Thursday, February 27, 2025
HomeCyber Security NewsAuthorities Shut down the Worlds Largest Darknet Child Sex Website That Contains...

Authorities Shut down the Worlds Largest Darknet Child Sex Website That Contains 250,000 Unique Videos

Published on

SIEM as a Service

Follow Us on Google News

“Welcome to Video”, the world’s largest child sexual exploitation darknet website has been seized and the operator (Jong Woo Son, 23) behind the site has also been charged and convicted in South Korea.

Authorities also seized approximately eight terabytes of 250,000 unique child sexual exploitation videos and the server that he used to operate a Darknet market.

It is used for exclusively advertised child sexual exploitation videos that are available for download by members of the site. it is one of the largest seizures so far related to this child abuse.

This operation collaborates with various countries around the world and the Son was arrested by the agents from IRS-CI, HSI, National Crime Agency in the United Kingdom, and the Korean National Police in South Korea.

According to the statement released by the Department of Justice, Not only Son but additionally 337 site users have been arrested around the world with the help of law enforcement from 38 countries, and 92 individuals were arrested from the U.S alone. 

As a result of the operation, at least 23 minor victims have been rescued those who reside in the United States, Spain, United Kingdom, and these Child victims were being actively abused by the users of the site.

“Darknet sites that profit from the sexual exploitation of children are among the vilest and reprehensible forms of criminal behavior,” said Assistant Attorney General Brian A. Benczkowski of the Justice Department’s Criminal Division.

In this case, In the Washington, D.C.-metropolitan area, the operation has led to the execution of five search warrants and eight arrests of individuals who both conspired with the administrator of the site and were themselves, users of the website. 

Two users of the Darknet market committed suicide subsequent to the execution of search warrants.”

“Welcome to Video” Darknet Website’s Nasty Activities

Jong Woo Son, an admin of the Welcome to video website started about 2015 and is hosted on the darknet, which can be accessed only via Tor.

Operators and users behind the sites uploaded videos and images related to child pornography also stated that “do not upload Adult porn”.

Based on the download details mentioned in the Videos, visitors downloaded thousands of videos more than a million times, and the users uploaded more than 200,000 videos.

The worst part is that the videos are taken by abusing even a 2-year-old child, and the site provides the option for users to search based on age using keywords like “%2yo”, “%4yo” etc.

Every user needs to register and create an account to download the videos, and the customers allow to browse images of videos preview that are available to download in 3 ways.

To download the videos, customers need to get points that can be obtained in 3 ways.

  1. Upload the Child pornography Video
  2. Referring to new customers to the website
  3. Paying 0.03 bitcoin for a VIP account to unlimitedly download videos for 6 months.

Between, June 2015 and March 2018, Welcome to Video received at least 420 bitcoin( Aprx $3 Million) via 7,300 transactions.

Customers from various countries including U.S., Britain, and South Korea sent BTC to “Welcome to Video”.

U.S. prosecutors said in the indictment that they found several IP addresses: 121.185.153.64 and 121.185.153.45 and these IP addresses are resolved to South Korean telecommunication.

The server behind the website was operated from the site admin bedroom and the operator failed to conceal these 2 IP addresses which were easily identified by law enforcement by just right-clicking on the website page and selecting the “view page source”.

You can follow us on LinkedinTwitter, and Facebook for daily Cybersecurity and hacking news updates

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

New “nRootTag” Attack Turns 1.5 Billion iPhones into Free Tracking Tools

Security researchers have uncovered a novel Bluetooth tracking vulnerability in Apple’s Find My network...

Authorities Arrested Hacker Behind 90 Major Data Breaches Worldwide

Cybersecurity firm Group-IB, alongside the Royal Thai Police and Singapore Police Force, announced the...

Cisco Nexus Vulnerability Allows Attackers to Inject Malicious Commands

Cisco Systems has issued a critical security advisory for a newly disclosed command injection...

New Wi-Fi Jamming Attack Can Disable Specific Devices

A newly discovered Wi-Fi jamming technique enables attackers to selectively disconnect individual devices from...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

New “nRootTag” Attack Turns 1.5 Billion iPhones into Free Tracking Tools

Security researchers have uncovered a novel Bluetooth tracking vulnerability in Apple’s Find My network...

Authorities Arrested Hacker Behind 90 Major Data Breaches Worldwide

Cybersecurity firm Group-IB, alongside the Royal Thai Police and Singapore Police Force, announced the...

Cisco Nexus Vulnerability Allows Attackers to Inject Malicious Commands

Cisco Systems has issued a critical security advisory for a newly disclosed command injection...