RAW videos from REAL hackers

RAW videos from REAL hackers

🎙 John Hammond 👥 2.2M 📅 November 22, 2025 ⏱ 20 min 👁 334K 📄 documentary 🧭 2026-08-16
Available in: English (current) Français

Keywords

session hijackinginfo stealeranti-detect browserGraphSpyaccount takeover

Summary

John Hammond presents two raw screen recordings from real threat actors, showcasing real-world cyber attacks. The first video, provided by Flare, shows a threat actor using an anti-detect browser (Octo Browser) and info stealer logs to hijack a YouTube session. The attacker drags and drops cookie files, configures a residential proxy to mimic the victim’s location, and gains access without credentials or MFA. The second video, from Huntress, shows a threat actor using GraphSpy to access a Microsoft 365 account via stolen access tokens, reading emails and searching for financial information. Hammond explains the technical details, emphasizing that these attacks are simple and effective, relying on stolen cookies and tokens rather than passwords. He also promotes Flare’s threat intelligence platform and highlights the importance of monitoring dark web for exposed credentials. The video provides a unique educational insight into the methods of cyber criminals, underscoring the ease of account takeover and the need for robust security measures.

157 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides high-value, real-world evidence of cyber attack techniques, offering a rare first-person perspective. The argumentation is solid, as Hammond explains each step clearly, linking the actions to broader concepts like session hijacking and info stealers. He effectively demonstrates that these attacks are not sophisticated but rely on readily available tools and stolen data. The inclusion of two different attack scenarios (YouTube and Microsoft 365) strengthens the argument that this is a widespread threat. However, the video is partly sponsored, which may introduce bias, but the technical content remains objective and educational.

Scientific Rigor, Source Quality, Title Accuracy

The video relies on primary sources: raw screen recordings from threat actors, provided by reputable cybersecurity firms (Flare and Huntress). The sources are credible, and Hammond correctly attributes them. The title accurately reflects the content. The video does not cite external academic sources, but the practical demonstration and expert commentary provide sufficient rigor. The redaction of sensitive information is handled responsibly. The sponsor segment is clearly identified, and the promoted product (Flare) is relevant to the topic.

185 words

Title / Content Match

The title accurately reflects the content: raw screen recordings of real hackers, as promised.

Quality & Reliability

8/10

The video presents raw screen recordings from real threat actors, provided by reputable cybersecurity firms (Flare and Huntress). The commentary is technically accurate and explains the attack chain clearly. However, the provenance of the videos is not independently verified, and some details are redacted, limiting full verification.

Key Moments

Cited Sources

  • Flare — Provided the first raw video and is the sponsor; threat intelligence platform.
  • Huntress — Provided the second raw video; managed security provider.
  • Octo Browser — Anti-detect browser used by threat actor in the first video.
  • GraphSpy — Tool used in the second video for Azure AD/Office 365 exploitation.

Concurring Sources

  • Flare — Threat intelligence platform that tracks dark web activities.
  • Huntress — Managed security provider that detected the threat actor.

External References

Contribution & Novelties

This video offers a unique educational value by presenting raw, unedited screen recordings from real threat actors, providing an unprecedented look into their methods. It demystifies cyber attacks, showing that they often rely on simple techniques like cookie theft and proxy configuration rather than sophisticated exploits. The video also highlights the importance of threat intelligence and monitoring the dark web for exposed credentials.

Pour aller plus loin :

  • Session hijacking — Overview of the attack technique demonstrated.
  • Info stealer — Explanation of malware that steals credentials and cookies.
  • Anti-detect browser — Tools used to evade fingerprinting.
  • GraphSpy — Open-source tool for Azure AD exploitation.

104 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical depth. This indicates a well-balanced video that is both informative and accessible, though it may not delve into advanced technical details for experts.

Reliability 8/10

💬 Très positif. Sur les 30 commentaires analysés, la majorité exprime enthousiasme et appréciation pour le contenu unique et éducatif, avec des remarques humoristiques sur les stéréotypes des hackers.