Interviews

Hacking markets

by Mark Rowe

Black and gray markets for computer hacking tools, services and byproducts such as stolen credit card numbers continue to expand, creating an increasing threat to businesses, governments and computer users. That’s according to a new study by the US research body RAND Corporation.

The US researchers point to tne example of the December 2013 breach of retail giant Target, in which data from about 40 million credit cards and 70 million user accounts was hijacked. Within days, that data appeared — available for purchase — on black market websites.

Lillian Ablon was lead author of the study, an information systems analyst at RAND, a nonprofit research organization.She said: “Hacking used to be an activity that was mainly carried out by individuals working alone, but over the last 15 years the world of hacking has become more organised and reliable. In certain respects, cybercrime can be more lucrative and easier to carry out than the illegal drug trade.”

The growth in cybercrime has been assisted by sophisticated and specialized markets that freely deal in the tools and the spoils of cybercrime. These include items such as exploit kits (software tools that can help create, distribute, and manage attacks on systems), botnets (a group of compromised computers remotely controlled by a central authority that can be used to send spam or flood websites), as-a-service models (hacking for hire) and the fruits of cybercrime, including stolen credit card numbers and compromised hosts.

In the wake of several highly-publicised arrests and an increase in the ability of law enforcement to take down some markets, access to many of these black markets has become more restricted, with cybercriminals vetting potential partners before offering access to the upper levels. That said, once in, there is very low barrier to entry to participate and profit, according to the report.

RAND researchers did more than two dozen interviews with cybersecurity and academics, security researchers, news reporters, security vendors and law enforcement officials. The study outlines the characteristics of the cybercrime black markets, with consideration given to botnets and their role in the black market, and “zero-day” vulnerabilities (software bugs that are unknown to vendors and without a software patch). Researchers also examine various projections and predictions for how the black market may evolve.

What makes these black markets notable is their resilience and sophistication, Ablon said. Even as consumers and businesses have fortified their activities in reaction to security threats, cybercriminals have adapted. More law enforcement arrests has resulted in hackers going after bigger targets. More and more crimes have a digital component.

The study says there will be more activity in “darknets,” more checking and vetting of participants, more use of crypto-currencies such as Bitcoin, greater anonymity capabilities in malware, and more attention to encrypting and protecting communications and transactions. Helped by such markets, the ability to attack will likely outpace the ability to defend.

Hyper-connectivity will create more points of presence for attack and exploitation so that crime increasingly will have a networked or cyber component, creating a wider range of opportunities for black markets. Exploitations of social networks and mobile devices will continue to grow. There will be more hacking-for-hire, as-a-service offerings and cybercrime brokers.

However, there is disagreement on who will be the most affected by the growth of the black market, what products will be on the rise and which types of attacks will be more prevalent, Ablon said.

The study, “Markets for Cybercrime Tools and Stolen Data: Hackers’ Bazaar,” can be found at www.rand.org. Other authors of the study are Martin Libicki and Andrea A Golay. Support for the study was provided by Juniper Networks as part of a multiphase study on future cybersecurity.

Related News

  • Interviews

    Q&A with Daren Blackwell

    by Mark Rowe

    Here’s a Q&A with Daren Blackwell, Yodel’s director of security. Briefly to introduce Daren, pictured, he has a background in logistics security,…

  • Interviews

    Digital and trust

    by Mark Rowe

    In conversations with banking and finance customers around the world, I hear the same message again and again: we must embrace digital…

Newsletter

Subscribe to our weekly newsletter to stay on top of security news and events.

© 2024 Professional Security Magazine. All rights reserved.

Website by MSEC Marketing