With the recent indictment of Larry Harmon, alleged operator of the Bitcoin tumbling service Helix and dark web search engine Grams, we decided to profile the follow-up to Grams: Kilos.
What is Kilos?
In November 2019, a dark web search engine called “Kilos” emerged from the depths of the cybercriminal underground to play the role of new heavyweight champion of search engines for cybercriminal marketplaces, forums, and illicit products. And with this title, Kilos recognized the need to stand out from the crowd and ensure its entrance onto the scene was not one to be forgotten.
Kilos possibly evolved from the well-known dark web search engine “Grams”, which ceased operations in 2017. Both Grams and Kilos are dark web search engines that clearly imitate the well-known design and functionalities of the Google search engine and, in a clever play on words, both follow a naming convention inspired by units of measure. Since going online in November 2019, Kilos appears to have taken on the task of indexing more platforms and adding more search functionalities than Grams ever did. In addition, Kilos has introduced updates, new features, and services that aim to ensure security and anonymity for its users and also add a more human element to the site not previously seen on other prominent dark web-based search engines.
How did Kilos evolve from Grams?
Grams was launched in early April 2014 and proved extremely useful to cybercriminals and researchers alike before its indexing capability was shut down by the administrator, who announced their decision to take down the site in December 2017.
In essence, Grams was a search engine for dark web cybercriminal markets. By using custom APIs, Grams scraped several of the most prominent cybercriminal markets at the time, such as AlphaBay, Hansa, and Dream Market. It allowed users to search for multiple illicit products by using a rather simple search interface that also featured popular search engine-like functions such as “I’m Feeling Lucky”. Grams also allowed users to hide transactions for illicit products through its bespoke Bitcoin mixer service “Helix”.
Grams interface mimicking the aesthetics and functionalities of Google
Back in the day, Grams was a revolutionary tool that allowed users to explore the darker corners of the Internet with relative ease. However, its index was somewhat limited. According to its administrator—whom Wired interviewed anonymously in April 2014—the team behind Grams did not “have the capabilities yet to spider all of the darknet” and had instead resolved to work on “making an automated site submitter for people to submit their sites and get listed” on the search engine. The administrator added that the site “wanted to make it easier for advertisers to buy ads through an automated system”. They admitted that although the site “would love to hire a programmer”, it would be hard to find a programmer they could trust while maintaining anonymity.
Grand plans ahead by the looks of it, but come December 2017 the site had ceased collection, largely due to ongoing difficulty with marketplace collection, but also because of the time required for maintenance of the site and its services.
Kilos: The new heavyweight of dark web search engines
In November 2019, chatter started circulating on cybercriminal forums that a new dark web-based search engine was up and running under the name Kilos. Though it can’t be conclusively confirmed whether Kilos has pivoted directly from Grams or whether the same administrator is behind both projects, the initial similarities are uncanny. The same popular search engine-like aesthetics have been applied and the naming convention has remained.
Kilos search engine interface with advanced filtering options
So which functions does Kilos have to offer that justify its weightier name? Quite a few, as it turns out.
Kilos lives up to its name though in the sense that it allows users to perform even more specific searches from a larger index than Grams did, enabling users to search across six of the top dark web marketplaces for vendors, listings and reviews.
These marketplaces include CannaHome, Cannazon, Cryptonia, Empire, Samsara, and Versus. As shown in the image above, Kilos also appears to have a much more advanced filter function that allows users to create much more specific search queries, filtering on price, shipping origin and destination, specific markets, and displayed currencies. At the time of writing Kilos has already indexed the following from a total of seven marketplaces and six forums:
- 553,994 forum posts
- 68,860 listings
- 2,844 vendors
- 248,159 reviews
Kilos has thus managed to index an unprecedented amount of the dark web’s contents, with numbers that appear to increase by the day. It provides invaluable insight into the contents, products, and vendors of current prominent cybercriminal markets and forums. But it doesn’t stop here.
Since the site’s creation in November 2019, the Kilos administrator has not only focused on increasing the site’s index but has also implemented updates and added new features and services to the site. These updates and features ensure the security and anonymity of its users but have also added a human element to the site not previously seen on dark web-based search engines, by allowing direct communication between the administrator and the users, and also between the users themselves.
Bulking up: new features for Kilos
One of the new updates to the site is a new type of CAPTCHA that prompts users to rank randomized product and vendor feedback by their level of positive or negative sentiment. According to the Kilos administrator, this new type of CAPTCHA was implemented because of the added security it would provide the site as it is allegedly “harder to automate, both for machines and for CAPTCHA cracking APIs”. Other updates to the site include its search algorithm, which has been updated to allow for faster searches, and the advertising system, which has been changed to allow users to bid on listings directly from the listing page as a way of making the bidding process easier.
Kilos CAPTCHA task
Bitcoin Mixer for transactions
The Kilos administrator has also announced a new Bitcoin mixer service called “Krumble”, which is now available in Beta mode. By having its own Bitcoin mixer service, Kilos is yet again matching—and perhaps even upping—the game compared to Grams. According to the Kilos administrator, Krumble takes great effort in ensuring user anonymity compared with other Bitcoin mixers by randomizing the transaction and commission fees, enforcing a randomized transaction delay, and only operating over TOR.
Bitcoin mixer service Krumble
Direct Communication with Kilos Admin
The Kilos administrator has added features that allow for more direct communication, both between the users themselves and between users and the administrator. The administrator created an Ask-Me-Anything page on reddit in February 2020 on which they described themselves as “the owner of a search engine that indexes products for sale on the deep web”.
Live Chat for Members
Next, a live chat function was added to the site that users could use to discuss a variety of topics with each other. According to an update by the Kilos administrator, the site team originally wanted to install an Internet Relay Chat (IRC) client for members to use, but due to an apparent reluctance by “the DNM community” to use an IRC client, they added the live chat function instead.. Although the contents of the live chat are partially accessible to any Kilos user, only registered site members who are logged in are able to use the function. So far members have used this functionality to ask for recommendations for vendors, look for specific products, advertise offerings, and discuss news and updates from dark web forums and marketplaces.
What’s next for Kilos?
Kilos’ growing index, new features, and additional services combined could allow Kilos to continue to grow and position itself as a natural first stop for an increasingly large user base, whether it’s to find and purchase illicit products, search for specific vendors, look for reviews, or stay up to date on current news and updates on markets and forums. Assuming Kilos’ index and features will keep growing and developing at this pace, there will soon be much more data readily available for threat actors and security researchers alike. A lot of it. You could almost say tons of it…
If you’d like to read more into cybercriminal forums, you can view our report The Modern Cybercriminal Forum: an enduring model.
If you’re interested in dark web monitoring, Digital Shadows’ SearchLight monitors across sources where criminals are active, no matter is that is on the open, deep, or dark web. This includes continually monitoring and indexing hundreds of millions of dark web pages, pastes, criminal forums, Telegram, IRC, and I2P pages.If you’d like to see your organization’s exposure on the dark web, you can sign up for a test drive of SearchLight here.