Finjan Unveils the Latest Cybercrime Organizational Structures and Modus Operandi
Know Your Cybercrime Enemy – In its Q2 2008 Web Security Trends Report, Finjan outlines the latest developments in the cybercrime commercialization economy The report includes real documented discussions conducted by Finjan’s researchers with resellers of stolen data and their “bosses”, confirming Finjan’s analysis of the current state of the cybercrime economy. “Over the course of the last 18 months we have been watching the profit-driven Cybercrime market maturing rapidly. It has evolved into a booming business, operating in a major shadow economy with an organizational structure that closely mimics the real business world. This makes businesses today even more vulnerable for cybercrime attacks, especially considering the maturity of the cybercrime market and its well-structured cybercrime organizations,” said Yuval Ben-Itzhak, Finjan’s CTO. “Recent industry reports containing record numbers of malware infections during the first half of 2008 alone underline again the huge impact of cybercrime on today’s businesses.” These cybercrime organizations consist of strict hierarchies, in which each cybercriminal is rewarded according to his position and task. The “boss” in the cybercrime organization operates as a business entrepreneur and does not commit the cybercrimes himself. Directly under him is the “underboss”, acting as the second in command and managing the operation. This individual provides the Trojans for attacks and manages the Command and Control (C&C) of those Trojans. “Campaign managers” reporting to the underboss lead their own attack campaigns. They use their own “affiliation networks” as distribution channels to perform the attacks and steal the data. The stolen data is sold by “resellers”, who are not involved in the Crimeware attacks themselves. As a preventative measure, businesses should look closely at their security practices to make sure they are protected. A layered security approach is a highly effective way of handling these latest threats, and applying innovative security solutions, such as real-time content inspection, designed to detect and handle them is a key factor is being adequately protected. Quelle: Finjan Software Inc. |