News: 1587038405

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Bad news: So much of your personal data has been hacked that lesson manuals on how to use it are the latest hot property

(2020/04/16)


With more people looking to get into the online crime racket and huge caches of personal information cheap and easy to come by, documents describing the process of committing (and getting away with) online fraud are becoming hot commodities.

This according to [1]a study [PDF] from security biz Terbium Labs, which analyzed three massive darknet markets, and found that fraud guides were by far the most popular item being sold. The study was based on observations of Empire Market, White House Market, and Canadian HeadQuarters, three underground souks the researchers likened to Amazon and eBay in their massive footprints and use of ratings to rank merchants.

The Terbium team reckons that these guides, which help newbie crooks through the process of things like setting up bank fronts, crafting phishing emails and stealing money out of victim accounts, make up just under half (49 per cent) of all data transactions on the store (not including drugs or for-hire services like DDoS attacks).

"What they have in common is detailed information on how to export an organization's current policies," Terbium Labs said of the guides. "Oftentimes, the content in fraud guides doesn't require any prior knowledge from the reader (criminal) and can realistically lead to successful execution of the outlined steps."

By comparison, financial data records were a distant second, only accounting for 15.6 per cent of all transactions, followed by non-financial account details, which made up 12.2 per cent of what people were buying.

The merchants are not only selling more of the guides, they are also getting a better price for them than stolen financial records generally fetch. A single fraud guide will typically run you about $7.80, while account details will vary widely in prices and low-value credentials could only for for about $1 each.

"We routinely see stolen data for sale on these markets for surprisingly low prices, considering how expensive the consequences of stolen data can be to an organization," said Terbium chief strategy officer Tyler Carbone. "The missing piece here is the way criminals buy that data and make use of available knowledge and tools to exploit it."

Another day, another Google cull: Chocolate Factory axes 49 malicious Chrome extensions from web store [2]READ MORE

This despite what Terbium says is a skeptical attitude toward the guides and their accuracy of information. Despite not expecting many of the schemes in the guides to actually work (criminals can't be trusted - go figure), would-be hackers are so desperate for material that they buy up the how-to manuals in droves.

Interestingly, what Terbium advises its customers to do is learn about what is in these guides and guides and take countermeasures.

In addition to protecting companies from the specific schemes mentioned, this will also play against the greatest weakness of these markets: the common belief among criminals that guides are often unreliable and inaccurate.

"This is a good thing for businesses – if a business purchases a fraud guide early, they can change the affected internal policies immediately and thereby, render that fraud guide useless," Terbium explains.

"As a result, the seller of that fraud guide will be discredited and likely deemed untrustworthy by other criminals." ®

Sponsored: [3]Legacy Modernization: Finding Your Way With Low-Code



[1] https://www.dropbox.com/s/k6vvgotghvz81ql/Data%20Commodity%20Report.pdf?dl=0

[2] https://www.theregister.co.uk/2020/04/15/google_malicious_chrome/

[3] https://go.theregister.co.uk/tl/1936/-8553/legacy-modernization-finding-your-way-with-low-code?td=wptl1936

So, basically businesses should acquire fraud guides

Pascal Monett

Meaning that they should have an account on the Dark Web, a computer that accesses that account, and pay the crims for guidance on they can be compromised.

While I accept that buying a guide would certainly be less expensive than actually having a breach, I would wager that it would be in the best interest of those businesses that deem themselves important enough to do this that the computer they use to access the Dark Web be physically isolated from the company network, with an IP address that cannot be traced to the company and absolutely no company references whatsoever on said computer.

Time to set up the Dark Web Room !

Re: So, basically businesses should acquire fraud guides

Roger Greenwood

Pad that out a bit and you could sell it :-)

Re: So, basically businesses should acquire fraud guides

Joe W

Time to set up the Dark Web Room !

... said the actress to the bishop.

Well... that term sounds a bit.... hm. sketchy. Might attract the, ahem, other kind of customer.

Re: So, basically businesses should acquire fraud guides

Flywheel

physically isolated from the company network, with an IP address that cannot be traced to the company

Oooh, wishful thinking, or you work for the UK "Government"...

When there's a gold rush on

Christopher Reeve's Horse

Don't join the rush, start selling shovels.

Piffy aphorisms aside, why would anyone trust a guide to fraud that's sold by fraudsters? Honour amongst thieves? Do they have some sort of 5 star ratings and review system? I barely trust reviews on most of the 'normal' internet (the Light Web?).

Re: When there's a gold rush on

doublelayer

Very good point, but they actually do have a ratings system where accounts need to be verified in order to post reviews. It's weird how normal these sites can look if you ignore what the products are.

Less than you'd think?

Pete 2

> The Terbium team reckons that these guides, ...

> make up just under half (49 per cent) of all data transactions on the store (not including drugs or for-hire services like DDoS attacks)

So in reality, just a tiny fraction - when you exclude all the high profit stuff!

It also makes you wonder what is in these "how to" guides for online fraud.

I can imagine how the advertising goes:

Buy my book on how to commit online fraud. Only ₿1

and inside the book is just the sentence:

Create an advertisement for a book telling people how to commit online fraud.

Re: Less than you'd think?

Yet Another Anonymous coward

Dress that up with a fancy logo and you are basically a management consultancy

Doctor Syntax

If each business buys a copy for its own information it means there's still a lot of money in it for the publishers and an incentive to produce more versions. A better option would be to disseminate the contents as widely as possible for free in order to destroy the market. There doesn't seem too much scope for alleging copyright infringements when identifying yourself opens you up to prosecution for conspiracy to commit fraud.

doublelayer

True, but if you publish them where the general public can read them, then you'd better hope that you and everyone else have protected against what it says. What would be useful is to create a closed group of organizations that distribute them internally when they are obtained (and if they can be obtained by theft or without completing a payment I'm all in favor) and another public site where the pathetic wrong ones get released publicly. Anyone who finds that public site won't be able to complete a fraud with the instructions, and we avoid funding the how-to-commit-fraud industry.

An alternate suggestion is that we create some guides of our own, which we submit to the reviewers on these sites until they let us on, then we send all those who purchase it a PDF of that guide but with extra malware inserted. Bonus points if the malware can be written to turn these people in.

Take me drunk, I'm home again!