Categories: Cyber CrimeSecurity

Russian cybercrime, not only a localized threat

Several times I wrote on cybercrime trying to analyze a phenomenon that grows with an impressive rhythm. The trend is uniform all over the word, cybercrime business is increasing its profits despite the economic crisis. The impact of cybercrime is transversal, industry, private businesses and governments, are all players that suffers the incoming cyber threats.

I’ve found really interesting a research made realized by the Russian security firm Group-IB that analyze the cybercrime activities conduced by the Russian mafia and other criminal organizations. The numbers are impressive, the figures are doubled in 2011.

The official estimates says that the global cyber crime market was worth $12.5 billion in 2011, $4,5 billion of the market are related to Russian speaking cybercrime market and $2.3 billion took place in Russia alone. Related to last years the grow is doubled.

The report provides a clear picture of the cybercrime market providing an interesting perspective on analysis, cybercrime studied as part of a local economies of a region. We are speaking of crime of course but also the crime could have an economic impact on local economies especially for those regions that lives in evident discomfort.

The study highlights key aspects of cybercrime market:

  • on line fraud  (e.g. online banking fraud, phishingattacks) It should be noted that this aspect includes cashing services for stolen funds, taking up around 40% of this entire aspect.
  • spam, including services for sale of drugs and counterfeit products.
  • Internal market (cybercrime to cybercrime), including services for anonymization and sale of traffic, exploits, malware, and loaders.
  • DDoS attacks

Really interesting the diagram proposed in the report related the economic profit of the activities and the damages to the end users, On-line Spam campaign and banking fraud are the most profitable activities. Due large profits related this crimes security sector is observing a rapid grown of number of incidents.

What is really worrying is that the growth of cybercrime activities indicates that the crime is becoming organized, in more than one occasion I have compared crime organization to structured companies that operate with clear objectives and that sustain their affairs. In particular this aspect signs a substantial difference with the past, Russian cybercriminal operations were unorganized and managed by different and not coordinate groups of criminals.

In 2011, the following general trends of cybercrime market development can be highlighted:

  • Consolidation of the cybercrime market share, we are assisting to the formation of several major cybercrime groups that differently from the past are setting up in structured organizations.
  • Increasing of the activities of collaboration between cybercrime organizations, what we have defined cybercrime to cybercrime business (C2C). The cybercrime is arranging its business in main groups that mutual supports criminal activities such as botnets creation and management and fraud development.
  • Infiltration of cybercrime in the social contest, reinvesting the profit of the operations in cyber criminals activities but also in legal business. The cybercrime is changing, it is merging its structures with the traditional ones, with the subsequent resource allocation from the mafia’s areas of control (prostitution, drug and arms trafficking, and so on) in favor of cybercrime. Let’s also consider that cybercrime presents the advantages of high profits with relative low risks … usually it goes unpunished.
  • Penetration of the cybercrime market by individuals with little technical education. The cybercrime activities mainly require capital investments, not specialized knowledge. The emergence of this trend has led to the expansion of the internal cybercrime market (C2C) and the appearance there of outsourcing services (administration, training, consulting, etc.);
  • Growth of the Cybercrime to Cybercrime (C2C) services, provided on a paid basis by specialized teams of hackers.

Actually cybercrime is widespread throughout Russia, many expert have defined the Russian areas the cybercrime heaven, the main reason of the growth of thi type of crime in the countries of the former Soviet Union is the absence of an efficient Russian laws that contrast the phenomenon.  Russian laws require significant improvements and in my opinion its not possible to fight agaist cybercrime without an international cooperation, that is a critical aspects because the policy of Moscow Government is closed to external support. The report address another problem, Russia doesn’t devote attention to training law enforcement officers and court officials regarding the main issues of IT security, allowing them to make independent
judgments on various aspects of cybercrime.

Thus, because of imperfections in Russian laws and the lack of severe penalties, stable law enforcement practice, and regular training regarding counter cybercrime measures, cybercriminals are disproportionately liable for the crimes they commit.

The cybercrime is a cross nations threat and the only way to fight it is the establishment of international laws and throught the collaboration of every countries … cybercrime has no borders … the same must be for the measures to prevent it.

Pierluigi Paganini

 

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Over 1,400 CrushFTP internet-facing servers vulnerable to CVE-2024-4040 bug

Over 1,400 CrushFTP internet-facing servers are vulnerable to attacks exploiting recently disclosed CVE-2024-4040 vulnerability. Over…

2 hours ago

Sweden’s liquor supply severely impacted by ransomware attack on logistics company

A ransomware attack on a Swedish logistics company Skanlog severely impacted the country's liquor supply. …

4 hours ago

CISA adds Cisco ASA and FTD and CrushFTP VFS flaws to its Known Exploited Vulnerabilities catalog

CISA adds Cisco ASA and FTD and CrushFTP VFS vulnerabilities to its Known Exploited Vulnerabilities…

15 hours ago

CISA adds Microsoft Windows Print Spooler flaw to its Known Exploited Vulnerabilities catalog

U.S. CISA added the Windows Print Spooler flaw CVE-2022-38028 to its Known Exploited Vulnerabilities catalog.…

21 hours ago

DOJ arrested the founders of crypto mixer Samourai for facilitating $2 Billion in illegal transactions

The U.S. Department of Justice (DoJ) announced the arrest of two co-founders of a cryptocurrency mixer…

22 hours ago

Google fixed critical Chrome vulnerability CVE-2024-4058

Google addressed a critical Chrome vulnerability, tracked as CVE-2024-4058, that resides in the ANGLE graphics…

1 day ago

This website uses cookies.