This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

The Mass Effect: How Opportunistic Workers Drift into Cybercrime

Download resources

About this session

Masarah Paquet-Clouston and Serge-Olivier Paquette recount a research journey with Sebastian Garcia's Stratosphere Laboratory that began with the Geost Android banking botnet and ended with a statistical portrait of an informal workforce at the periphery of cybercrime. A private Skype log of about 6,000 Russian messages among 32 people who spread Geost's infected APKs revealed three key actors, an entrepreneur, a developer and a webmaster, who also posted publicly on searchengines.guru, a half-million-member internet marketing forum. Using Flare Systems data, they embedded 400,000 forum users with UMAP, ran a thematic analysis of the chat (an adverse business environment, amateur work, leniency toward criminality) and found the trio near the map's undifferentiated centre. Username matching with entropy and time filters identified about 1,500 'drifters' active on 38 cybercrime forums, statistically indistinguishable from other users; group-based trajectory modelling showed roughly three quarters stay 'criminal curious' while a quarter migrate permanently. Across similar forums, that is a mass of hundreds of thousands of opportunistic workers, which they argue policy should address through legal opportunities rather than by chasing motivated offenders alone.

By focusing on the most visible cybercriminals, our security community often overlooks the impact of massive groups supporting criminal activities. Yet, these groups act like the “mass effect”, where a primary pathology generates

an inflating mass that pressures its surrounding, increasing the initial problem’s scale. This research was motivated by a desire to uncover the context and motivations of individuals involved in spreading the Geost

banking Trojan, and ended with large-scale statistical analyses of behaviors in an informal online market, one of the largest out there. The market was found to host dubious activities through a hide in plain sight approach.

The research unexpectedly opened-up an alternative way of conceptualizing cybercrime economies, one that includes an ordinary working class, involved in any

economic activity for the sake of little crumbs of profit. More than that, we realized that the motives of these individuals did not represent the excitement that is traditionally depicted by cybersecurity storytelling, nor

they embodied the criminal ethos. What is concerning is rather their aggregated effect, their growing mass.

This presentation shares our research journey, depicting the actors involved in the operation of a botnet, their motivations, challenges, and an analysis of the informal market in which they grounded their criminal activities. By using machine learning techniques and a statistical analysis of the informal market population, we found other similar opportunistic entrepreneurs. The analysis also indicated that the informal market may be a revolving door to underground, more criminally prone, communities.

Through this research, we hope to provide researchers, law enforcement officials and policy makers a better grasp on this type of cybercrime economy and a point of view that is closer to what these individuals actually experience.  

Key takeaways

  • Look beyond the botnet operators: malware distribution depends on a peripheral workforce of low-skill, poorly paid contractors recruited on ordinary forums.
  • Private chat logs found on VirusTotal can be paired with public forum data to reconstruct who does what in a criminal operation.
  • Username reuse across platforms, filtered by entropy and time window, gives a defensible lower bound on overlap between legitimate and criminal communities.
  • Do not expect posting behaviour to flag drifters; on this forum none of the tested variables separated them from other users.
  • Prevention policy should offer legitimate opportunities to the 'criminal curious' rather than focus only on motivated offenders.

Speakers

Masarah Paquet-Clouston
Masarah Paquet-Clouston
Security Researcher · GoSecure
Masarah is an assistant professor at Université de Montréal and a research collaborator at the Stratosphere Laboratory affiliated with the Czech Technical University in Prague. She holds a Ph.D. in criminology and is specialized in the study of… Read moreRead less

Masarah is an assistant professor at Université de Montréal and a research collaborator at the Stratosphere Laboratory affiliated with the Czech Technical University in Prague. She holds a Ph.D. in criminology and is specialized in the study of profit-driven crime enabled by technologies. Previously, she worked five years at GoSecure as a researcher and has presented at international conferences including NorthSec, BlackHat, DEFCON and RSA.

Serge-Olivier Paquette
Serge-Olivier Paquette
Senior manager of data science · Secureworks
Serge-Olivier Paquette is the senior manager of data science at Secureworks. His research focuses on the ability to infer, through machine learning, the context of security events from incomplete information. He also serves as President for… Read moreRead less

Serge-Olivier Paquette is the senior manager of data science at Secureworks. His research focuses on the ability to infer, through machine learning, the context of security events from incomplete information. He also serves as President for Northsec, a non-profit organization that hosts a series of world-class technical cyber security events, held annually in Montreal.

Sebastian Garcia
Sebastian Garcia
Network malware researcher · Czech Technical University
Sebastian Garcia is a network malware researcher and Assistant Professor that has extensive experience in machine learning applied to network traffic. He created the Stratosphere IPS project, a machine learning-based, free software IPS to protect… Read moreRead less

Sebastian Garcia is a network malware researcher and Assistant Professor that has extensive experience in machine learning applied to network traffic. He created the Stratosphere IPS project, a machine learning-based, free software IPS to protect the civil society. He likes to analyze network patterns and attacks with machine learning. As a researcher in the AIC group of Czech Technical University in Prague, he believes that free software and machine learning tools can help better protect users from abuse of their digital rights. He has been teaching in several countries and Universities and working on penetration testing for both corporations and governments. He was lucky enough to speak at Ekoparty, DeepSec, Hacktivity, Botconf, Hacklu, InBot, SecuritySessions, ECAI, CitizenLab, ArgenCon, Free Software Foundation Europe, VirusBulletin, BSides Vienna, HITB Singapore, CACIC, etc. As a co-founder of the MatesLab hackspace he is a free software advocate that worked on honeypots, malware detection, distributed scanning (dnmap) keystroke dynamics, Bluetooth analysis, privacy protection, intruder detection, robotics, microphone detection with SDR (Salamandra) and biohacking.

Resources

Tags

More from GoSec 2021

Also from Masarah Paquet-Clouston

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.