Home > Security News > Online crime as ugly as ever
Security News:
EMAIL THIS

Online crime as ugly as ever

By Victor R. Garza, Contributor
30 Aug 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

MOUNTAIN VIEW, Calif. – According to the keynote speaker at this year's Conference on Email and Antispam (CEAS), spam is still driven by bands of underground Internet miscreants driven by a lust for money and mischief.

Rob Thomas, CEO and research fellow with Internet security think-tank Team Cymru, opened the third annual gathering of antispam researchers and software engineers with a lively presentation on the 'underground economy.'

Thomas said in his work with clients he has come across villains who are driving a mature and robust economy that continues to expand.

"It's grown well beyond [credit] cards, warez and porn... now you can get everything; credit cards, CVV [credit card verification numbers], bots, bot code, DoS nets" and even U.S. visas, birth certificates and passports, which can go for as much as $500 each.

Thomas went on to describe the early union of spammers and bot herders, a term for individuals who use scores of machines running automated software to distribute spam, generating a substantial revenue opportunity for spammers and created the myriad of email headaches that network administrators face today.

Today Thomas said the underground economy is rife with data stolen and traded illegally in much the same way that traders in a bazaar or flea market sell their wares. In fact, he said, stolen data is costing businesses in the UK $150,000 in U.S. dollars each hour.

Included in this information Thomas said are "fulls" or fully identifying information of distinct victims including names, addresses, phone numbers, mother's maiden names, Social Security numbers, secret questions, secret answers, banking information and more. While credit cards may not be quite as alluring as they once were, numbers from the major credit cards firms are available, including Visa, MasterCard and Discover and even the coveted American Express Centurion cards, "they love those, and yes, they do trade them".

Thomas went on to talk about the communication methods used by these miscreants to interact including a variety of different instant messaging, peer-to-peer and stolen Skype VoIP accounts. He said the Skype accounts used to conduct miscreant business are usually used in pairs and, once used, are disposed of..

Most online criminals, according to Thomas, by and large are not all that tech savvy, and for them "it's not about technology, it's about crime," since most of these individuals were "selling drugs on the street and then found that it was a lot easier to clean out bank accounts from their La-Z-Boy."

And when it comes to online fraud, spammers aren't strictly interested in credit cards. Thomas said online banking accounts are just as susceptible to subversion and hijacking. He pointed out that access to a bank account containing roughly $3 million dollars had been sold from one criminal to another for just pennies on the dollar.

While the bank in question compensated the victim, in this case Thomas pointed out that someone with that much money has pull with the bank, "but if it had been someone with $800, which we more commonly see, what does the person with eight hundred bucks have in the way of clout?"

Thomas noted out that it's a problem that isn't going away. "People are getting nickeled and dimed, but for these people nickels and dimes are all they have."

Victor R. Garza is a technology/security consultant and lecturer at the Naval Postgraduate School in Monterey, Calif.

Tags: Hacker Tools and Techniques: Underground Sites and Hacking GroupsEmail and Messaging Threats (spam, phishing, instant messaging)Security Awareness Training and Internal ThreatsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Hacker Tools and Techniques: Underground Sites and Hacking Groups
Russian cybercriminals target H1N1 Swine Flu fears
Metasploit Project acquisition ups ante for penetration testing market
Successful rogue antivirus hinges on social engineering
DEFCON survey suggests hacker community on vacation
DoD urges less network anonymity, more PKI use
New hacker skills optimize revenue
Maturing cybercriminal economy buoyed by business savvy hackers
Juniper pulls ATM hacking presentation from Black Hat
Botnet platform helps cybercriminals bid for zombie PCs
Man pleads guilty in online banking hacking scam

Email and Messaging Threats (spam, phishing, instant messaging)
Yahoo login credentials at risk to hijacking attack
The world's top 5 riskiest domains
How to secure a .pdf file
Top spammer gets four years in jail for stock fraud scheme
New Zeus spam poses as Social Security statements
Messaging security risks have upper hand on solutions
Web-based attacks skyrocket, pirating sites surge, security firms say
Pushdo botnet uses Facebook to spread malicious email attachment
Scareware report highlights successful business model
How to prevent phishing attacks with social engineering tests
Email and Messaging Threats (spam, phishing, instant messaging) Research

Security Awareness Training and Internal Threats
Information security book excerpts and reviews
Schneier-Ranum face-off, part 2: Social networking
Health Net breach failure of security policy, technology
Health Net healthcare data breach affects1.5 million
Massive T-Mobile UK security breach involves insiders
Secure your remote users in 2010
Layoffs prompt insider threat fears, cybersecurity survey finds
How to use Internet security threat reports
Creating a HIPAA employee training program
Successful rogue antivirus hinges on social engineering

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
black hat  (SearchSecurity.com)
cracker  (SearchSecurity.com)
cyberextortion  (SearchSecurity.com)
cyberterrorism  (SearchSecurity.com)
Echelon  (SearchSecurity.com)
hacker  (SearchSecurity.com)
man in the middle attack  (SearchSecurity.com)
van Eck phreaking  (SearchSecurity.com)
zero-day exploit  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts