Tag: dark web

  • Ransomware Ecosystem: How Are Cybercriminals Structured?

    Ransomware Ecosystem: How Are Cybercriminals Structured?

    When the media reports on ransomware, you often see the end result: the stolen corporate data has ended up on the dark web. But what happened before that? Is there a single “hacker” or cybercriminal who is solely responsible for all of this, or does the ransomware ecosystem work differently?

    A Ransomware Ecosystem Based on Division of Labor

    Contrary to what is still frequently reported today, cyberattacks are generally not carried out by a single individual. Instead, the actors behind the scenes are highly organized, with a clear division of labor. The structure behind ransomware groups can be represented in an organizational chart, much like that of a typical company.

    Ransomware Organizational Chart
    Ransomware Ecosystem: CEO, Developer, Hosting, Customer Service, Affiliates, Initial Access Broker

    The Ransomware Operator / CEO

    At the very top of the organizational chart is the managing director (or “CEO”). He ensures that the individual “departments” work together as smoothly as possible, assigns tasks, establishes rules and principles, and primarily handles organizational responsibilities. This includes, for example, stipulating that no medical facilities (e.g., hospitals) may be attacked in the name of his organization. The position of managing director/organizer may be held by more than one person.

    Development

    The actual malware is programmed in the development department. In some cases, individual developers work here, while in others, teams handle the task. Generative AI is also being used more and more frequently in this area, either to assist with development or to take over entire development steps.

    Hosting

    Hosting is often outsourced to specialized “bulletproof hosting” providers. Their business model essentially consists of accepting (almost) anything on their servers, or, in other words, not looking too closely at what’s being hosted. They also generally do not respond to requests from authorities to hand over data or to shut down the hosted services.

    Affiliates

    Affiliates are individuals recruited externally, often on the dark web, who leverage the ransomware group’s existing infrastructure and established reputation to actually attack companies, steal data, and leave a ransom note. The affiliates’ methods are diverse, ranging from exploiting technical security vulnerabilities to using stolen credentials they have acquired on the dark web. These credentials are offered by so-called “initial access brokers” and often originate from computers that have been infected with infostealer malware.

    Customer Service

    If a company is willing to pay the demanded ransom despite all recommendations against doing so, it often does not want to pay the full amount. To allow for further negotiation, the criminals typically provide a customer service channel and are often willing to negotiate within certain limits. This customer service channel is also used to guide inexperienced victims, for example, by explaining how to purchase Bitcoins for the ransom and then “transfer” them to the ransomware operators. Once the ransom has been paid, a decryption code is often provided.

    Money Laundering

    Bitcoins are anything but an untraceable form of payment. Most cybercriminals are now aware of this as well. As a result, they often use services that claim to conceal the true origin of illegally obtained ransom payments. In some cases, there is also overlap with traditional organized crime (outside the purely digital realm).

    Conclusion

    The ransomware ecosystem is structured as follows: The actors work in a division of labor and are by no means lone wolves. Any gaps in knowledge are filled by recruiting people into their own organization or through outsourcing. Just like in a normal company, there is a sort of CEO and various departments reporting to them. This way, everyone fulfills a clearly defined role. These roles cover a wide range of tasks, from developing malware and launching attacks on corporate infrastructure to laundering the ransom payments they receive.

  • Darknet – What is the Clearweb, Deepweb and Dark Web?

    Darknet – What is the Clearweb, Deepweb and Dark Web?

    Many people have heard of the “darknet”, but what exactly is it all about? Is it the dingy corner of the internet where only criminals hang out? In this article, you will learn the most important basics about the darknet and what you need to connect to it.

    Clearweb, deepweb, darknet and dark web

    In simple terms, the clearweb is the part of the internet that our parents can access. It is the part of the internet that can be accessed with standard hardware and software without any special access restrictions. This is where you can find news and streaming portals, webmail providers, forums and this blog, for example.

    The deep web is the part of the internet that cannot be found in the search engine index (e.g. Google, DuckDuckGo, etc.). This is where you can find underground hacking forums, for example, but also something like a university’s online repository, where users first have to register in order to access the latest scientific publications.

    Special access software is required to access the Darknet. Due to this additional hurdle, the term “hidden services” is often used. Sometimes the term “onion services” is also used in reference to the domain that can be found in the Tor network.

    Difference between darknet and Tor network

    According to the definition, there is not just one darknet. However, the most widespread today is the so-called “Tor network”. Tor, formerly written in capital letters TOR, originally stood for “The Onion Router”. In addition to the Tor network, which is managed by the “Tor Project”, there are also other ‘darknets’, such as the “Freenet Project”.

    Theoretically, you could also team up with your friends, program your own access software and you would have your own “darknet”.

    When people talk about “the darknet” in the media or colloquially, they are usually referring to the Tor network. This is the best-known and most widespread “hidden” network.

    Is there a difference between darknet and dark web?

    Darknet and dark web are actually different. The darknet refers to the entire network that can be accessed via the special access software. In addition to web browsing, this also includes other predominantly TCP-based services, such as SSH (Secure Shell), instant messaging or VNC.

    By using the Tor network, you can, for example, access devices in your home network (after prior configuration), even though you are located elsewhere in the world.

    Is the dark web illegal?

    Using the Tor network is not illegal as long as you are not doing anything illegal there.

    So if you just enjoy the additional anonymity and look at legal things on the darknet, you are completely legal.

    However, as soon as you do something illegal – and there is a lot of it there – it is of course just as punishable as on the Clearweb. Examples of illegal use are hate comments, ordering drugs and any form of cybercrime.

    How do I connect to the Tor network?

    Connecting to the darknet is surprisingly easy. Download the so-called “Tor Browser” from the official website (and only from there, please!). Search for the “Download” button on the official website torproject.org and download the Tor browser for your operating system (e.g. Windows or macOS).