Everyday life of a cyber detective: spies, cartels and Russian hackers

Victims of hackers - from ordinary users to states

The most common victim of hackers is

financial companies.Who can be the victim of a hacker?The first thing that comes to mind is banks. Still, money is the most pressing issue, especially in Russia. But this is not the only motivation, and banks are not the only object of interest to hackers.

They attack not only the financial sector, but alsotelecom or energy. Ordinary users, marketplaces, online trading platforms are under threat. No one is protected - the accounts of those who use the Internet and buy goods can be hacked. And for ordinary users, the main threat is theft of personal information, account hijacking.

Hackers are of different levels - from fraudsters to special services.There are several levels of crackers, and each of them has its own victims.

First of all, there are ordinary petty fraudsters.Attacks to attract attention, earn extra money, steal someone's accountfor fun, to prove that "I can do it."

But there are also organized groups thatdeal with attacks professionally. They prepare multi-stage targeted attacks and go through the entire process from infiltrating an organization to accessing isolated network segments where important data is located, such as card processing systems in banks or servers with critical information.

The next level is people who attackpro-government sites, it can be intelligence agencies and government hackers. They usually hack into energy infrastructure and the telecom sector.

In 2020, many of these groups switched toreal military operations, attacks of critical objects. Nuclear facilities are especially often attacked. Moreover, this is done in certain countries - where there is a military conflict, rival countries begin to attack each other. For example, in 2020 there were many such attacks in Iran and Israel - the political situation was reflected in what happened in cyberspace.

Russian hackers are an established image. But their influence is exaggerated

There are hackers from Russia, but in the United States, their image has been demonized.Recently, there have been a lot of rumors and accusations against Russian hackers.This is due to the fact that most attacks are carried out on the financial sector, such as bank card thefts,  mostly occurGiven the relationship between the two governments, many are beginning to suspect the Russians.

During the race and after the US electionsRussian hackers were accused of interfering in the process. What is the reason for this, given that there is no evidence? Sometimes hackers joke - for example, a specialist in Internet technologies and the author of the Russian apache web service published a post like this.

He collected a lot of reposts and responses, many supported the joke.

Or another example - early presidential electionsUSA on Public Services. If a person reads Russian "Twitter", knowing the language, how can he know that we have such humor? So the picture is emerging - Russian hackers who are sitting in a hat with earflaps with a tame bear and breaking into the Pentagon. This is superimposed on the idea that Russian programmers and developers are some of the best on the world market.

Russian hackers have an unspoken rule - do not work in the .ru zone. But not everyone does this.It's logical and obvious: don't work where you live. If you work in the .ru zone and live in Russia, you will be identified much faster. Most attackers follow this rule.

But there is an exception - the OldGremlin group does notcomplies with this rule, they like to take risks and attack Russian companies in the field of medicine, health care and finance. That is, they have no specific goals - they attack completely different organizations throughout Russia. In 2020, they carried out at least nine attacks, encrypted entire corporate infrastructures and demanded significant ransoms for this.

Blackmail, politics and money: why hackers take risks and attack

Hackers not only want to make money, sometimes it is an ideology.Money is the biggest motivation.But if we are talking about pro-government groups, then they want to gain access to some super-secret information. Hackers want to research it and transfer it to their state, so that the authorities can later use it for their own purposes.

But there are more and more motivations every year.Someone wants to take a chance, others want to see the world on fire, and still others want to take money away from some and pass it on to others. Someone wants to prove that he can hack some systems, or to practice.

Plus there are hacktivists - hackers who wantto draw attention to the problem through attacks. For example, the Anonymous group are the very guys who every year carry out actions and attacks in honor of the victims of the Holocaust. Therefore, every year it becomes more and more difficult to determine what is the real motivation for a particular attack.

During the pandemic, many switched to ransomware.This way you can gain access to financialorganization and not have to worry about getting into an isolated network segment and understanding the control system. It is much easier to find important information, copy it, encrypt it and ask for a ransom for it.

One of the latest trends is affiliate programs... For example, some group has opened access tocorporate network of the organization. But they can't do anything about it, they don't have the right tools. For this, there are ransomware operators who have the tools to encrypt everything. Why don't they unite? Some get access, others encrypt everything, and they divide the ransom among themselves.

It got to the point that some operatorsCryptographers, such as the Maze group, have organized their own cartel. Moreover, the trend has become not just encryption of everything in a row, but only important data. If attackers see that there are backups of this information, they delete or steal it.

They not only ask for ransom, but also threaten thosethat the data will be in the public domain. This increases the value of the data and the likelihood of being paid for sure. Maze even has a website where they post stolen data from companies that refused to pay them.

Those who engage in phishing have also switched to affiliate programs.So far, Russia is the only country where this phenomenon exists.

Phishing in Russia is evolving every year.stronger. Over the past year, 118% more fraudulent resources have been identified. And now clones of sites are made for absolutely everything - sports betting, Netflix, Microsoft, Steam. Due to the fact that people do not have high awareness, and due to the fact that they cannot determine that the link is fraudulent, the number of victims is growing.

Billions of dollars, stolen accounts and the sale of personal data

Hacks are a huge market, but these statistics are incomplete.The total carding market this year amounted to almost$2 billion, but this is only 3% of the total number of attacks. In other cases, it is unknown how the attack ended—whether they were paid or not; companies prefer not to disseminate such information. This is a large amount, but it is not even close to the real figure.

If we take the first half of 2020, another 227 accesses have appeared on sale, and this is only in open sources. There are also private forums, we have no data on them.

Cyber ​​detectives prevent hacking and search for criminals.Images of real ones immediately come to minddetectives, Sherlock Holmes. But a cyber detective investigates cyber crimes - Holmes could collect evidence, investigate it, draw conclusions and find the culprit. In cyberspace, the situation is more complicated, there is no universal specialist who can do everything perfectly. Therefore, a cyber detective has a composite image.

What should be done when an attack occurs?First, it needs to be detected - for this there are special organizations that monitor cyber threats around the world. Nowadays, many companies that truly value their security maintain a monitoring team that looks at and validates suspicious activity reports.

Then panic begins due to the attack, especiallyif there is suspicious traffic and it was detected. The analysis is very short-term, it takes 1-2 hours. If during this time it is not possible to collect information, then everything is passed on to the incident response specialists. They begin to collect evidence, examine digital artifacts and try to understand how they got into the organization, whether they are in the organization now, at what stage of the attack. At the same time, incident investigators investigate the malicious code.

If a company wants to punish a hacker, it needs to collect evidence.This is where classic forensics comes into play.Incident response and forensics follow each other, they use the same base. Forensic experts collect digital evidence, analyze it, draw conclusions from it. These findings will help formulate the application for the court. During the trial, an examination will also be carried out, which will involve computer forensics.

If there is an assumption who carried out the attack - thatdo next? In the digital space, everyone has a digital personality that leaves traces. There are separate specialists who are trying to connect a digital portrait and a real person. This is a laborious process, it takes a very long time. These specialists create social graphs and investigate the places where the accounts were lit up and what information was there. They try to analyze how the communication between the attackers took place and look for little clues. Then they restore the full picture bit by bit and work directly with the authorities that detain hackers and groups.

A hacker can be caught on his digital footprints.There is always a human factor, some small oneshuman errors, mainly due to them, are what catch real people. Someone, for example, stole so much that there was nowhere to spend the money and the person began to send money without laundering, putting it on the phone of loved ones. Someone there couldn’t leave the girl, corresponded with her and got caught. There was a case when it was possible to identify all the group members because they had a correspondence where they discussed a friend’s wedding and there were common photographs.

How digital hygiene helps protect personal data

In order to protect your data, you need to adhere to several rules.Most users are not familiar with the rulesdigital hygiene, although they are very simple. There is nothing complicated about using different passwords, but they are difficult to remember. There is a solution for this: password managers. Therefore, it is very important to understand this topic, monitor your digital hygiene and increase your level of awareness. I made a checklist: what needs to be done right now, what needs to be done always and what needs to be done regularly. But the most important thing is to really pay attention to this problem, remember that it is important, and remember that it is necessary.

The most important misconception: “Who needs me?Who will attack me? " In fact, everyone is being attacked right now. Common scammers want social media accounts that they can then resell.

There is a constant race between cybercriminals and cybercriminals.When one side comes up with something, others find a way around it. This is an endless process - an eternal battle between good and evil, which grows like a snowball.

Remember, hackers are real, they are not legend. And they are interested in everything, and you are no exception. So use a checklist, watch your digital hygiene, and be careful.

Read more

Chinese open-top electric car maneuvers like a motorcycle and changes the position of the steering wheel

See the prehistoric skis found in the Norwegian glacier. Archaeologists are now looking for their owner

Take a look at digital art made from analysis of Isaac Asimov's books