Inside The Mind Of Cyber Criminals

There are some common misperceptions that security professionals have about cybercrime and the people who do it.

Information sharing amongst security specialists is crucial; in the eyes of a criminal, no company is unique. As a rule of thumb, perpetrators will initially cast a wide net and move downstream toward the easiest prey. It’s more likely to become a victim via common attack vector, rather than to experience a highly sophisticated and tailored attack.

On the other hand, security specialists should never underestimate the determination of an attacker. Highly valuable and quickly sold on underground information such as payment, healthcare, and personally identifiable records, as well as sensitive M&A information, must be identified as a targeted asset, quarantined, and stored encrypted. 

The actionable contingency plan must be rehearsed and quickly activated in the case of a breach including a clear response strategy if extortion is attempted. Security professionals must be aware of upcoming threats and successful mitigation practices when establishing a robust and secure network, making sure the proper data backups are in place.

What are some common misperceptions that security pros have about cyber-crime and the people who do it?

The common misperception about cyber criminals we often observe is that it is assumed that illicit actors have diverse skills and experience, allowing them to initiate a wide range of attacks, subsequently earning a hefty amount of money as a result. In reality, the current underground has shifted toward mass plug-and-play automated services, offering the opportunity to participate in illicit activities to a broad number of novice members. Recorded Future has recently identified a survey, conducted among members of a closed underground community, revealing that the majority of cyber criminals are earning a mere $1,000 to $3,000 a month, while only 20% are earning significantly larger amounts of $20,000 a month or more.

Who are these criminals? Are they part of established criminal groups or one-man shows?

For the most part, the largest demographic of members participating in underground communities are lone actors with a clean criminal record and without any ties to organised syndicates. These criminals tend to maintain a stable day job while partaking in illegal activities mostly on an occasional basis. Often these actors are introduced to the life of cyber-crime during their early college years and remain active many years to follow.

A separate and significantly more sophisticated cohort are cyber-criminal syndicates which maintain a strict hierarchy, comprised of highly skilled members, each with a very narrow set of responsibilities.

A typical group is controlled by a single mastermind “boss”, a very intelligent and highly educated person, and includes bankers with extensive connections in the financial industry to arrange money laundering and cash out of stolen funds. 

Additionally, forgers are responsible for fake documents and supporting paperwork and professional project managers oversee the technical aspects of operations, software engineers, and skilled hackers. 

Some groups include ex-law enforcement agents responsible for information gathering as well as counter-intelligence operations.

Team members tend to have strong ties in real life and often are respected members of their communities, viewed by many as successful businessmen and entrepreneurs. The group will often have a diversified investment portfolio and maintain a presence in real estate, hospitality, and auto-related businesses.

Cyber-criminal syndicates don’t regard themselves as ordinary street criminals and rarely cross paths with everyday gangsters, preferring to remain in the shadows and avoid unnecessary attention from both law enforcement and local mafia branches.

However, on certain occasions, requiring the involvement of a vast number of “troopers,” often, related to a large cash-out operations, a one-time project can be launched through a chain of intermediaries.

What types of research do you feel are most beneficial for an enterprise security team?

We have to understand no silver bullet will solve every security problem. An effective security perimeter has to include the combination of:

  • Automated tools responsible for identification of unusual behavior.
  • Alerts on known IOCs and TTPs.
  • Intelligence obtained from underground communities.
  • Response procedures and guidelines.

Direct access to deep and dark web is crucial, but for a variety of safety reasons, might not be a viable option. Hidden criminal communities are not very fond of researchers, and in certain situations, an inexperienced researcher can draw unnecessary attention to the company and put it in danger.

In one of the recent cases, a poorly trained researcher has openly inquired about penetration solutions in newly adopted infrastructure which was tested at a limited number of corporate locations, immediately observing a sudden surge of malicious activity.

To avoid this, we would recommend utilising the help of professional threat intelligence providers that operate undercover on a day-to-day basis and are familiar with all of the complex politics of these communities.

Several providers allow users to research deep and dark web sources in a safe and secure manner, without risking the integrity of the organisation.

Companies also must foster internal security teams, ensuring they are capable of discovering relevant and actionable data as well as stimulating the unrestricted environment, providing the opportunity to initiate counter-measures quickly, and minimising the red-tape procedures.

RecorderdFuture:              Cybercrime Inc. Hackers Model Themselves On Big Business:

 

« Irish Law Firms Experience 50% Increase In Cyberattacks
Snowden Loses In Norway »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Libraesva

Libraesva

Libraesva specialize in Email Security. From Email Security, Phishing Awareness and Email Archiver. We can assist you with any email issues you may have.

Cobwebs Technologies

Cobwebs Technologies

Cobwebs Technologies provide web intelligence solutions for Law Enforcement (including cybercrime), Intelligence Agencies and Federal Agencies.

Verve Industrial

Verve Industrial

Verve specialize in providing software and services to help protect and secure critical industrial control systems.

Centre for Cyber Security (CFCS) - Denmark

Centre for Cyber Security (CFCS) - Denmark

The Centre for Cyber Security is the Danish national IT security authority, Network Security Service and Centre for Excellence within cyber security.

Devel

Devel

Devel is a LATAM cybersecurity company specialized in providing red, blue and purple team services for the financial sector.

Center for Applied Cybersecurity Research (CACR) - University of Indiana

Center for Applied Cybersecurity Research (CACR) - University of Indiana

CACR serves Indiana and the nation by tackling cyber risk in research and other unusual environments through agile, holistic, principle-based cybersecurity.

Quantea

Quantea

Our multi-patented solutions - QP Series Network Analytics Accelerator appliance and PureInsight Analytics Software Suite allows you to capture, analyze, store, replay, network traffic data.

Bitfury Group

Bitfury Group

Bitfury Group is the largest full-service blockchain technology company in the world.

Augusta HiTech

Augusta HiTech

Augusta Hitech is a focused product development, software services and technology consulting company. Our Vision is to become the most socially impactful and innovative technology company in the world

Cyber Talents

Cyber Talents

CyberTalents is on a mission to close the gap of cyber security professionals shortage across the globe.

Nameshield Group

Nameshield Group

Nameshield is one of most experienced domain name registrars, trademark protection specialists and managers of online reputational risk in the world today.

Enclave Networks

Enclave Networks

Our mission is to give IT professionals a simple way to rapidly build secure connectivity between any application, computer system, device or infrastructure - regardless of the underlying network.

SAIFE

SAIFE

SAIFE has adapted a Software Defined Perimeter approach and paired it with a Zero Trust model that defines access by the user, their device, and where they are located.

Boeing

Boeing

Boeing is the world's largest aerospace company and leading manufacturer of commercial jetliners, defense, space and security systems.

Reach Security

Reach Security

Reach is the first generative AI platform purpose-built to empower enterprise security teams. With Reach, organizations measure, manage, and improve their enterprise security posture at scale.

ITRM

ITRM

ITRM are one of the UK’s top managed service providers and offer a range of award-winning IT solutions, from ad-hoc consultancy to cyber security.