Chinese Cybercrime Develops Lucrative Hacking Services

Stu Sjouwerman | Jan 2, 2018

The McAfee blog gave an interesting perspective on an area we do not look at too closely normally. 

Underground cybercrime profits in China have likely already exceeded US$15.1 billion (100 billion Chinese yuan); caused more than $13.8 billion (91.5 billion yuan) worth of damage relating to data loss, identity theft, and fraud; and will grow at an even faster pace as underground hackers expand international business operations to increasingly target foreign businesses, according to one Chinese report.

Operating-Structure-1-707x1024 Image Courtecy McAfee

Advanced hacking tools such as botnets, control server infrastructure, remote access tools, malware creation and obfuscation services, source-code writing services, and targeted exploitation toolkits are available on underground markets.

The upshot of the report is that the Chinese cybercrime underground mostly targets Chinese citizens and businesses. However, a growing number of criminal groups offer hacking services that target foreign websites or businesses.

These underground criminal groups are stealthy and have gradually grown in sophistication through an institutionalized chain of command, and by setting master-and-apprentice relationships to expand their business operations. 

They offer a variety of malicious tools and hacking services through instant messaging networks like Tencent and have established successful surreptitious transaction processes. For example, Tencent QQ, is an instant messaging software service that also offers online social games, music, shopping, microblogging, movies, and group and voice chat software.

Any multinational with an operating company in China would be smart to step their employees through new-school security awareness training so that they are an effective human firewall against criminal hacking attempts. 

We strongly recommend to phish your own users to prevent these types of very expensive snafus. If you're wondering how many people in your organization are susceptible to phishing, here is a free phishing security test (PST):

Get Your Free PST Now

Source: McAfee 

Topics: Cybercrime

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.