Catch a hacker: who calls you from "banks", hacks into accounts and leaks data to the network

Who are hackers

Cybercrimes are any offenses that are committed using technology and

information resources.You can identify an ordinary offender by evidence or video cameras, but cybercriminals have no face. This could be anyone - a student, a schoolboy, a neighbor whom you meet every day in the elevator. When you meet such a person, you will never guess that he is a hacker.

There are three types of motivation for hackers:

- Money. They attack banks, financial institutions or any other companies. For example, in the first quarter of 2022, hackers stole crypto assets worth €1.3 billion from users.

- State interests. Most often, these structures include peoplewho are close to government agencies or military personnel. For example, the pro-government Chinese group TA428 has been engaged in cyber espionage in Eastern Europe for several years.

- activism. Hacktivists are attention-grabbing hackersto social issues or political ideas through cyberattacks. They attack government websites, servers of large companies, for example, in the name of freedom of speech. There is no material benefit in the actions of such hacker groups. A group of hacktivists can have very different people in their views and goals. For example, the Anonymous group compares itself to a flock of birds: some birds join, others leave it and fly in a different direction. Therefore, it is difficult to determine who exactly is in this group.

Recently, another type has begun to be distinguished -attacks with implicit motivation, when it is difficult to determine the intentions of the perpetrator. Anyone can be among these hackers. For example, the group "Crackas With Attitude" included a British schoolboy who, at the age of 15, without a specific purpose, gained access to the personal information of the head of the CIA. There are many of them: someone plays "Mr. Robot", suffers from idleness and changes grades for students in a rural school.

There are also unwilling hackers - people whoare involved in cybercrime, but they themselves do not know about it. Specialists are hired for regular work as programmers, they perform small tasks for the development of modules, and then these modules are combined into hacker tools. These employees turn out to be malware creators. In order to attract applicants for such work, attackers often disguise themselves as real HR of serious IT companies.

Where talents are born

Hackers not only "have no face", this activityalso international. There is a myth about Russian hackers, they are especially demonized in the USA. Hackers from Russia are credited with cyberattacks on the instructions of the Russian special services. For example, two years ago, the United States announced the involvement of the Sandworm Team hacker group in the GRU of the Russian Federation.

In fact, there are hackers in most countriesWorld: America is the leader in carding-related crimes, and there are many well-trained pro-government groups in China. Every technologically advanced country has its own “cybers”. For example, in the spring of this year, Group-IB helped Interpol catch the leader of a cyber group from Nigeria.

Criminals may have different motivations andnationality, but cybercriminals have one thing in common - they improve the means for attacks. New trends appear, the tools and techniques used by the attackers change.

“Hackers have no face, this activity is also international”

Cybercrime Trends: From Phishing to Ransomware

Cybercriminals have their own attack patterns for every victim they target. Be it state corporations or bank card holders.

For example, in 2021, 45% of Russians experiencedphishing. The word itself means "fishing". This is a type of fraud in which hackers want to extract confidential information from users: login, password, account or bank card information, in order to sell them later or harm the victim.

One of the most common phishing methods isThis is vishing, phone phishing. Using his example, one can understand how well the infrastructure of such criminal groups is developed. Here everyone has their own task. The administrator coordinates the group's activities and determines who will pose as the bank's security officer and who will communicate with the client, helping the victim transfer money or withdraw it from an ATM. Some scammers even "connect" the victim to "law enforcement" who confirm that someone is trying to steal money from the customer's card. The scammers learn the contact and personal data of the victim by buying “leaked” databases on the dark web.

Phishing crimes are on the riseand data acquisition methods are improving. For example, affiliate programs for criminals have recently appeared, where new attackers are introduced to tools, attack methods, and are helped in every possible way. Hackers use digital marketing: they study the target audience, create personalized links, content, develop attack strategies.

You can access confidential dataand without interacting with their owners. To do this, JS-sniffers are used - a code embedded in the websites of online stores or other platforms where card users make online purchases. This code steals user data, such as those needed to pay for goods. Attackers can steal money, pay for goods, or sell data on the dark web.

If the main goal of the attack is extortion, more oftenjust use cryptographers. These are programs that encrypt user files, after which hackers begin to blackmail their owner. A couple of years ago, many groups that used ransomware to attack various organizations gained access to victims' computers through brute force (hacking by guessing a username and password), "spilled" the ransomware, and then asked for a ransom. Later, attackers began not only to encrypt data, but also to steal it before extorting a fee. So they increased their chances by demanding a ransom not only for decryption, but also for the fact that the stolen data did not fall into the public domain. In this way, in 2021, the American pipeline system Colonial Pipeline was attacked. The work of all pipelines was stopped for 5 days, and a state of emergency was declared on the entire East Coast.

Later, RaaS appeared - services in whichoperators develop ransomware and write guides on how to use them. Any group can get these guides and malware for their attacks by paying a percentage to the developers.

Recently, a new trend has emerged:using Initial Access Brokers to gain access to the victim's network. "Initial access brokers" use various techniques to gain access to "secure" networks and then sell it to other attackers.

The availability of information is giving rise to more and morenumber of cybercrimes. Now it will not be difficult to find the right guide, framework or use an affiliate program if the criminal sets himself such a goal. That is why it is always necessary to observe digital hygiene in order not to become a victim of hackers.

Who investigates high-tech crimes

Data security is handled by many differentspecialists. For example, pentesters and redtimers are white hat hackers. Clients hire them to find vulnerabilities in a system or figure out how to improve data security. "White hackers" simulate attacks on the company's information resources, looking for vulnerabilities so that a real attacker cannot use the same methods.

There are many different specialists involved in data security—they are called “white hat hackers.”

There are companies that specialize inprevention and investigation of cybercrime, for example, Group-IB. They have entire teams that consist of incident response specialists, computer forensics, malware analysis specialists, security solution developers, and other specialists to counter hackers.

It may seem that to enter the circle of specialists,who fight against cybercriminals is difficult and requires a special background. In fact, if there is a desire and time, a person with any education can master these professions. For example, the head of the Group-IB computer forensics laboratory has a liberal arts education.

Due to the increased cyber threat, the demand forcybersecurity professionals have grown sharply. About 2.5 thousand vacancies for information security specialists were published on the HeadHunter website in July. Vocational training is also available -  Many educational institutions have opened specialized areas and courses.

A profession in information security is a prestigious and interestingwork, it will only be more in demand. Gartner analysts predict that by 2025, cybersecurity will become a priority for 60% of companies when choosing business partners. And the law on the protection of personal data will cover 5 billion people.

"Use two-factor authentication and complex passwords"

Digital hygiene is not a whim, but a necessity

Many specialists are working to stop hackers, but users should not forget about digital hygiene, although there is no 100% security guarantee.

  • Use two-factor authentication and complex passwords with twelve or more random characters: letters, numbers, and optional characters.
  • Do not store passwords in browsers, text fileson a computer or phone. The best way is a password manager, a centralized "safe" that stores passwords in encrypted form. It also helps to generate complex combinations.
  • All passwords must be changed periodically.
  • Check links before clicking on them.Be careful when entering personal data - phishing groups often disguise themselves as legitimate sites. Check domains with dedicated resources like VirusTotal, which analyzes suspicious files and URLs.
  • Do not trust emails with sweepstakes and super-lucrative offers, even if they allegedly came from Google or Telegram support.

Digital hygiene is vigilance. But even following all the rules does not guarantee security and there is always a risk of suffering from the actions of scammers.

Read more:

The ancient Vikings suffered from a dangerous disease. It is caused by a parasite from Africa

Plant on Mars produces oxygen at the rate of an average tree

Physicists have cooled atoms to record temperatures. They are a billion times colder than outer space.