We need help with the strange disappearance of Dancho Danchev
Summary: Zero Day blogger and malware researcher Dancho Danchev has gone missing since August last year and we have some troubling information that suggests he may have been harmed in his native Bulgaria.
Update: After a lot of help from folks, Dancho has resurfaced in a tweet received on Jan 21. We're not going into details---so he can explain, but here's the tweet.
The original post follows:
Zero Day blogger and malware researcher Dancho Danchev (right) has gone missing since August last year and we have some troubling information that suggests he may have been harmed in his native Bulgaria.
Dancho, who was relentless in his pursuit of cyber-criminals, last blogged here on August 18. His personal blog has not been updated since September 11, 2010.
At ZDNet, we made multiple attempts to contact him, to no avail. Telephone numbers are going to Bulgarian language voicemails and our attempts to reach him via a snail mail address also came up empty.
Over the last few months, we have contacted the Bulgarian CERT authorities and used anti-virus contacts there to help us figure out Dancho's disappearance. No one can figure out what happened to Dancho.
Last month, we finally got a mysterious message from a local source in Bulgaria that "Dancho's alive but he's in a lot of trouble." We were told that he's in the kind of trouble to keep him away from a computer and telephone, so it would be impossible to make contact with him.
Just recently, a trusted member of the malware research community reached out to us to say he had received a troubling letter from Dancho on September 9, 2010, about the threat of persecution in Bulgaria.
Here is Dancho's letter:
[Name redacted],
As I consider you as a trusted colleague, and someone who understands the big picture of cyber crime and cyber espionage, I'm attaching you photos of the "current situation in my bathroom", courtesy of Bulgarian Law enforcement+intell services who've been building a case trying to damage my reputation, for 1.5 years due to my clear pro-Western views+the fact that a few months ago, the FBI Attache in Sofia, Bulgaria recommended me as an expert to Bulgarian CERT -> clearly you can see how they say "You're Welcome".
I'm sending you these not with the idea to see them published, but as an insurance in case things get ugly, knowing that a trusted third-party has access to these and can always distribute them to [redacted] mailing list members, and pretty much the entire industry, especially the press.
The LEO behind the whole operation: [ NAME REDACTED ]
I'm in a process of contacting journalists -> just in case.
I hope you're the trusted industry contact that I think you are, and you'll basically keep these somewhere safe. Thank you, and please use my PGP key.
Best regards
Alongside the letter, Dancho attached several photographs on what appears to some sort of bugging device and wires coming out of walls in his apartment:
We are unsure about how to proceed and decided to publish this information in the hope that someone in the know can help shed some light on Dancho's disappearance.
If you have any information on his whereabouts or can help point us in the right direction, please don't hesitate to contact us.
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.




Talkback
Looks like...
Which is not to say that I don't think the situation is serious.
Tough to figure out. From what I can see, it looks odd
RE: We need help with the strange disappearance of Dancho Danchev
RE: We need help with the strange disappearance of Dancho Danchev
RE: We need help with the strange disappearance of Dancho Danchev
Agree it doesn't seem to be a bugging device and probably has nothing to do with him being missing.
RE: We need help with the strange disappearance of Dancho Danchev
Why would such a disguise be extended to show...
And how long has Danchev been in this house? The wiring could easily pre-date him.
RE: We need help with the strange disappearance of Dancho Danchev
RE: We need help with the strange disappearance of Dancho Danchev
Possibly triggered by the stress of actually being watched or threats from the criminal community.
I think I speak for all of us when I say that if you' re reading this Dancho, I wish you the best of luck with whatever is troubling you. Hope you're ok and back blogging soon.
RE: We need help with the strange disappearance of Dancho Danchev
"I think I speak for all of us when I say that if you' re reading this Dancho, I wish you the best of luck with whatever is troubling you. Hope you're ok and back blogging soon."
But I'd go for a change of field :) security related issues are enough don't you agree? :) there are dozens of computer related wonderful topics to blog on!
RE: We need help with the strange disappearance of Dancho Danchev
_ryan
RE: We need help with the strange disappearance of Dancho Danchev
May I suggest Interpol or if he is a U.S. citizen try contacting the U.S. Embassy or Consulate. I would recommend sending the photos and any electronic data you have to them. Perhaps they can help, I don't know but it may be worth a shot.
RE: We need help with the strange disappearance of Dancho Danchev
Diplomatic representation from the US:
chief of mission: Ambassador James B. WARLICK, Jr
embassy: 16 Kozyak Street, Sofia 1407
mailing address: American Embassy Sofia, US Department of State, 5740 Sofia Place, Washington, DC 20521-5740
telephone: [359] (2) 937-5100
FAX: [359] (2) 937-5320
Hey
RE: We need help with the strange disappearance of Dancho Danchev
RE: We need help with the strange disappearance of Dancho Danchev
RE: We need help with the strange disappearance of Dancho Danchev
RE: We need help with the strange disappearance of Dancho Danchev
hmm...
You should look for enemies as the people and corporations he exposed in his blog.
<tinfoil hat>
</tinfoil hat>