Wednesday, May 1, 2024

Cybercriminals scamming each other for millions, report reveals

Cybersecurity company Sophos unveiled a four-part report which indicated that cybercriminals are scamming each other out of millions of dollars and use arbitration to settle disputes about the scams.

Photo from Freepik.com

The report also revealed how attackers use classic techniques — some decades-old, such as typo-squatting, phishing, backdoored malware, and fake marketplaces — to carry out their scams against each other.

For this report, Sophos X-Ops experts investigated Exploit and XSS, two Russian-language cybercrime forums that provide Access-as-a-Service (AaaS) listings, and BreachForums, an English-language cybercrime forum and marketplace specializing in data leaks. All three sites have dedicated arbitration rooms.

The practice of scammers scamming scammers is lucrative. During a 12-month period, Sophos examined approximately 600 scams that resulted in threat actors losing more than $2.5 million to each other, just on these three forums—with claims ranging from $2 to $160,000.

“While investigating cybercriminal scams, we stumbled upon an entire sub-economy that includes not just lower-tier criminals, but some of the most prominent ransomware groups. And these scams aren’t always just financially motivated. Personal beefs and rivalries were common,” said Matt Wixey, senior threat researcher at Sophos.

“We also found incidents where scammers would scam the scammers who scammed them. In one case, we found a trolling contest set up to get revenge on a scammer trying to trick users into paying $250 to join a fake underground forum. The ‘winner’ of the contest received $100.”

Sophos also discovered that the arguments and arbitration process left behind a wealth of untapped intelligence that security professionals and law enforcement could leverage to better understand and defend against cybercriminal behaviors.

“Because criminals often need to offer up a lot of evidence when reporting the scams that they themselves have fallen victim to, they provide a wealth of tactical and strategic information about their operations — something which has been an untapped resource until now,” Wixey said.

“These arbitration reports also give us an inside look at attackers’ priorities, their rivalries, and alliances, and, ironically, how they’re susceptible to the same types of deception used against their victims.”

Subscribe

- Advertisement -spot_img

RELEVANT STORIES

spot_img

LATEST

- Advertisement -spot_img