Cyber extortion techniques

Cyber extortion techniques




Introduction to cyber extorsion

In the digital age many insufficiently educated and naive users can easily be tricked into opening  malicious e-mails or downloading extremely harmful files presented as free or useful applications. Most of them can be deleted and stopped by modern antivirus software but some of them pass unnoticed and get implanted into computer system causing data loss, information leakage and other serious problems that can hardly be solved. In the digital age, data has a great value for business purposes, but also for criminal intent of cyber extortionists. Legitimate users can be threathened in many ways by temporary encoding its data by encryption, restricting data access (e.g. DDoS), and the data can also have discreditable effect on the victim which enables extortion with digital video clips and miscellaneous personal documents. Data can therefore be seen as a hostage of modern digital world. It can be held in a complex manner by replacing the encryption key existing in a database, and holding the new key hostage., it can be held brute-force style via DDoS, or as simple as stealing the latest backup and deleting the original version from the owner�s servers. This post should educate you about cyber extortion, the actors involved, and most probable repercussions. Those techniques are also described on here. Figure 1 shows that cyber extortion can target miscellaneous websites, corporations and individuals using different techniques like malware and DDos attacks.

                                                               
      Figure 1: Cyber extortion targets and techniques

Ransomware

Ransomware is a type of malware specifically designed to block or encrypt data, followed by a ransom demand. Figure 2 shows that the ransomware attack begins when a PC is under attack by a cyber extortionist using different social engineering or penetration techniques and a victim then has a choice to pay or not to pay the extortionists to save their encrypted data or blocked computer. When ransomware attack occurs, a warning message usually pops up explaining that an attempt to uninstall or inhibit the ransomware�s functionality in any way would lead to an immediate data loss. Ransomware is usually spread by spam, phishing emails with malicious attachments, links to bogus websites, and malvertising. Once a victim�s system is accessed, an encryption type of ransomware installs itself and launches a complete hard disc scan, in order to locate documents of interest that will be converted into an unreadable form and some ransomware programs typically �lock� the entire PC, terminating all processes that are non-essential to paying the ransom, and can eventually receive an �unlock� code.  Finally, a ransom message is displayed on the victim�s screen that demands a particular sum (usually between $100-1,500 for ordinary users) in exchange for a decryption key (usually claimed to be unique). One of the most famous ransomware is a malicious program called CryptoLocker, encryption based ransomware published on 5 September 2013 which was successfully used to extort  a total of around $3 million from victims.

     Figure 2: Ransomware attack
                           
DDoS attack

Another popular extortion tactic is to threat a company�s website or online business with a DDoS attack.  DDoS can be organized by extortionists, unfair competitors, or pesky people who just want to prove their hacking power and a DDoS imposed downtime might cost the targeted company a loss in revenue, clients, and prestige. They target a wide variety of important resources, from banks to news websites, and present a major challenge to making sure people can publish and access important information. 
And DDoS service prices are constantly going down, which also contributes to the epidemic proportions of this problem and depending on how huge the target is, rates for downing websites vary from as little as $5 to $100 per hour. DDoS dealers circulate everywhere online, in underground forums, even on the public Internet and theyir attacks are very difficult to stop. Similar to some instances of ransomware, DDoS attacks may be time limited in order to achieve a maximum psychological effect. Cyber extortionists justify the ransom size with crude calculations of the approximate financial negative impact on the victim�s online business in the event of successful DDoS attack.

In this post cyber extortion techniques and its main consequence and properties have been described, ransomware and DDos attacks have been explained. In the next post, social aspect of those activities will be described along with the victims dillemas that may occur in those situations.

download file now