Monday, October 22, 2012

Cybercrime Ecosystem


Most IT professionals are not aware of the vast criminal ecosystem thriving on the internet. Criminal organizations have developed a way to monetize the exploitation of computer systems in many ways. Identity Theft is the most prevalent in the media, where criminals will obtain and sell credit cards and other personal identifiable information to commit many types of fraud. In addition to a “dox” marketplace, cybercriminals will sell DOS services, botnets, targeted malware, and as covered in a recent article, remote access to corporate computers. One of the leading security researchers, Dancho Danchev, often covers the latest malware frameworks on the web. Entire software suites exist to manage targeted DOS and phishing operations, such as Zeus. Leading security researchers in large organizations can attest to what is considered that Advanced Persistent Threat.   

                APT’s are the hot topic in the security realm these days, which describe dangerous and recurring security attacks that are usually state sponsored and  difficult to detect. They have a targeted purpose and active only when a special set of circumstances are met. While these attacks may be state sponsored for the time being; due to the vast amount of knowledge and expertise it requires to create such a dangerous software attack, the cybercrime ecosystem is evolving to a point where APT’s may come with a dollar value. Criminal organizations have thrived off of monetizing any kind of illegal acts, as long as there is a benefit and a market. As the internet expands, encompassing more than just corporations, one can definitely expect the expansion of a cybercrime market. 

No comments:

Post a Comment