Skip to main content

Black Markets for Hackers Are Increasingly Sophisticated, Specialized and Maturing

Black and gray markets for computer hacking tools, services and byproducts such as stolen credit card numbers continue to expand, creating an increasing threat to businesses, governments and individuals, according to a new RAND Corporation study.
One dramatic example is the December 2013 breach of retail giant Target, in which data from approximately 40 million credit cards and 70 million user accounts was hijacked. Within days, that data appeared — available for purchase — on black market websites.
“Hacking used to be an activity that was mainly carried out by individuals working alone, but over the last 15 years the world of hacking has become more organized and reliable,” said Lillian Ablon, lead author of the study and an information systems analyst at RAND, a nonprofit research organization. “In certain respects, cybercrime can be more lucrative and easier to carry out than the illegal drug trade.”
The growth in cybercrime has been assisted by sophisticated and specialized markets that freely deal in the tools and the spoils of cybercrime. These include items such as exploit kits (software tools that can help create, distribute, and manage attacks on systems), botnets (a group of compromised computers remotely controlled by a central authority that can be used to send spam or flood websites), as-a-service models (hacking for hire) and the fruits of cybercrime, including stolen credit card numbers and compromised hosts.
In the wake of several highly-publicized arrests and an increase in the ability of law enforcement to take down some markets, access to many of these black markets has become more restricted, with cybercriminals vetting potential partners before offering access to the upper levels. That said, once in, there is very low barrier to entry to participate and profit, according to the report.
RAND researchers conducted more than two dozen interviews with cybersecurity and related experts, including academics, security researchers, news reporters, security vendors and law enforcement officials. The study outlines the characteristics of the cybercrime black markets, with additional consideration given to botnets and their role in the black market, and “zero-day” vulnerabilities (software bugs that are unknown to vendors and without a software patch). Researchers also examine various projections and predictions for how the black market may evolve.
What makes these black markets notable is their resilience and sophistication, Ablon said. Even as consumers and businesses have fortified their activities in reaction to security threats, cybercriminals have adapted. An increase in law enforcement arrests has resulted in hackers going after bigger targets. More and more crimes have a digital component.
The RAND study says there will be more activity in “darknets,” more checking and vetting of participants, more use of crypto-currencies such as Bitcoin, greater anonymity capabilities in malware, and more attention to encrypting and protecting communications and transactions. Helped by such markets, the ability to attack will likely outpace the ability to defend.
Hyper-connectivity will create more points of presence for attack and exploitation so that crime increasingly will have a networked or cyber component, creating a wider range of opportunities for black markets. Exploitations of social networks and mobile devices will continue to grow. There will be more hacking-for-hire, as-a-service offerings and cybercrime brokers.
However, experts disagree on who will be the most affected by the growth of the black market, what products will be on the rise and which types of attacks will be more prevalent, Ablon said.
The study, “Markets for Cybercrime Tools and Stolen Data: Hackers’ Bazaar,” can be found at www.rand.org. Other authors of the study are Martin Libicki and Andrea A. Golay.
Support for the study was provided by Juniper Networks as part of a multiphase study on the future cybersecurity environment.
The study was conducted within the Acquisition and Technology Policy Center of the RAND National Security Research Division. The division conducts research and analysis on defense and national security topics for the U.S. and allied defense, foreign policy, homeland security and intelligence communities and foundations and other nongovernmental organizations that support defense and national security analysis.
The RAND Corporation is a research organization that develops solutions to public policy challenges to help make communities throughout the world safer and more secure, healthier and more prosperous. This article was originally published at the RAND Corportation.

Comments

Popular posts from this blog

You MUST Ask Yourself These Before Ending Your Relationship

Are you staying for the stuff? When a relationship is fizzling out, you know it. The intense chemistry you once had with your partner has shifted, and you spend more time not talking than talking. It isn't bad but it certainly isn't good either. If you and your mate are considering parting ways, it is a serious thing for both of you. The one ingredient that I believe you must have to make it work is collaboration. Have you ever stayed in a relationship just for the stuff ? For example, do you have a great bed? One woman said she stayed in her relationship just because of a Tempur-Pedic mattress. Do you belong to a country club? Do you own a second home in another state that would no longer be yours if you left the relationship? All of this stuff can tempt you to stay in the relationship even if you know it should be over. Is your happily-ever-after starting to look a little dim?    When is it time to move on? It's important to real...

How to lose weight

More than one-third of adults in the United States are obese. In fact, the furor over obesity, which some have termed an “epidemic,” has reached such proportions that one big-city mayor has gone about banning large-sized, sugary soft drinks and the First Lady has been on a crusade to control the dietary offerings in public schools. Even many adults who do not fit the clinic definition of obese are still overweight, and a large percentage are looking for the best ways to lose weight. Shedding pounds largely comes down to the two-pronged factors of diet and exercise. Not modifying the first one enough, and not getting enough of the second one, ends up giving the individual a recipe for being overweight.  Conditions related to obesity include heart disease, stroke, type 2 diabetes, and certain types of cancer, according to the Centers for Disease Control and Prevention. Counseling someone to eat less and exercise more might be the simplest advice possible, but it’s also, partiall...

Stress Management

  How to Reduce, Prevent, and Cope with Stress It may seem that there’s nothing you can do about stress. The bills won’t stop coming, there will never be more hours in the day, and your career and family responsibilities will always be demanding. But you have more control than you might think. In fact, the simple realization that you’re in control of your life is the foundation of stress management. Managing stress is all about taking charge: of your thoughts, emotions, schedule, and the way you deal with problems. Identify the sources of stress in your life Stress management starts with identifying the sources of stress in your life. This isn’t as easy as it sounds. Your true sources of stress aren’t always obvious, and it’s all too easy to overlook your own stress-inducing thoughts, feelings, and behaviors. Sure, you may know that you’re constantly worried about work deadlines. But maybe it’s your pr...