Showing posts with label cybercrime. Show all posts
Showing posts with label cybercrime. Show all posts
Monday, November 27, 2017
Webinar: Is Cognitive Computing the Next Step to Help Fight Cybercrime?
On December 7, 2017, at 10 AM EST, James Bone, author of Cognitive Hack: The New Battleground in Cybersecurity ... the Human Mind, is conducting a webinar on "Is Cognitive Computing the Next Step to Help Fight Cybercrime?"
Thursday, June 2, 2016
New Studies of Russian Ransomware: How Much Users Pay and How Much Money They Make
This morning, deep and dark web intelligence firm Flashpoint released the findings from a five month study of an organized Russian ransomware campaign.
The new research reports, titled Inside an Organized Russian Ransomware Campaign and Hacking Healthcare, detail the pay out schemes and how cybercriminals are using Ransomware as a Service (RaaS) to successfully target victims, with the healthcare industry being identified as a priority target.
The reports detail ransomware campaign key metrics, including average salaries for various members of ransomware schemes, ransom amounts per US victim, and average monthly ransom payments as well as some of the latest healthcare-focused attacks and the response in underground forums.
The reports can be found at Ransomware as a Service and Hacking Healthcare.
Friday, October 31, 2014
Cybersecurity Nightmares
It's Halloween, and it's not just trick-and-treaters that scare us, or TK Keanini. Keanini, Chief Technology Officer at Lancope, has compiled a number of short and horrifying cybersecurity scenarios entitled "Welcome to My Cyber Security Nightmare."
Welcome to My Cybersecurity Nightmare
This past year, we have seen some pretty scary stuff happen in cybersecurity. Being that Halloween is almost here; I thought I would share with you some scenarios that keep me up at night. These are scenarios that we are not ready to battle, and that are well beyond the horrific headlines we read on a daily basis. If you enjoy a good scare, read on.
User Participation in Cyber-Attacks
Most of the resources cybercriminals use to carry out their objectives are acquired through some method that results in compromised computers on the Internet. These resources remain available until the user or organization detects and remediates the incident. But what if the user participated willingly? Instead of bad guys having to compromise hosts, what if they instead cut other people such as corporate insiders in on the profits? Given crypto currency, the TOR network, and a few other factors, this could be a nightmare scenario, as we are not ready for this type of surge in distributed attacks.
The recruitment for this could be something like the ‘work from home’ signs you see around your town. The work could be as easy as downloading and installing a package and could earn the host user as much as $10.00/day. That is $300.00/month for someone to simply leave their computer running and connected. The average citizen is not likely to know what type of activity their computer is involved in on a daily basis.
The end result of this scenario would be a massive number of networked computers available for distributed denial-of-service, cryptographic brute forcing, or remote network sniffing. With the cooperation of the host, the capability list is endless, and because they are making money, the host will be motivated to help the cybercriminals persist. Service providers and law enforcement are not ready for this type of attack. This could lead to botnet armies with size and capabilities we have never seen before.
Expansion of Capability Marketplaces
Another nightmare scenario is for cybercriminals to expand their marketplace networks. Today you look at coordination networks like Uber, Instacart, Care.com, etc. These services are facilitators connecting a consumer who wants something delivered with a network of people who can deliver it.
Now think of applying this pattern to cybercrime. On one end there is a criminal who would like the login credentials of a Global 2000 executive. Via TOR networking, they go to a site where they can place their request, submit their crypto currency, and a skilled global workforce accepts this objective and delivers it within the terms of the agreement. This lowers the coordination cost for cybercrime to near zero and connects the demand with the supply in ways that have never been seen to date.
Because so many people are motivated by money, a service like this could turn citizens into cybercriminals if they believe they cannot get caught and that they can easily make a few bucks on the side.
The last thing I will say about this type of participation and marketplace networks is that they fragment security events into small, seemingly disconnected pieces where one event might not look harmful, but only when seen as a whole can the impact and significance be evaluated.
The Next Level of Cybercrime: Click to Compromise
Consider a SaaS service that helped a person compute their cybercrime – Cybercrime as a Service.
The power of big data analytics and machine learning can compute amazing insight for businesses, and it can do the same for criminals. A criminal could log in to a website and declare their objective, and the service would compute several attack plans that the criminal could choose from. This would work in the same way that a user is presented with multiple routes to reach a destination when getting directions online.
This Cybercrime as a Service would have social networks mapped, personal information on each individual, language analysis that yields a level of trust between individuals, mapping to various accounts (some of which may have been compromised), etc. All of this would be creating a corpus of data that can lead the criminal through a directed graph leading to the objective (exfiltration of a file, ransomware, etc.).
Remember, cybercrime is a business and profitable businesses only get smarter and more effective. These are things that keep me up at night because in our current state, there is nothing that makes these types of attacks hard to execute for cybercriminals, and they could easily turn from nightmare to reality.
Monday, October 8, 2012
Chinese firms draw fire in House Intelligence report; Cisco cuts ties to China's ZTE after Iran probe
Well, of course the Chinese firms would call the charges "baseless."
Seems like the House Intelligence Committee did something right. Reuters reports that the committee is recommending that Huawai and ZTE be barred from buying US companies because of fears that they could be used for cyber-espionage. Of course, depending on who wins the Presidential election next month, the committee's recommendation has a good chance of being ignored. I'm suprised we allow them to sell kit into the US, or at least the defense establishment. As I said before, cyber-espionage is still esponiage. Is it any easier done over networks than by coopting employees of target companies or government agencies? I'd be more concerned about cyberwarfare. And didn't India ban Chinese telecom firms from selling into the country because of security concerns? Frankly, I'd be as worried about French and Israeli providers.
10/9/12 -- According to Reuters, Cisco cuts ties to China's ZTE after Iran probe. Shall I rest my case now?
Seems like the House Intelligence Committee did something right. Reuters reports that the committee is recommending that Huawai and ZTE be barred from buying US companies because of fears that they could be used for cyber-espionage. Of course, depending on who wins the Presidential election next month, the committee's recommendation has a good chance of being ignored. I'm suprised we allow them to sell kit into the US, or at least the defense establishment. As I said before, cyber-espionage is still esponiage. Is it any easier done over networks than by coopting employees of target companies or government agencies? I'd be more concerned about cyberwarfare. And didn't India ban Chinese telecom firms from selling into the country because of security concerns? Frankly, I'd be as worried about French and Israeli providers.
10/9/12 -- According to Reuters, Cisco cuts ties to China's ZTE after Iran probe. Shall I rest my case now?
Friday, December 2, 2011
Symantec's Top Trends in IT Security from 2011 and for 2012
With the end of the year close at hand, Symantec has taken a look back at the top trends in IT security from 2011 that we think will continue throughout 2012. No surprises here. Advance persistent threats and smart mobile devices top the list.
Shameless plea: I'm still looking for someone to write an book about APTs.
Shameless plea: I'm still looking for someone to write an book about APTs.
Monday, August 15, 2011
China: Agency Reports 500,000 Cyberattacks in 2010
is this a tit-for-tat? Is China making a clumsy effort to detract from it's own actions? Over the past years, I've heard some scary-smart guys talk about which security threats worry them most, and it's always China. Whether it's cyber espionage and warfare or malware burned into firmware, China is always at the top of the list. As long is China remains the low cost provider, the firmware threat will increase. But it is worrisome to think about all the computers, including those in sensitive areas, that have Chinese components always calling home. At least the US government is preventing Chinese companies from buying US high-tech manufacturers and service providers. Eventually, though, the Chinese will spread enough money around Congress to make this happen, too. This makes Russian cybercrime look pretty tame.
Wednesday, August 10, 2011
When does hacktivism become a criminal activity?
RIM is threaten with being hacked if it for helps UK cops stop riots. Credit card companines were hacked for cutting off Wikileaks. When does hacktivism become a criminal activity? It's an interesting situation. Many would argue that Wikileaks engaged in criminal activity by releasing the State Dept documents, and that cyberthugs got payback. It's really not a big step to from using social media to organize demonstrations to using it to organize flashmobs for rioting and looting. The role of social media in the Middle East uprisings not withstanding, does it's use to forment crime warrant warrant cooperation between service provides and government. Civil disobediance frequently leads to demonstrations, and demonstratios to riots as the original intent is corrupted by those who see an opportunity for criminal profit.
What's this say about the security of service providers? I don't know why I was surprised that Wilileaks supporters were able to hit MasterCard and Visa. You'd assume their security was good, and obviosuly the assumption was wrong. Is RIM as vulnerable? It'll be interesting to see if it's hacked regardless of whether or it cooperates with UK cops. Is there anything it can do to prevent it now that it's been warned.
Jim Tiller suggested that enterprises really can't "protect and detect," but can only "respond." If true, then perhaps hackers don't need to penetrate systems, but just threaten. This opens a new area of threat.
What's this say about the security of service providers? I don't know why I was surprised that Wilileaks supporters were able to hit MasterCard and Visa. You'd assume their security was good, and obviosuly the assumption was wrong. Is RIM as vulnerable? It'll be interesting to see if it's hacked regardless of whether or it cooperates with UK cops. Is there anything it can do to prevent it now that it's been warned.
Jim Tiller suggested that enterprises really can't "protect and detect," but can only "respond." If true, then perhaps hackers don't need to penetrate systems, but just threaten. This opens a new area of threat.
Subscribe to:
Posts (Atom)