Threat Intelligence

10/18/2018
10:00 AM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
100%
0%

Inside the Dark Web's 'Help Wanted' Ads

How cybercriminals recruit everyone from car drivers to corporate insiders and pay them according to the risk they assume.

Lurking on the Dark Web are threat actors seeking help for a range of illegal activities, from malware attacks to insurance fraud to murder. When they need a new hire, they post virtual ads, vaguely describing the role while offering the most money for jobs with the greatest risk.

It's not the only way in which the underground looks like a traditional job market, report researchers from Trustwave SpiderLabs. A new study digs into the intricacies of Dark Web recruitment to learn more about how cybercriminals do business. It's the second in a series of reports investigating the actors and unwritten rules that keep the underground running.

Researchers found this network is comprised of organizational structures resembling small to large businesses, all of which compete for talent in their illicit economy. As in our legal economy, two principles apply.

First is the idea that supply breeds demand. For example, if someone creates a dangerous piece of malware, another party will buy it and exploit targets. Both buyer and seller turn a profit.

Second, is a workforce hierarchy: operators who manage activity but do less actual work, skilled laborers who perform expert work and are paid more, and menial laborers who do less technical work for lower pay, but do so to build knowledge and eventually move up into higher-paying roles.

"We found that the business they conduct, or the rules they follow, are a lot more structured and enforced than one may expect," says Ziv Mador, vice president of security research at Trustwave SpiderLabs. "You may think cybercriminals do whatever they want. In reality, they follow very strict rules of engagement, clear rules on how to determine the reputation of players so others don't scam them."

One of the key correlations is between assumed risk and reward. The more dangerous the position, the higher compensation becomes.

More Risk, More Money

Most job postings on the Dark Web sound like regular advertisements, with details withheld to be discussed on messaging apps like Telegram.

A post seeking a car driver, for example, promises $1,000 per week – the same amount an ordinary driver makes in one month, not including the living expense compensation the underground worker will receive during employment. Details later show the driver will deliver drugs, which poses a great enough risk to warrant their high payment.

Drivers typically leave drugs in previously agreed upon places, for which they could face several years in prison if caught by police. In cases where they're given expensive merchandise, workers put down a "deposit" of cash worth the equivalent of the goods, which they get back upon completion of the task. This ensures they do the job, rather than take the drugs and run.

Among the highest paid are corporate insiders recruited by cybercriminals who want to learn business secrets. They may want to make sure a broader operation is going as expected, or track specific people. Most commonly targeted are financial employees, who may be hired to get a loan or increase the cash withdrawal limit on a bank card. One Russian-language ad offered $3,150 USD – in an area where the common bank worker makes only $550 per month.

"Bank employees can make a lot more money by working with cybercriminals," says Mador. "Of course, they could take enormous risk." If caught, an insider could face prison time, most likely lose their job, and could be banned from the entire industry.

It's not only finance employees who are targeted. Some actors try to recruit postal workers to intercept and reroute packages. Others attempts to recruit security experts and government or law enforcement employees for what they describe as "long-term collaboration."

Threat actors also seek cyber expertise, and forums are full of ads from people who sell malware or offer custom versions of malware. "It's all over the place," says Mador. Actors sell exploits, Trojans, bots, and people who can provide bot support.

Less Skill, Future Potential

The most popular job on the Dark Web is a "dropper," or someone who receives money or goods and redirects it to another dropper, as a means to widen the distance between the recipient of illicit merchandise and the original seller. Droppers are not specific to country or region; location varies depending on where help is needed.

Toward the bottom of the hierarchy are unskilled jobs in advertising. One ad, posted in Ukraine, promises about $15 USD per day for a low-skill task that carries a small risk of being punished for vandalism. It doesn't seem like a lot of money but considering the local minimum wage is about $140/month, this type of job is appealing among students and young people.

Recruiting this age demographic is essential for Dark Web operators who want to train future leaders, and some of the work can be done online. Workers will earn above minimum wage for sending spam messages or filling roles as captcha solvers or data entry clerks.

Related Content:

 

 

 

Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Crowdsourced vs. Traditional Pen Testing
Alex Haynes, Chief Information Security Officer, CDL,  3/19/2019
BEC Scammer Pleads Guilty
Dark Reading Staff 3/20/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Well, at least it isn't Mobby Dick!
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
The State of Cyber Security Incident Response
The State of Cyber Security Incident Response
Organizations are responding to new threats with new processes for detecting and mitigating them. Here's a look at how the discipline of incident response is evolving.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-4035
PUBLISHED: 2019-03-22
IBM Content Navigator 3.0CD could allow attackers to direct web traffic to a malicious site. If attackers make a fake IBM Content Navigator site, they can send a link to ICN users to send request to their Edit client directly. Then Edit client will download documents from the fake ICN website. IBM X...
CVE-2019-4052
PUBLISHED: 2019-03-22
IBM API Connect 2018.1 and 2018.4.1.2 apis can be leveraged by unauthenticated users to discover login ids of registered users. IBM X-Force ID: 156544.
CVE-2019-9648
PUBLISHED: 2019-03-22
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information.
CVE-2019-9923
PUBLISHED: 2019-03-22
pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.
CVE-2019-9924
PUBLISHED: 2019-03-22
rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.