Home > Security News > Criminals find safety in cyberspace
Security News:
EMAIL THIS

Criminals find safety in cyberspace

By Bill Brenner, Senior News Writer
18 Dec 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

A new report from McAfee Inc. explains one of the reasons why so many criminals have set their sights on cyberspace. It's simply safer and more lucrative to steal online from the comfort of the nearest Starbucks than to jump out at people in dark alleys.
It's a lot safer to run a botnet than it is to go to the street and break someone's kneecaps.
David Marcus,
security research and communications manager, McAfee Avert Labs

That has made it easier for organized criminal outfits to recruit people to do their bidding -- including students as young as 14, said David Marcus, security research and communications manager for McAfee Avert Labs in Santa Clara, Calif.

"For organized crime, the Internet is the best thing to come along since bootlegging and moonshine," Marcus said. "And it's a lot safer to run a botnet than it is to go to the street and break someone's kneecaps." Organized crime is recruiting teenagers who feel safer doing illegal activity online than in the street, according to a McAfee Virtual Criminology Report.

The second annual, which draws on input from Europe's leading high-tech crime units and the FBI, suggests that criminal outfits are targeting top students from leading academic institutions and helping them acquire the skills to commit high-tech crime on a massive scale. The tactics used to groom them are much like those the KGB used during the cold war, the report said.

"Organized crime lacks the technical skills to rob people online, but it does have the money to find 16-year-olds, get them trained and put them in a company where they can be an insider threat," Marcus said.

The sense of immunity people find in cyberspace also makes them more willing to engage in criminal activity than if they were operating in the real world. Someone who won't steal an elderly woman's pocket book might be willing to sit in a Starbucks and try to penetrate a network, Marcus said, adding, "They sit there sipping coffee and looking at their laptop, and for all people know they're just surfing the Internet. And they don't have to see the victim."
Cyber criminals:
Online crime as ugly as ever

Spy vs. Spy

Feds court infosec pros in fight against cybercrime

Given the situation, IT shops should expect and prepare for increasingly nasty and prolific threats in 2007 and beyond, Marcus said. IT professionals should also start thinking of a game plan to secure hand-held devices because that's the next big target of these criminals.

"Mobile is a big area of fascination for both the research community and the criminals," Marcus said. "We're not seeing a lot of mobile malware now, but you'll see more of it in the next 10 months because hand-held devices are getting more advanced and becoming more like your PC."

He said governments around the world also need to deal with the threat by making better global laws to address issues like extradition. Criminals are more likely to base themselves in countries without extradition laws, he said, adding, "Why would I traffic in drugs and be in danger when I can do this other stuff in an anonymous atmosphere in another country with no extradition laws?"

Among the report's other findings:

  • Cybercriminals are increasingly resorting to psychological warfare in order to succeed Phishing emails have increased by approximately 25% over the last year but are harder to detect as they increasingly trick unsuspecting people with ordinary scenarios instead of improbable ones such as sudden cash windfalls.

  • Cybercriminals are being drawn to the huge crowds of social networking and community sites. Loading fake profiles and pages with adware, spyware and Trojans, malware authors are cashing in on their popularity. They are also collating personal information divulged online to formulate virtual twin identities for fraudulent purposes.

  • Data is continually exposed without the need for sophisticated attacks. Password proliferation for consumer and work devices means often simple guesswork unlocks the door; and removable media devices like USB sticks make it easier to steal inside information.

  • Botnets are now the preferred method for Internet thieves to launch attacks. At least 12 million computers around the world are now compromised and are used for phishing schemes, illegal spamming, spreading pornography and stealing passwords and identities.

  • Smartphones and multifunctional mobile devices are making portable computers essential lifestyle accessories and cybercriminals will increasingly mine them for valuable information in the coming months. The increasing use of Bluetooth and VoIP will also lead to a new generation of phone hacking.

    Tags: Identity Theft and Data Security BreachesEmerging Information Security ThreatsMalware, Viruses, Trojans and SpywareHacker Tools and Techniques: Underground Sites and Hacking GroupsEmail and Messaging Threats (spam, phishing, instant messaging)VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Identity Theft and Data Security Breaches
    Health Net healthcare data breach affects1.5 million
    Massive T-Mobile UK security breach involves insiders
    Chip and PIN adoption serves lesson for U.S. payment industry
    Group to shed light on secure identity management threats
    Heartland CIO is critical of First Data's credit card tokenization plan
    Heartland CIO on end-to-end encryption, credit card tokenization
    Heartland CIO on PCI, E3 project
    Visa probes tokens, encryption for PCI card data protection
    University data breach exposes 163,000 women to identity theft
    TJX thrives following breach, bucks sour economy

    Emerging Information Security Threats
    Best practices for (small) botnets
    Cybersecurity grant to fund research into critical infrastructure threats
    RSA security conference 2010: news, interviews and updates
    Hackers to sharpen malware, malicious software in 2010
    Modern malware, stealthy botnets, adapt quickly, expert says
    New ransomware Trojan pushes victims to buy software
    Bruce Schneier on outsourcing, awareness training
    Marcus Ranum on cyberwarfare, infosec careers
    US-CERT warns of BlackBerry snooping software
    Researchers find thousands of flawed embedded devices

    Malware, Viruses, Trojans and Spyware
    The world's top 5 riskiest domains
    New Zeus spam poses as Social Security statements
    Increase in Gumblar backdoors poses FTP credential problems
    Hackers to sharpen malware, malicious software in 2010
    iPhone worm Rickrolls jailbroken phones
    Israeli Mossad add Trojan Horse to Syrian laptop
    Schneier-Ranum Face-Off: Is antivirus dead?
    Modern malware, stealthy botnets, adapt quickly, expert says
    Computer worm infections up, scareware antivirus down, Microsoft says
    Web-based attacks skyrocket, pirating sites surge, security firms say

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    bot worm  (SearchSecurity.com)
    CISP-PCI  (SearchFinancialSecurity.com)
    cookie poisoning  (SearchSecurity.com)
    drive-by pharming  (SearchSecurity.com)
    extrusion prevention  (SearchSecurity.com)
    identity theft  (SearchSecurity.com)
    parameter tampering  (SearchSecurity.com)
    pretexting  (SearchCIO.com)
    Rock Phish  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts