Read The Times Australia

Daily Bulletin

What the underground market for ransomware looks like

  • Written by: Roderic Broadhurst, Chair professor, Australian National University
image

The attack of ransomware “WannaCry” has put governments and businesses around the world on edge, but in fact the underground market for exploit or software vulnerabilities bugs like this has been an existence at least since the 1990s.

Informal sharing of these vulnerabilities goes back to the dawn of computing - notably phone “phreaking” - tinkering with telecommunication devices and the Massachusetts Model Railway Club credited with the early fostering of a hacker sub-culture from the 1960s onwards.

From here it slowly developed into a global market in the sale of exploits and exploit kits. This included hacking tools such as Blackhole, Zeus and Spyeye – sometimes known as “script kiddies” because the programming skills required are basic and the hacks more or less delivered via a menu-driven program.

The Russian carding market, which developed in the 1990s as online forums for the sale of stolen credit cards and identities, morphed into a sophisticated business enterprise. It mimicked online legal markets such as eBay. In short these criminals industrialised.

The Australian Communication Media Authority’s Spam Intelligence Database showed that spam-distributed malware, with the capability of locking data-files on an exposed computer system, begun to appear in 2012 with many cases reported in 2013 onwards.

The modern malware market

The industrialisation of the cybercrime market developed rapidly with the advent of virtual private networks (VPNs) and The Onion Router or “Tor” for short in the mid-2000s. The UNODC’s 2013 Comprehensive Report on Cybercrime flagged the importance of these markets in the spread of monetised hacking tools.

The RAND corporation’s report on the Hacker’s Bizarre in 2014 notes:

These black markets are growing in size and complexity. The hacker market — once a varied landscape of discrete, ad hoc networks of individuals initially motivated by little more than ego and notoriety — has emerged as a playground of financially driven, highly organized, and sophisticated groups….Black and gray markets for hacking tools, hacking services, and the fruits of hacking are gaining widespread attention as more attacks and attack mechanisms are linked in one way or another to such markets.

The Australian Cyber Security Centre’s 2015 Threat report highlights the emergence of cybercrime as a service, introducing new business models to cybercriminals, and increasing their spread and sophistication. Cybercrime Division prosecutor, Gavin Corn, observed that networking among criminal groups has been greatly enhanced by the emergence of new encrypted applications:

Cybercrime wasn’t even a part of organized crime before, and now it’s the epitome of it.

The evolution of the internet has also seen the rapid take up of encrypted and anonymous technology.

The value of this underground market today is guessed to be in the hundreds of millions. Some vulnerabilities have been reportedly sold for as much US$900,000 recently. Higher prices are paid for the more secure systems such Apple iOS – iphones and so on, but lower fees for older legacy operating systems like Windows XP.

The market operates in an orderly way with testing and evaluation prior to purchase. It’s similar to the carding business in that it seeks to create a stable reliable service encouraging repeated use.

Don’t just blame the black market

When it comes down to the effectiveness of the products - malware, ransomware - where the underground market drops off, businesses with lax security are most at risk.

Legitimate penetration testing by cyber-security companies as well as national security agencies wanting to improve cyber arsenals for offensive purposes also have had a role in boosting the value of exploits. The secret acquisition of exploits leaves many users unaware of the “bug” and legitimate bug bounty projects.

In reality, any enterprise in e-commerce or dependent on the internet should also be a security company. Intrusions that target confidential data or service delivery are now common and can devastate trust in the business.

A stand out problem is the presence of legacy computing systems or applications with old operating systems that are no longer supported by the vendor. The Windows XP operating system is a good example and exploits frequently target these older systems.

It’s estimated that half of all web pages still run on the old unsecure http script, rather than the more secure https, now the industry standard. This legacy of older web page formats, leaves everyone exposed to the risk of being compromised by cybercriminals. These criminals hijack technology and use their website addresses to redirect victims to such sites in order to unwittingly download a virus such as a Trojan or other malware.

The mass distribution of the “WannaCry” ransomware signals the shift of ransomware intrusion techniques from a specialist or individually tailored mode of cybercrime, to one capable of simultaneously targeting many vulnerable computer systems or networks. Coupled with the creation of large scale botnets (a network of computers that can be controlled remotely), often designed to deliver mass-spam emails or social media messages, the scale of these events grows.

At best attacks on this scale have been described as “weapons of mass annoyance” – disruptive but not fatal. The emergence of campaign style attacks is now common place.

They are capable of delivering well designed social engineered messages that trick users into visiting a compromised webpage and inadvertently downloading an executable file that locks up data. In other attacks, hidden programs that log keystrokes or manipulate the computer’s operating system can be implemented via unpatched bugs in many older systems.

The notion of the “digital divide”, where some have access to certain technology and others don’t, has the additional dimension of security as well. Consumers and enterprises constantly reviewing the trustworthiness of their tech exchanges becomes more difficult than ever, as cybercriminals can easily duplicate perfect examples of well known trusted enterprises.

Authors: Roderic Broadhurst, Chair professor, Australian National University

Read more http://theconversation.com/what-the-underground-market-for-ransomware-looks-like-77703

Business News

Is Your Brand Showing Up in AI Search? Most Melbourne Brands Aren't.

The New Front Door Nobody Told You About Something changed. Quietly. Without a press release. The way buyers find businesses in Australia has been rewired. Not replaced, rewired. Google isn't dead...

Daily Bulletin - avatar Daily Bulletin

How Australian Businesses Can Measure SEO ROI

SEO can feel vague when you are staring at a dashboard full of numbers that do not clearly connect to revenue. The key is to measure the right signals in the right order, then tie them back to outcome...

Daily Bulletin - avatar Daily Bulletin

How Commercial Roller Shutters Improve Site Security Without Slowing Operations

Security upgrades can be frustrating when they make everyday work harder. A door that takes too long to open, creates bottlenecks at shift change, or fails at the worst time can turn “better protectio...

Daily Bulletin - avatar Daily Bulletin

Why a Document Destruction Service Still Matters for Modern Businesses

Businesses generate large volumes of information every day, from staff records and contracts to invoices, reports and customer files. While attention often focuses on how documents are stored, the way...

Daily Bulletin - avatar Daily Bulletin

Bicycle Rack Safety and Space-Smart Storage

Bike storage problems usually show up as small annoyances first: tangled handlebars, scratched frames, and bikes that topple when you pull one out. Over time, those issues become safety risks, especia...

Daily Bulletin - avatar Daily Bulletin

How to Tell if a Childcare Centre Is a Good Fit for Your Child

Choosing childcare can feel like you’re making a huge decision with limited information. Tours are short, centres are often on their best behaviour, and your child might act differently in a new space...

Daily Bulletin - avatar Daily Bulletin

Car Import Timeline: What Usually Happens at Each Stage

Importing a car into Australia can feel confusing because multiple agencies and checkpoints are involved, and the timeline is shaped as much by paperwork quality as it is by shipping speed. The most u...

Daily Bulletin - avatar Daily Bulletin

Portable Toilet Hygiene Standards Explained: Clean vs Sanitised vs Disinfected

In portable toilet servicing, the words clean, sanitised, and disinfected often get used as if they mean the same thing. They don’t. And that difference matters because a unit can look tidy and still ...

Daily Bulletin - avatar Daily Bulletin

Options Available When a Company Faces Financial Distress

Financial distress can develop gradually or arrive suddenly, and when it does, the decisions made in the early stages often determine what options remain available later. Directors who act promptly ...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

What Actually Makes a Good Criminal Lawyer in Melbourne

Most people only think about this question once. That is usually too late. Most people charged wi...

Why Working With A Chatswood Tutor Can Improve Academic Performance

Academic expectations continue increasing for students across primary school, high school, and senio...

Is It Worth Getting Solar Panels in Melbourne?

The real question is not whether solar works in Melbourne. It works. The question is what it is co...

How A Diploma Of Project Management Builds Practical Skills For Modern Work Environments

Developing the ability to plan, execute, and deliver outcomes efficiently is a key requirement in to...

How to Choose the Right Football for Every Level

Choosing a football may seem straightforward, but the right option depends on who will be using it a...

What to Ask a Wedding Photographer Before You Book

Booking a wedding photographer can feel deceptively simple: you like the photos, you like the vibe...

Why Stress Relief For Dogs Is Essential For Emotional Balance And Long-Term Wellbeing

Managing emotional health is just as important as physical care when it comes to pets, which is why ...

Australia’s Best Walking Trails and the Shoes You Need to Tackle Them

Australia is not short on spectacular walks. You can follow ocean cliffs in Victoria, cross ancien...

Why Pre-Purchase Building Inspections Are Essential Before Buying a Home in Australia

source Have you ever walked through an open home and started picturing your furniture, family d...