cybercrime: from kudos to profit

24
Cybercrime: From Kudos to Profit Gerhard Eschelbeck, CTO Sophos

Upload: paytah

Post on 09-Feb-2016

64 views

Category:

Documents


0 download

DESCRIPTION

Cybercrime: From Kudos to Profit. Gerhard Eschelbeck, CTO Sophos. What do these businesses have in common ?. Interpol. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Cybercrime: From  Kudos  to  Profit

Cybercrime: From Kudos to ProfitGerhard Eschelbeck, CTO Sophos

Page 2: Cybercrime: From  Kudos  to  Profit

2

What do these businesses have in common ?

Page 3: Cybercrime: From  Kudos  to  Profit

Interpol

“In the past, cybercrime has been committed by individuals or small groups of individuals. However, we are now seeing an emerging trend with traditional organized crime syndicates and criminally minded technology professionals working together and pooling their resources and expertise.

This approach has been very effective for the criminals involved. In 2007 and 2008 the cost of cybercrime worldwide was estimated at approximately USD 8 billion. As for corporate cyber espionage, cyber criminals have stolen intellectual property from businesses worldwide worth up to USD 1 trillion.”

Page 4: Cybercrime: From  Kudos  to  Profit

FBIMasses of resources, details of activity. Most wanted page!

Page 5: Cybercrime: From  Kudos  to  Profit

Cybercrime as a “Business”

Page 7: Cybercrime: From  Kudos  to  Profit

Malware central to Cybercrime

“...individuals, normally working with others, with the capability to commit serious crime on a continuing basis, which includes elements of planning, control and coordination, and benefits those involved. The motivation is often, but not always, financial gain.”

SOCA

Organised crime

Page 8: Cybercrime: From  Kudos  to  Profit

Malware was „Easy“ in the Early Days

The Michelangelo Virus

Page 9: Cybercrime: From  Kudos  to  Profit

Current threat landscapeIn 1 slide

Page 10: Cybercrime: From  Kudos  to  Profit

Ransomware• Ransomware

• Pay ransom to access locked/encrypted files

Simple• Password

protected archives

Medium• XOR• shift

Complex• RC4• Public key crypto

Recover data?

Page 11: Cybercrime: From  Kudos  to  Profit

Ransomware (cont’d)Reveton: family of ransomware that locks users out of their machine

http://www.youtube.com/watch?feature=player_embedded&v=-qR3D-Jx6FQ

GEOIP lookup – locale specific lock pages

Page 12: Cybercrime: From  Kudos  to  Profit

Ransomware (cont’d)Additional tricks to socially engineer victim. Fear factor.

Page 13: Cybercrime: From  Kudos  to  Profit

13

PoS Malware - Troj/Trackr

• Umbrella detection name for all Point of Sale (PoS) RAM scraping malware. Includes: Alina, Dexter, VSkimmer, Kaptoxa, Chewbacca, etc.

• Troj/Trackr-* steals payment data from the RAM of PoS systems.

• Adds socially-engineered filenames, network functionality, bots, packed etc.

• Installed DLL version – malicious DLL is registered as a service and performs the RAM scraping.

Page 14: Cybercrime: From  Kudos  to  Profit

14

Who does Troj/Trackr- target?

Page 15: Cybercrime: From  Kudos  to  Profit

What about Mobile ?

Page 16: Cybercrime: From  Kudos  to  Profit

Mobile malware growth accelerating

2011-12 2012-01 2012-02 2012-03 2012-04 2012-05 2012-06 2012-07 2012-08 2012-09 2012-10 2012-11 2012-12 2013-01 2013-02 2013-030

20000

40000

60000

80000

100000

120000

140000

160000

180000

200000

Total Unique Samples

Page 17: Cybercrime: From  Kudos  to  Profit

Anatomy of a hacked device

Page 18: Cybercrime: From  Kudos  to  Profit

Crimeware kits‘Monetization’ : the bulk of today’s threats are automated, coordinated & professional

Page 19: Cybercrime: From  Kudos  to  Profit

It’s all about traffic• Stolen FTP credentials

• Use sFTP! (should be enforced)• Vulnerable software on site

• Wordpress plugins• Image gallery• -> upload PHP shell/kit

• Vulnerable server• Patched?

• 0wned server• e.g. Darkleech

Compromised sites used to drive traffic. 85% of all bad stuff.

Page 20: Cybercrime: From  Kudos  to  Profit

Drive-by downloads

“Monetization”

Page 21: Cybercrime: From  Kudos  to  Profit

Crimeware in Action

Page 22: Cybercrime: From  Kudos  to  Profit

A Global Challenge

Page 23: Cybercrime: From  Kudos  to  Profit

Reporting a crimeYES. See NakedSecurity articles for links to advice.

Page 24: Cybercrime: From  Kudos  to  Profit

Questions/Discussion?

24

[email protected]