Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

10/13/2020
02:10 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

25% of BEC Cybercriminals Based in the US

While the US is known to be a prime target for BEC attacks, just how many perpetrators are based there came as a surprise to researchers.

A new analysis of business email compromise (BEC) attacks reveals the global footprint of BEC activity: Twenty-five percent of perpetrators behind these threats are located in the United States. Of these attackers, nearly half are based in five states: California, Georgia, Florida, Texas, and New York.

The Agari Cyber Intelligence Division (ACID) today published the results of a study to better understand the operations of BEC attacks – in particular, the location of attackers and the money mules responsible for laundering their proceeds. While Nigeria has been a hot spot for social engineering scams, researchers found only half of attacks came from the West African country.

Related Content:

Scale Up Threat Hunting to Skill Up Analysts

2020 State of Cybersecurity Operations and Incident Response

New on The Edge: What Is End-to-End Encryption?

Their report contains information from more than 9,000 defense engagements between May 2019 and July 2020. In more than 2,200 of these, researchers could identify the attackers' likely locations. These do not include incidents in which attackers were likely using a proxy or other technique to anonymize their locations.

Based on these engagements, researchers identified BEC attackers in more than 50 different countries. Sixty percent of the attackers were based in 11 African countries; of these, 83% were based in Nigeria. South Africa was home to 14% of Africa-based attackers and the third-largest base for BEC groups worldwide. This was the only country in the study to see a decline in BEC attackers during the study. Eleven percent of global BEC actors were in South Africa during the last eight months of 2019, but this number dropped to 6% in the first seven months of this year.

Nearly 30% of global attackers were based in the Americas. Of these, 89% call the US home. While the US is known to be a prime target for BEC attacks, researchers were surprised to learn many perpetrators are based there. They also noticed clusters of attackers around a few metro areas including Atlanta, New York, Los Angeles, Houston, and Miami.

"The part about the US took us by surprise," says Crane Hassold, senior director of threat research at Agari. After removing instances in which attackers were using proxies and other anonymization sources, researchers assumed the percentage of US-based attacks would drop.

A closer look at the top US metro areas for BEC activity reveals a correlation with major arrests that have happened over the past couple of years, Hassold continues. One of these was Operation reWired, a law enforcement operation targeting BEC that led to the arrest of 281 people worldwide, including 74 in the US, 167 in Nigeria, 18 in Turkey, and 15 in Ghana.

"Geolocation is one of the many data points that defense is taking on when they're thinking of where threats come from," he explains. "One of the big things to keep in mind here is that location data may not be as helpful in some cases."

If security teams are only watching for attacks that originate in Nigeria, for example, they'll only see half of all BEC attacks that occur.

Tracking Illicit Funds: A Look at BEC Money Mules
Money mules were spotted all around the world: Over the course of the 15-month study, the team collected 2,900 mule accounts in 39 countries. Through these accounts, scammers intended to receive more than $64 million in stolen funds from BEC victims, researchers report.

Learning where money mules are located, and whether they're witting or unwitting in BEC operations, was a significant part of the research, Hassold says.

"The money mules are essentially the piece of the machine that makes this entire attack go, and without the mules, the entire ecosystem would fall apart," he explains. "Really understanding where they are, especially in the US, I found very fascinating because they're essentially the first stop for the money when it comes down to the business."

BEC attackers typically use a mule in the country where the target is based. This is unsurprising – Hassold says most mules were based in the US to start with – but may be partly due to restrictions that prohibit large international transfers. If an attacker sends a $30,000 payment to someone in the same country, it may not raise as many red flags as an international transfer. International transfers are typically disguised as corporate account payments, he notes. 

Researchers identified more than 900 US-based money mules used in BEC scams between May 2019 and July 2020. At least one mule was spotted in every state, as well as the District of Columbia. Many of these are people who fall for romance scams or work-from-home scams, in which victims apply for and accept a job that could include receiving and reshipping goods, receiving "payments" from clients, or printing and sending checks – all part of a BEC operation.

While most mule accounts were at US-based banks, payments requested for those accounts were much lower than in other countries. For example, the average payment requested by BEC scammers for US-based accounts was $39,500. Payments requested for Hong Kong-based mule accounts averaged $257,300.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 10/27/2020
Chinese Attackers' Favorite Flaws Prove Global Threats, Research Shows
Kelly Sheridan, Staff Editor, Dark Reading,  10/27/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-27652
PUBLISHED: 2020-10-29
Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
CVE-2020-27653
PUBLISHED: 2020-10-29
Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
CVE-2020-27654
PUBLISHED: 2020-10-29
Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands via port (1) 7786/tcp or (2) 7787/tcp.
CVE-2020-27655
PUBLISHED: 2020-10-29
Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via inbound QuickConnect traffic.
CVE-2020-27656
PUBLISHED: 2020-10-29
Cleartext transmission of sensitive information vulnerability in DDNS in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via unspecified vectors.