Criminal Groups Offer Big Salaries For Cyber Skills

New research from Digital Shadows reveals that criminal groups are promising salaries averaging the equivalent of $360,000 per year to accomplices who can help them target high-worth individuals, such as company executives, lawyers and doctors with extortion scams.
 
These salary promises can be higher still for those with network management, penetration testing, Cyber and Programming skills, with one threat actor willing to pay the equivalent of $768,000 per year, with add-ons and a final salary after the second year of $1,080,000 per year.
 
One principal method of extortion where criminals deem potential victims to be particularly vulnerable is so-called ‘sextortion’. Researchers tracked a sample of sextortion campaigns and found that from July 2018 to February 2019 over 89,000 unique recipients faced some 792,000 extortion attempts against them. An analysis of Bitcoin wallets associated with these scams found that sextortionists could be reaping an average of $540 per victim.
 
The campaigns follow a similar pattern: The extortionist provides the user with a known password as “proof” of compromise, then claims to have video footage of the victim watching adult content online, and finally urges them to pay a ransom to a specified Bitcoin (BTC) address.  However, it is worth noting that other campaigns can be even more sinister, the so-called ‘Hitman’ spam campaign Digital Shadows noted from December 2018 simply claims recipients will be “killed” unless a Bitcoin demand is paid.
 
Extortion is in part being fuelled by the amount of ready-made extortion material readily available on criminal forums. These are lowering the barriers to entry for wannabe criminals with sensitive corporate documents, intellectual property, and extortion manuals being sold on by more experienced criminals to service aspiring extortionists. Blackmail guides, for example, are on sale for less than $10.
 
In one such example, seen by Digital Shadows, the guide specifically focuses on a sextortion tactic whereby the threat actor begins an online relationship with a married man and then threatens to reveal details of the affair with his partner unless a ransom is paid. 
 
The guide claims this extortion method is the easiest for ‘novice’ threat actors to start with, suggesting they could earn between $300-$500 per extortion attempt. Dedicated subsections exist on criminal forums for these type of dating scams.
Even greater levels of sophistication could be around the corner if so-called ‘crowd funding’ schemes take off. In April 2018, threat actor ‘thedarkoverlord’ stole documents belonging to the insurance provider, Hiscox. 
 
This included files related to the 9/11 attacks in the US. The threat actor hoped to play on the public’s appetite for 9/11-related controversy and encourages people to raise funds in order to view the documents. Currently this campaign has amassed some $11,600.
 
Crowdfunding models such as this allow extortionists to raise funds from the general public rather than relying on victims giving in to ransom demands. Organisations dealing with inflammatory or sensational information should therefore consider how they would respond if an attacker opts for this course of action. 
 
Rick Holland, CISO and Head of the Photon Research Team at Digital Shadows, comments: “The research shows that cybercriminal groups are increasing their targeting of high net worth individuals and / or those that hold positions of power within companies. Many threat actor groups are actively on the recruit for members to collaborate with and to help them scale their operations. Holland continues: “Widespread and opportunistic extortion campaigns are also lucrative.
 
The social engineering aspects of these emails prey upon the recipients and entice them into paying the extortion amount. Unfortunately, our analysis of a select number of the campaigns, shows us the criminals have amassed over $300,000. 
 
“Education and minimising your personal and professional online exposure are essential for thwarting extortionists goals. Since the lines between our personal and professional lives are so blurred, firms should educate their staff and tell them never to pay out a sextortion request.”
 
Digital Shadows advises the following to reduce the risk of extortion:
 
• Do not respond to sextortion emails. These scams are generally mass, opportunistic campaigns. Treat them as spam.
 
• Use HaveIBeenPwned to find previously breached accounts. Sextortion emails sometimes include a previously breached password that belongs to the victim in an effort to add legitimacy to the email. If you have email accounts that have been publicly exposed, update the password for the account and enable multi-factor authentication if possible.
 
• Develop a ransomware playbook. Regularly back up data and store sensitive files in detached storage away from the main network. Do not forget to periodically test your back-up and recovery processes. The wrong time to identify flaws in your disaster recovery strategy is after all your critical data has been encrypted.
 
• Shrink your potential attack surface. Make remote-access solutions (such as remote desktop protocol) accessible only over a VPN, and disable all other legacy or unnecessary features to harden your system against attack. Identify your most critical systems and apply vendor patches to publicly known vulnerabilities.
 
• Apply best practices for user permissions. Remove local admin rights, restrict execution privileges on temporary and data folders that ransomware typically execute from, and implement whitelisted application lists.
 
• Secure email end-users. Strong spam filters and restrictions around email attachments can help prevent spam extortion emails and malware from reaching the end-users’ email boxes.
 
• Submit a complaint to the FBI’s IC3. The FBI’s Internet Crime Complaints Center (IC3) accepts complaints from the public regarding scams like ransomware and sextortion. In the UK, contact Action Fraud or you local police authority. 
 
HelpNetSecuriity
 
You Might Also Read:
 
Pay Rates For Security Professionals:
 
 
 
« Cyber-Spies For Hire
US Under Attack By Chinese & Iranian Hackers »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

Tines

Tines

The Tines security automation platform helps security teams automate manual tasks, making them more effective and efficient.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

Hack in the Box Security Conference (HitBSecConf)

Hack in the Box Security Conference (HitBSecConf)

HITBSecConf is a platform for the discussion and dissemination of next generation computer security issues. Our events feature two days of training and a two-day multi-track conference

KZ-CERT

KZ-CERT

KZ-CERT is the national Computer Emergency Response Team for Kazakhstan.

NovaTech Automation

NovaTech Automation

NovaTech products and services make the world’s power grids and essential process industries more reliable, efficient, sustainable and secure.

Smoothwall

Smoothwall

Smoothwall develop intelligent web filtering, Monitoring and security solutions designed to protect users worldwide.

achelos

achelos

achelos is an independent software development company providing innovative technical solutions for micro-processor chips / security chips and embedded systems in security-critical application fields.

Ziroh Labs

Ziroh Labs

Ziroh Labs leverages advanced cryptography to keep your highly sensitive, private data safe throughout the lifecycle of data.

EPIC Insurance Brokers & Consultants

EPIC Insurance Brokers & Consultants

EPIC is an insuarnce broker and consultancy firm. Risk management services include risk consultancy and cybersecurity insurance.

KBR

KBR

To help governments and other agencies to combat cyber threats, KBR is safeguarding their most valuable systems with sophisticated tools, hardware and training.

Cigent Technology

Cigent Technology

Cigent keeps the most valuable asset in your organization safe—your data. Our advanced endpoint and managed network security solutions prevent ransomware and data theft.

Firmus

Firmus

As the leading penetration testing services provider in Malaysia, Firmus evaluates the ability of your internal or external information assets to withstand attacks.

Datastream Cyber Insurance

Datastream Cyber Insurance

DataStream Cyber Insurance is designed to give SMB’s across the US greater confidence in the face of increasing cyber attacks against the small and medium business community.

Infosec Institute

Infosec Institute

Infosec is a leading cybersecurity training company, we help IT and security professionals advance their careers with skills development and certifications.

VulnCheck

VulnCheck

VulnCheck helps organizations outpace adversaries with vulnerability intelligence that predicts avenues of attack with speed and accuracy.

NetScout Systems

NetScout Systems

NetScout assures digital business services against disruptions in availability, performance, and security.

Synagex

Synagex

Synagex Modern IT is a simple IT and cybersecurity solution for businesses.

FoxPointe Solutions

FoxPointe Solutions

FoxPointe Solutions is a full-service cyber risk management and compliance firm.