sb-nz logo
Story image

Dark web dangers threaten world's top enterprises

17 Jun 2019

The dark web is now a serious threat to enterprises, with 4 in 10 dark web traders now selling targeted hacking tools and services against Fortune 500 and FTSE 100 businesses.

New research from the University of Surrey, sponsored by Bromium, says that the dark web is home to a variety of bespoke and off-the-shelf tools designed to target the enterprise.

University of Surrey senior lecturer in criminology Dr Mike McGuire and his team talked with cybercriminal vendors across the dark web. They also gathered intelligence and consulted with industry experts to find out how the dark web poses a threat to the enterprise.

The study found that bespoke services most frequently target banking (34%), ecommerce (20%0, healthcare (15%), and education (12%).

“Almost every vendor offered us tailored versions of malware as a way of targeting specific companies or industries,” says McGuire. 

“The more targeted the attack, the higher the cost, with prices rising even further when it involved high-value targets like banks. The most expensive piece of malware found was designed to target ATMs and retailed for approximately US$1,500.”

Researchers also requested hacking tools that targeted high value organisations. Services against Fortune 500 companies and similar can range from $150 to $10,000 – but it depends on the target company and how customised the malware needs to be, explains McGuire.

The study also found:

•    A 20% rise in the number of dark net listings with a direct potential to harm the enterprise since 2016
•    The dark net has become a haven for custom-built, targeted malware, with threats tailored to specific industries or organisations outnumbering off-the-shelf varieties 2:1
•    Access to corporate networks is sold openly – 60% of vendors approached by researchers offered access to more than 10 business networks each
•    70% of dark net vendors engaged invited researchers to talk on encrypted messaging applications, like Telegram, to take conversations beyond the reach of law enforcement

Phishing services remain a popular service on the dark web. McGuide says that corporate invoices can range from $5 to $10 on the dark web.

“These documents can be used to defraud organisations or as part of phishing campaigns to trick employees into opening malicious links or email attachments, which deliver malware that triggers a breach or gives hackers a backdoor into corporate networks which could be sold.”

“Organisations need to strengthen their defenses to protect their endpoints and networks against threats posed by the dark net,” says McGuire. 

“But the dark net can also help them in gathering intelligence and monitoring threats that are out there. Enterprises, researchers, and law enforcement must continue to study the dark net to get a deeper understanding of the adversaries that we are dealing with, and better prepare ourselves for counteracting the effects of a growing cybercrime economy.”

Statistics are taken from Bromium’s Behind the Dark Net Black Mirror study.

Link image
How to prioritise metrics as an e-commerce CTO
E-commerce technology leaders need to track, analyze, and act on large volumes of business and system performance data. Danny Miles, the CTO of Dollar Shave Club, shares a powerful framework for thinking about and prioritizing e-commerce metricsMore
Download image
Why there's a huge push for NFV in today's enterprises
To help networking and IT professionals better understand the opportunities and challenges associated with deploying NFV technology, new research based on responses from more than 1,300 IT and networking professionals from around the world is now available. More
Story image
Three-in-one cloud security can ease business through difficult times
By leveraging a comprehensive security platform, organisations can block threats and prevent leakage for all interaction between endpoints, devices and apps, writes Bitglass product marketing manager Juan Lugo. More
Story image
DDoS attacks surge 542% amidst COVID-19 pandemic - report
Generally considered the “off season” for DDoS attacks, researchers attribute the surge in incidents to malicious efforts during the COVID-19 pandemic.More
Story image
80% of security breaches involve exposure of customer data - IBM
The new report from IBM indicates that 80% of surveyed organisations reported having exposed customers’ personally identifiable information (PII) as a result of a breach.More
Story image
Increased demand for cloud computing as organisations look to achieve business continuity - Aruba
The increase in remote working has also created a focus on cyber security for all businesses.More