, we all know the boundaries for international waters. But when it comes to cyber, we somehow let the bullies hang this upside down and shake the change out of our pockets every second of every minute of every day. Jonathan thinks the US should start contracting some of this offensive hacking out to trust firms like they do more traditional weaponry. They could set up some rapid response teams. Where is a nation going to draw its red line? Right? Which is exactly what Elhander says he was doing, drawing a red line. I'm really not either getting for anything like crazy radical like, like, yeah, let's attack that everybody that attacked us. It's really more just, they're not just attacking government stuff. They are now hitting private citizens and nothing is being done.
That is until North Korea targeted the wrong guy and he decided to teach them a lesson by turning off their internet for a little while. This is Click Here. Click Here is a production of recorded future news and PRX. Today's show was written and produced by Megan Dietri, Sean Powers, Erica Gutta, Zach Hirsch, and Maya Fawaz. It was edited by Karen Duffin and Sarah Coveto and fact-checked by Darren Anker. No music is by Ben Levingston with additional music from Blue Dot Sessions. Our staff writer is Lucas Riley. Our illustrator is Megan Goff and our sound designers and engineers are Jake Cook and Jesse Nicewanger. I'm Dina Tumbo-Reston and thanks for listening.
Support for this program comes from Recorded Future. And Cybersecurity, the biggest risk isn't what can be seen, it's what gets missed. Recorded Future analyzes billions of signals to help organizations stay ahead of threats. Recorded Future, know what matters, act first. If you're looking for a daily guide to cybersecurity news and policy, sign up for the Cyber Daily from Recorded Future News. It serves up the day's most interesting and important cyber stories from our sister publication The Record and then aggregates all of the big cyber stories you might have missed from news outlets around the world. Just go to the record.media and click on Cyber Daily to get all you need to know about the world of cybersecurity right in your inbox.
More episodes
More from Click Here

Iran: Why send a Tomahawk when Starlink will do?
Click Here

China is run by engineers, America is run by lawyers
Click Here

The hidden power of China’s video games
Click Here

Iran’s internet shutdown: keeping people apart is the point
Click Here