Bad news: So much of your personal data has been hacked that lesson manuals on how to use it are the latest hot property
- Reference: 1587038405
- News link: https://www.theregister.co.uk/2020/04/16/cybercrimeby_fraud_lessons/
- Source link:
This according to [1]a study [PDF] from security biz Terbium Labs, which analyzed three massive darknet markets, and found that fraud guides were by far the most popular item being sold. The study was based on observations of Empire Market, White House Market, and Canadian HeadQuarters, three underground souks the researchers likened to Amazon and eBay in their massive footprints and use of ratings to rank merchants.
The Terbium team reckons that these guides, which help newbie crooks through the process of things like setting up bank fronts, crafting phishing emails and stealing money out of victim accounts, make up just under half (49 per cent) of all data transactions on the store (not including drugs or for-hire services like DDoS attacks).
"What they have in common is detailed information on how to export an organization's current policies," Terbium Labs said of the guides. "Oftentimes, the content in fraud guides doesn't require any prior knowledge from the reader (criminal) and can realistically lead to successful execution of the outlined steps."
By comparison, financial data records were a distant second, only accounting for 15.6 per cent of all transactions, followed by non-financial account details, which made up 12.2 per cent of what people were buying.
The merchants are not only selling more of the guides, they are also getting a better price for them than stolen financial records generally fetch. A single fraud guide will typically run you about $7.80, while account details will vary widely in prices and low-value credentials could only for for about $1 each.
"We routinely see stolen data for sale on these markets for surprisingly low prices, considering how expensive the consequences of stolen data can be to an organization," said Terbium chief strategy officer Tyler Carbone. "The missing piece here is the way criminals buy that data and make use of available knowledge and tools to exploit it."
Another day, another Google cull: Chocolate Factory axes 49 malicious Chrome extensions from web store [2]READ MORE
This despite what Terbium says is a skeptical attitude toward the guides and their accuracy of information. Despite not expecting many of the schemes in the guides to actually work (criminals can't be trusted - go figure), would-be hackers are so desperate for material that they buy up the how-to manuals in droves.
Interestingly, what Terbium advises its customers to do is learn about what is in these guides and guides and take countermeasures.
In addition to protecting companies from the specific schemes mentioned, this will also play against the greatest weakness of these markets: the common belief among criminals that guides are often unreliable and inaccurate.
"This is a good thing for businesses – if a business purchases a fraud guide early, they can change the affected internal policies immediately and thereby, render that fraud guide useless," Terbium explains.
"As a result, the seller of that fraud guide will be discredited and likely deemed untrustworthy by other criminals." ®
Sponsored: [3]Legacy Modernization: Finding Your Way With Low-Code
[1] https://www.dropbox.com/s/k6vvgotghvz81ql/Data%20Commodity%20Report.pdf?dl=0
[2] https://www.theregister.co.uk/2020/04/15/google_malicious_chrome/
[3] https://go.theregister.co.uk/tl/1936/-8553/legacy-modernization-finding-your-way-with-low-code?td=wptl1936
Re: So, basically businesses should acquire fraud guides
Pad that out a bit and you could sell it :-)
Re: So, basically businesses should acquire fraud guides
Time to set up the Dark Web Room !
... said the actress to the bishop.
Well... that term sounds a bit.... hm. sketchy. Might attract the, ahem, other kind of customer.
Re: So, basically businesses should acquire fraud guides
physically isolated from the company network, with an IP address that cannot be traced to the company
Oooh, wishful thinking, or you work for the UK "Government"...
When there's a gold rush on
Don't join the rush, start selling shovels.
Piffy aphorisms aside, why would anyone trust a guide to fraud that's sold by fraudsters? Honour amongst thieves? Do they have some sort of 5 star ratings and review system? I barely trust reviews on most of the 'normal' internet (the Light Web?).
Re: When there's a gold rush on
Very good point, but they actually do have a ratings system where accounts need to be verified in order to post reviews. It's weird how normal these sites can look if you ignore what the products are.
Less than you'd think?
> The Terbium team reckons that these guides, ...
> make up just under half (49 per cent) of all data transactions on the store (not including drugs or for-hire services like DDoS attacks)
So in reality, just a tiny fraction - when you exclude all the high profit stuff!
It also makes you wonder what is in these "how to" guides for online fraud.
I can imagine how the advertising goes:
Buy my book on how to commit online fraud. Only ₿1
and inside the book is just the sentence:
Create an advertisement for a book telling people how to commit online fraud.
Re: Less than you'd think?
Dress that up with a fancy logo and you are basically a management consultancy
If each business buys a copy for its own information it means there's still a lot of money in it for the publishers and an incentive to produce more versions. A better option would be to disseminate the contents as widely as possible for free in order to destroy the market. There doesn't seem too much scope for alleging copyright infringements when identifying yourself opens you up to prosecution for conspiracy to commit fraud.
True, but if you publish them where the general public can read them, then you'd better hope that you and everyone else have protected against what it says. What would be useful is to create a closed group of organizations that distribute them internally when they are obtained (and if they can be obtained by theft or without completing a payment I'm all in favor) and another public site where the pathetic wrong ones get released publicly. Anyone who finds that public site won't be able to complete a fraud with the instructions, and we avoid funding the how-to-commit-fraud industry.
An alternate suggestion is that we create some guides of our own, which we submit to the reviewers on these sites until they let us on, then we send all those who purchase it a PDF of that guide but with extra malware inserted. Bonus points if the malware can be written to turn these people in.
So, basically businesses should acquire fraud guides
Meaning that they should have an account on the Dark Web, a computer that accesses that account, and pay the crims for guidance on they can be compromised.
While I accept that buying a guide would certainly be less expensive than actually having a breach, I would wager that it would be in the best interest of those businesses that deem themselves important enough to do this that the computer they use to access the Dark Web be physically isolated from the company network, with an IP address that cannot be traced to the company and absolutely no company references whatsoever on said computer.
Time to set up the Dark Web Room !