Most IT professionals are not aware of the vast criminal
ecosystem thriving on the internet. Criminal organizations have developed a way
to monetize the exploitation of computer systems in many ways. Identity Theft
is the most prevalent in the media, where criminals will obtain and sell credit
cards and other personal identifiable information to commit many types of
fraud. In addition to a “dox” marketplace, cybercriminals will sell DOS
services, botnets, targeted malware, and as covered in a recent article, remote
access to corporate computers. One of the leading security researchers, Dancho
Danchev, often covers the latest malware frameworks on the web. Entire software
suites exist to manage targeted DOS and phishing operations, such as Zeus. Leading
security researchers in large organizations can attest to what is considered
that Advanced Persistent Threat.
APT’s
are the hot topic in the security realm these days, which describe dangerous
and recurring security attacks that are usually state sponsored and difficult to detect. They have a targeted
purpose and active only when a special set of circumstances are met. While
these attacks may be state sponsored for the time being; due to the vast amount
of knowledge and expertise it requires to create such a dangerous software
attack, the cybercrime ecosystem is evolving to a point where APT’s may come
with a dollar value. Criminal organizations have thrived off of monetizing any
kind of illegal acts, as long as there is a benefit and a market. As the
internet expands, encompassing more than just corporations, one can definitely
expect the expansion of a cybercrime market.
No comments:
Post a Comment