Home > Security News > Criminals find safety in cyberspace
Security News:
EMAIL THIS

Criminals find safety in cyberspace

By Bill Brenner, Senior News Writer
18 Dec 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

A new report from McAfee Inc. explains one of the reasons why so many criminals have set their sights on cyberspace. It's simply safer and more lucrative to steal online from the comfort of the nearest Starbucks than to jump out at people in dark alleys.
It's a lot safer to run a botnet than it is to go to the street and break someone's kneecaps.
David Marcus,
security research and communications manager, McAfee Avert Labs

That has made it easier for organized criminal outfits to recruit people to do their bidding -- including students as young as 14, said David Marcus, security research and communications manager for McAfee Avert Labs in Santa Clara, Calif.

"For organized crime, the Internet is the best thing to come along since bootlegging and moonshine," Marcus said. "And it's a lot safer to run a botnet than it is to go to the street and break someone's kneecaps." Organized crime is recruiting teenagers who feel safer doing illegal activity online than in the street, according to a McAfee Virtual Criminology Report.

The second annual, which draws on input from Europe's leading high-tech crime units and the FBI, suggests that criminal outfits are targeting top students from leading academic institutions and helping them acquire the skills to commit high-tech crime on a massive scale. The tactics used to groom them are much like those the KGB used during the cold war, the report said.

"Organized crime lacks the technical skills to rob people online, but it does have the money to find 16-year-olds, get them trained and put them in a company where they can be an insider threat," Marcus said.

The sense of immunity people find in cyberspace also makes them more willing to engage in criminal activity than if they were operating in the real world. Someone who won't steal an elderly woman's pocket book might be willing to sit in a Starbucks and try to penetrate a network, Marcus said, adding, "They sit there sipping coffee and looking at their laptop, and for all people know they're just surfing the Internet. And they don't have to see the victim."
Cyber criminals:
Online crime as ugly as ever

Spy vs. Spy

Feds court infosec pros in fight against cybercrime

Given the situation, IT shops should expect and prepare for increasingly nasty and prolific threats in 2007 and beyond, Marcus said. IT professionals should also start thinking of a game plan to secure hand-held devices because that's the next big target of these criminals.

"Mobile is a big area of fascination for both the research community and the criminals," Marcus said. "We're not seeing a lot of mobile malware now, but you'll see more of it in the next 10 months because hand-held devices are getting more advanced and becoming more like your PC."

He said governments around the world also need to deal with the threat by making better global laws to address issues like extradition. Criminals are more likely to base themselves in countries without extradition laws, he said, adding, "Why would I traffic in drugs and be in danger when I can do this other stuff in an anonymous atmosphere in another country with no extradition laws?"

Among the report's other findings:

  • Cybercriminals are increasingly resorting to psychological warfare in order to succeed Phishing emails have increased by approximately 25% over the last year but are harder to detect as they increasingly trick unsuspecting people with ordinary scenarios instead of improbable ones such as sudden cash windfalls.

  • Cybercriminals are being drawn to the huge crowds of social networking and community sites. Loading fake profiles and pages with adware, spyware and Trojans, malware authors are cashing in on their popularity. They are also collating personal information divulged online to formulate virtual twin identities for fraudulent purposes.

  • Data is continually exposed without the need for sophisticated attacks. Password proliferation for consumer and work devices means often simple guesswork unlocks the door; and removable media devices like USB sticks make it easier to steal inside information.

  • Botnets are now the preferred method for Internet thieves to launch attacks. At least 12 million computers around the world are now compromised and are used for phishing schemes, illegal spamming, spreading pornography and stealing passwords and identities.

  • Smartphones and multifunctional mobile devices are making portable computers essential lifestyle accessories and cybercriminals will increasingly mine them for valuable information in the coming months. The increasing use of Bluetooth and VoIP will also lead to a new generation of phone hacking.

    Tags: Identity Theft and Data Security BreachesEmerging Information Security ThreatsMalware, Viruses, Trojans and SpywareHacker Tools and Techniques: Underground Sites and Hacking GroupsEmail and Messaging Threats (spam, phishing, instant messaging)VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


    RELATED CONTENT
    Identity Theft and Data Security Breaches
    Researchers predict SSNs, crack algorithm putting identities at risk
    TJX to pay $9.75 million for data breach investigations
    Man pleads guilty in online banking hacking scam
    White House cybersecurity czar faces major hurdles
    Heartland breach cost $12.6 million, CEO says
    An inside look at security log management forensics investigations
    LexisNexis investigates breach, notifies thousands
    Senators hear call for federal cybersecurity restructuring
    Former Federal Reserve Bank employee arrested
    Attackers cash in on fundamental data handling mistakes, Verizon finds

    Emerging Information Security Threats
    DDoS attacks hit U.S., South Korean government websites
    New attack code targets Microsoft ActiveX zero-day vulnerability
    Adobe ColdFusion websites being compromised
    Antispyware buying guide for Indian enterprises
    ATM malware lets attackers take over machines
    FTC shutters rogue ISP for hosting malicious content, botnets
    The failing war against cybercriminals
    White House cybersecurity czar faces major hurdles
    Cybercrime and threat management
    The Pipe Dream of No More Free Bugs

    Malware, Viruses, Trojans and Spyware
    ISP shutdown latest cat-and-mouse game with hackers
    How to get rid of malware, botnets on a hospital IT network
    How can search results lead to malware?
    Should a national cybersecurity strategy include offensive botnets?
    How to prevent mobile phone spying
    How to defend against rogue DHCP server malware
    New Trojan stealing FTP credentials, attacking FTP websites
    Cybercriminals exploit Michael Jackson, Farrah Fawcett deaths
    When BIOS updates become malware attacks
    Antispyware buying guide for Indian enterprises

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    bot worm  (SearchSecurity.com)
    CISP-PCI  (SearchFinancialSecurity.com)
    cookie poisoning  (SearchSecurity.com)
    drive-by pharming  (SearchSecurity.com)
    extrusion prevention  (SearchSecurity.com)
    identity theft  (SearchSecurity.com)
    parameter tampering  (SearchSecurity.com)
    pretexting  (SearchCIO.com)
    Rock Phish  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    Focused on Channel Security?
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts