Leading Russian Security Firm Group-IB Releases 2014 Report on the Russian High-Tech Crime Market

Leading Russian Security Firm Group-IB Releases 2014 Report on the Russian High-Tech Crime Market

Group-IB, one of the leading companies in fraud prevention, cybercrime and hi-tech crime investigations, today announced their annual report on the Russian high-tech crime market for 2014. Analysts from Group-IB's computer forensics lab and its CERT-GIB unit prepared the 56-page report, covering the second half of 2013 and the first half of 2014.

The comprehensive report provides detailed assessments of the who, what, where and how of high-tech crime, naming which individuals and criminal groups are behind what crimes, where they originate and who they target. The report covers the trends, evolution and financial impact of various cybercrime practices. The report also details how specific cybercrime practices function, including fraud, banking information theft and malware infections. Individuals, bank employees, security administrators and others who read this report will know the threats targeting them and understand the vulnerabilities and entry points to be watchful of. Contents of the report include high-tech crime market assessments, trends over the last year including attack targets and methods, a forecast for 2014-2015, and profiles of key cybercriminals brought to justice over this report's period.

"With recent cybersecurity events such as the leaks at JPMorgan, Home Depot, Target and others, it pays to know which threats matter and where to best allocate security resources," said Ilya Sachkov, CEO at Group-IB. "Having solid information on the exact nature of cybercrime attacks, and knowing the vulnerabilities that criminal target and exploit, is invaluable to protecting personal and corporate data. Our report provides readers with the knowledge to make smart security decisions."

The report, which includes a recap of major trends over the past year and offers a forecast for 2015, is available at http://report2014.group-ib.com/

Key trends in 2014 include:

The carding black market looks like any online market: Group-IB undertook an extensive study of the Russian market for stolen credit card information. This investigation looked into organized marketplaces where the card market has become structured, complete with wholesalers and online trading platforms. Criminals can easily browse and purchase stolen credit card information as if they were shopping on any mainstream e-commerce site. A study of the online card market site SWIPED found that the most active card supplier is a criminal individual called "Rescator," who uploaded details of over 5 million cards to the online marketplace. In investigating a test sample, Group-IB found that all sampled cards were originally stolen from the retail chain Target, which famously suffered a security breach in the past year. Group-IB estimates the carding market at $680,000,000.

Criminals like cryptocurrencies: Group-IB found that 80% of payments on SWIPED are currently made using bitcoin, with other cryptocurrencies also playing a role as convenient tools for illegal transactions. Shadow Internet shops selling goods such as stolen information, weapons and drugs have switched to using cryptocurrencies as their primary payment methods. The use of malware-based botnets to mine bitcoins has also become so developed that botnet renting through services like SkyShare has become a reality. Stealing from cryptocurrency wallets using Trojans has also become more sophisticated and common.

Mobile banking threats experienced strong growth: This year, five criminal groups emerged that specialize in mobile banking theft using Trojans. These groups infect Android phones and steal information via SMS banking and the use of phishing sites. The scale of these thefts is limited only by the manual nature of the activity. The report also investigates mobile espionage, where malware allows criminals to read texts, listen to phone conversations and even pinpoint a victim's location with the GPS on their phone. The report includes screenshots of the tools criminals use to carry out these activities, displaying their invasive nature.

Targeted attacks on financial institutions continue: Groups targeting financial institutions have stolen about $40 million during the report period, using techniques including Trojans, phishing sites, and even assistance from personnel inside the banks. Criminals use sophisticated processes to evade policies barring bank workers from opening executable files, hiding malware inside of harmless looking document files.

Hackers reprogram ATM machines to hand out the big bills: Either by physical access or infection of local networks, hackers are able to introduce malicious scripts to ATM software. In some cases the purpose is to record any ATM card numbers and pins used on the compromised machines and to make cash withdrawals from those accounts. Other scripts can reprogram an ATM to pay out larger value notes than they should, for example, issuing 5000-ruble notes when 100-ruble notes ought to be issued. The total amount stolen from one group via this method exceeded 50 million rubles.

Online banking fraud is down: Of eight criminal groups active in Russian online banking theft last year, two have switched to foreign targets and one was broken up following the 2014 arrest of one of its leaders. This has resulted in a decrease in the total online banking fraud market, from an estimated $615,000,000 in 2012 to $425,000,000 in 2013-2014.

Spam provides high earnings to sellers of counterfeit pharmaceuticals: Group-IB detects 10,000 new online stores selling fake pharmaceuticals every month. These affiliate programs will sell pills actually consisting of ingredients like printer ink and drywall. The counterfeit stores will collude with employees of processing centers and legitimate online stores to skirt the rules of international payment systems like VISA and MasterCard, which prohibit payment for unlicensed medical sellers. The total market for spam fraud, including all counterfeit medicine, products and software, is estimated at $841,000,000.

Number of DDoS attacks falling in some areas, but power of attacks increasing: While DDoS attacks on government websites fell during the report period, attacks on banks and payment systems increased. Hackers are abandoning using botnets in favor of DNS/NTP amplification attacks, providing more powerful attacks at lower cost. Such attacks now account for 70% of the total.

About Group-IB

Global Cyber Security Company

Founded in 2003, Group-IB is one of the leading companies in fraud prevention, cybercrime and hi-tech crime investigations. Group-IB's mission is to protect our clients in cyberspace by creating and using innovative products, solutions and services.

Key activities of our company:

  • Cyber Intelligence and Threat Prevention
  • Anti-piracy
  • Online brand protection
  • Information Security Assessment and Vulnerability Research
  • Computer Forensics
  • Cybercrime and Hi-Tech crimes investigations
  • Innovative software products development for monitoring, detection and prevention of emerging cyberthreats.

In the technologies field, it is imperative that our team members are on the cutting edge. That is why our employees have earned several certificates: CISSP (Certified Information Systems Security Specialist), CISA (Certified Information Systems Analyst), CEH (Certified Ethical Hacker), Extreme Networks Administrator, A+ Certification, Net+, MCP (Microsoft Certified Professional), and MCSA (Microsoft Certified Systems Administrator).

We have more than 90 employees serving customers in more than 25 countries. Our clients include various banks, financial institutions, oil and gas companies, software and hardware vendors, telecommunications service providers from Australia, Argentina, Brazil, Canada, EU, Russian Federation, UK, USA and Ecuador.

Group-IB employees participate in key IT-security conferences such as e-Crime, Cardex, APWG:Counter-eCrime Operations Summit (CeCOS), Cyber Intelligence Asia and the SCADA Security Summit.

Group-IB
http://www.group-ib.com/


Related News

Putin’s Counselor: Accepting Bitcoin Payments Unacceptable, a Crime

In adding to the recent stance taken by Russian regulators and official authorities, Russian president Putin’s counselor has reportedly stated that accepting bitcoin in Russia is “a crime”. Newly appointed counsel and advisor on the internet German Klimenko, has reportedly claimed that accepting bitcoin as a payment instead of Russian rubles, is unacceptable and is a crime. The seemingly matter-of-fact comments was made in an interview with Russian online news publication Lenta.ru. The comments from the interview were translated and revealed by Russian bitcoin news outlet Forklog. An....

BBC Chairman Buys Share In Crypto Firm Despite Crypto Winter

A recent report connected the BBC Chairman, Richard Sharp, to a crypto company founded by a Russian oligarch. Sharp, a former banker, is said to have invested in cryptocurrency business using a foreign firm. The said firm was founded by one of the Russian oligarchs and was recently sanctioned due to the Russian-Ukraine war. The […]

Georgians Sell Russian Regions as NFTs to Raise Money for Ukraine

A tech innovations firm based in Georgia’s capital Tbilisi is now “selling Russia piece by piece” in the form of NFTs. The money from the collectibles, representing almost 2,500 Russian regions, will be used to help rebuild Ukraine, which was invaded by the Russian army two months ago. Georgian Project Auctions NFTs of Russian Land, Will Soon Offer the Kremlin Leavingstone, a digital creative agency from Georgia, has joined efforts to raise funds for Ukraine, which has been defending against Russian military aggression for eight weeks. The company is now selling....

Coinbase Warns Some Russian Users Their Accounts May Be Blocked, Report Reveals

Leading U.S. crypto exchange Coinbase has reportedly notified certain Russian customers that their accounts may be blocked at the end of this month. According to Russian media, the trading platform has offered them to withdraw their funds unless they prove they are not under sanctions. Coinbase Reportedly Asks Russian Clients to Withdraw Funds Some Coinbase users from Russia have received letters informing them that their accounts will be blocked on May 31, the crypto page of the Russian business news portal RBC reported. The company suggested that these customers withdraw their....

Russian Finance Ministry Proposes a 2-Year Prison Sentence for Bitcoin Adopters

According to a report, the Russian Finance Ministry is seeking to push for amendments to the Criminal Code by proposing two-year ‘corrective labor’ sentence, or a fine of up to 500,000 rubles for bitcoin users. The Russian Interior and Finance Ministries see cryptocurrencies as a threat to not only the Russian economy, but also its national security. ‘Corrective labor’ colonies are among the most common types of prisons in Russia. They are a combination of penal detention and forced labor. In a time where governments and regulators are taking varying approaches to popular decentralized....