Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

10/18/2018
10:00 AM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
100%
0%

Inside the Dark Web's 'Help Wanted' Ads

How cybercriminals recruit everyone from car drivers to corporate insiders and pay them according to the risk they assume.

Lurking on the Dark Web are threat actors seeking help for a range of illegal activities, from malware attacks to insurance fraud to murder. When they need a new hire, they post virtual ads, vaguely describing the role while offering the most money for jobs with the greatest risk.

It's not the only way in which the underground looks like a traditional job market, report researchers from Trustwave SpiderLabs. A new study digs into the intricacies of Dark Web recruitment to learn more about how cybercriminals do business. It's the second in a series of reports investigating the actors and unwritten rules that keep the underground running.

Researchers found this network is comprised of organizational structures resembling small to large businesses, all of which compete for talent in their illicit economy. As in our legal economy, two principles apply.

First is the idea that supply breeds demand. For example, if someone creates a dangerous piece of malware, another party will buy it and exploit targets. Both buyer and seller turn a profit.

Second, is a workforce hierarchy: operators who manage activity but do less actual work, skilled laborers who perform expert work and are paid more, and menial laborers who do less technical work for lower pay, but do so to build knowledge and eventually move up into higher-paying roles.

"We found that the business they conduct, or the rules they follow, are a lot more structured and enforced than one may expect," says Ziv Mador, vice president of security research at Trustwave SpiderLabs. "You may think cybercriminals do whatever they want. In reality, they follow very strict rules of engagement, clear rules on how to determine the reputation of players so others don't scam them."

One of the key correlations is between assumed risk and reward. The more dangerous the position, the higher compensation becomes.

More Risk, More Money

Most job postings on the Dark Web sound like regular advertisements, with details withheld to be discussed on messaging apps like Telegram.

A post seeking a car driver, for example, promises $1,000 per week – the same amount an ordinary driver makes in one month, not including the living expense compensation the underground worker will receive during employment. Details later show the driver will deliver drugs, which poses a great enough risk to warrant their high payment.

Drivers typically leave drugs in previously agreed upon places, for which they could face several years in prison if caught by police. In cases where they're given expensive merchandise, workers put down a "deposit" of cash worth the equivalent of the goods, which they get back upon completion of the task. This ensures they do the job, rather than take the drugs and run.

Among the highest paid are corporate insiders recruited by cybercriminals who want to learn business secrets. They may want to make sure a broader operation is going as expected, or track specific people. Most commonly targeted are financial employees, who may be hired to get a loan or increase the cash withdrawal limit on a bank card. One Russian-language ad offered $3,150 USD – in an area where the common bank worker makes only $550 per month.

"Bank employees can make a lot more money by working with cybercriminals," says Mador. "Of course, they could take enormous risk." If caught, an insider could face prison time, most likely lose their job, and could be banned from the entire industry.

It's not only finance employees who are targeted. Some actors try to recruit postal workers to intercept and reroute packages. Others attempts to recruit security experts and government or law enforcement employees for what they describe as "long-term collaboration."

Threat actors also seek cyber expertise, and forums are full of ads from people who sell malware or offer custom versions of malware. "It's all over the place," says Mador. Actors sell exploits, Trojans, bots, and people who can provide bot support.

Less Skill, Future Potential

The most popular job on the Dark Web is a "dropper," or someone who receives money or goods and redirects it to another dropper, as a means to widen the distance between the recipient of illicit merchandise and the original seller. Droppers are not specific to country or region; location varies depending on where help is needed.

Toward the bottom of the hierarchy are unskilled jobs in advertising. One ad, posted in Ukraine, promises about $15 USD per day for a low-skill task that carries a small risk of being punished for vandalism. It doesn't seem like a lot of money but considering the local minimum wage is about $140/month, this type of job is appealing among students and young people.

Recruiting this age demographic is essential for Dark Web operators who want to train future leaders, and some of the work can be done online. Workers will earn above minimum wage for sending spam messages or filling roles as captcha solvers or data entry clerks.

Related Content:

 

 

 

Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-29370
PUBLISHED: 2021-04-13
A UXSS was discovered in the Thanos-Soft Cheetah Browser in Android 1.2.0 due to the inadequate filter of the intent scheme. This resulted in Cross-site scripting on the cheetah browser in any website.
CVE-2021-3460
PUBLISHED: 2021-04-13
The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server certificate during communication with the support server which could lead to the communication channel being accessible by an attacker.
CVE-2021-3462
PUBLISHED: 2021-04-13
A privilege escalation vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could allow unauthorized access to the driver's device object.
CVE-2021-3463
PUBLISHED: 2021-04-13
A null pointer dereference vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could cause systems to experience a blue screen error.
CVE-2021-3471
PUBLISHED: 2021-04-13
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.