跳到主体内容

Beaches, carnivals and cybercrime: Kaspersky Lab shares insights on Brazilian cyber underground

2015年11月11日

Unique local cyberattacks and international cooperation with criminal groups in Eastern Europe, unsound government security and vague legislation, theft of money and private data, direct offensive ops on local victims and criminal-to-criminal services

Unique local cyberattacks and international cooperation with criminal groups in Eastern Europe, unsound government security and vague legislation, theft of money and private data, direct offensive ops on local victims and criminal-to-criminal services. For the first time Kaspersky Lab shares its intelligence on the human side of underground cybercriminal activity. The first report in the Cyber Underground series reveals the hidden life of cybercriminals in Brazil, a country ranked among the most dangerous for digital citizens.

Biting the hand that feeds

Unlike cybercriminals in other countries, who in general do not respect borders and operate globally, Brazilian cybercriminals are focused on ripping off their own fellow countrymen and local businesses. One of the reasons is vague legislation, resulting in fewer arrests for cybercrimes: the report cites a few examples when exposed criminals ended up spending little to no time in jail. Perceived impunity leads to cybercrime operating almost in the open. In other words, the cyber underground research in Brazil does not demand a lot of digging: criminals are mostly selling their goods and tools like a legitimate business, flashy landing pages and social network promotion included.

Expanding overseas

Operating locally does not mean that cybercriminals are not interacting with their counterparts in other countries. The report reveals how Brazilian criminals reach out to their colleagues in Eastern Europe. They share know-how, exchange favors and purchase services like bullet-proof web hosting. There is sufficient evidence that Brazilian criminals are cooperating with the Eastern European gangs involved with ZeuS, SpyEye and other banking Trojans created in the region.

Monitoring such activity around the world allows Kaspersky Lab to foresee the emergence of a certain cyber-attack and fine-tune protection methods, based on the knowledge obtained in another region.

Local peculiarities

Regional specifics is key to better understanding the threat landscape, and the Brazilian Cyber Underground report proves that. One of the most striking examples is the attack on boletos – banking documents specific to Brazil, used both online and offline to transfer money and pay for the goods. Boletos are part of online-offline system where one generates a payment order on a computer, but then prints it on paper and goes to the brick-and-mortar institution to proceed with the transaction. Boletos rely on barcodes, and cybercriminals have found a way to manipulate them to redirect money transfer to a different account.

In 2014 Brazil was ranked the most dangerous country for financial cyber-attacks. The constant monitoring of Brazilian cybercriminals’ malicious activities provides IT security companies with a good opportunity to discover new attacks related to financial malware.

Privacy issues and government security

Another notable weakness of Brazilian cyber environment is security of government and corporate IT resources. The report provides quite shocking examples, such as a seriously flawed government online resource leaving sensitive data about almost every Brazilian citizen in the open. Cybercriminals are also selling access to statewide data brokers, containing loads of private data, for a mere few dollars. In addition, an attack on a state IT resource, has directly led to further elimination of the Amazon rainforest.

Criminal-to-criminal

The report explores in-depth the business-to-business operations of the Brazilian cyber underground, when different groups cooperate and share their own part of intelligence or technology with each other. The so-called criminal-to-criminal ops are highly developed and widespread: a criminal is granted access to almost any service one can imagine, from illegal access to private data, to made-to-order development of malware. A ransomware toolkit costs only US$30, a keylogger is ten times more expensive.

Intelligence is the key

“One could imagine the work of Kaspersky Lab’s security experts as day-after-day crunching of malicious code. And this perception is quite true, but the expertise in social and business side of the cyber underground is also important. This report shows some examples of this intelligence that helps us to fine-tune the protection for our customers and develop new security technology. In Brazil, like in almost all other countries, we know the agenda of cybercriminals; their current heists and future plans. Combining this knowledge with deep technical expertise of cyber threats, we are able to fight the cybercrime even more efficiently. At the same time, when you look at the Brazilian cyber environment, you see that even the greatest effort from a security company is not enough. The solution to a safer cyberspace is intelligence sharing and cooperation between the security industry, businesses and government, including law enforcement”, commented Fabio Assolini, senior security researcher at Kaspersky Lab’s Global Research & Analysis Team.

Kaspersky Lab’s Cyber Underground report on Brazil is available at Securelist.com. To download the PDF version of the report click here.

Beaches, carnivals and cybercrime: Kaspersky Lab shares insights on Brazilian cyber underground

Unique local cyberattacks and international cooperation with criminal groups in Eastern Europe, unsound government security and vague legislation, theft of money and private data, direct offensive ops on local victims and criminal-to-criminal services
Kaspersky logo

关于卡巴斯基

卡巴斯基是一家成立于1997年的全球网络安全和数字隐私公司。卡巴斯基以“网络免疫”理念引领行业创新,致力于保护消费者、企业、关键基础设施和政府机构免受网络威胁,迄今为止已保护超过 10 亿台设备。

卡巴斯基秉持“Cybersecurity True to Business”的理念,专注于交付明确成果、保障营收、减轻团队负担并避免业务中断。卡巴斯基深厚的威胁情报和安全专业知识不断转化为创新解决方案和服务,服务于从小型企业到大型集团等各种规模的组织,将成熟的 AI 驱动型保护技术与简洁高效的管理和专家支持相结合。

卡巴斯基的解决方案经独立测试认可,深受全球数百万个人用户及近 20 万家企业的信赖,帮助客户更早识别威胁、更快速响应,以更强的信心与自由空间开展业务,保护对客户至关重要的资产。了解更多详情,请访问 www.kaspersky.com.cn

相关文章 企业新闻