Why cybercrime will always need humans

Kaspersky finds robots won't ever replace hackers completely

Forget automation, cybercrime still needs a human touch. 

With robotics and automation taking over researchers believe as many as five million jobs could disappear by 2020 it may seem as though high-tech jobs risk losing the personal touch. 

Consider the Metel cybercrime gang, revealed yesterday at Kaspersky's Security Analyst Summit, currently taking place in Tenerife.

The banking fraud group targets spear-phishing emails at employees of financial firms, in order to get access to payment processing computers. But rather than simply transfer funds to digital accounts, Metel sends its colleagues in crime to bank machines in person, where they take money out using a specific card.

Advertisement - Article continues below

Then, hackers who are watching for the card number to pop up on the payment processing computer click to cancel the transaction they actually sit there, clicking like mad, said researcher Sergey Golovanov, a Kaspersky researcher.

That highlights one problem with cybercrime that automation cannot seem to help with - laundering the cash. Indeed, another infamous hack shows how one group of cybercriminals also turned to human labour to attempt to solve that problem.

The hackers behind the Shylock attacks which spread via Skype needed help laundering the cash they had stolen, so they advertised for help online, said Adrian Nish, head of cyber intelligence systems at BAE, also speaking at the Kaspersky show. 

Nish showed a screenshot of a job ad for an "e-commerce representative". The requirements were odd: applicants would need internet access, no criminal record, and a verified PayPal account. 

"What they're doing is recruiting people who may think they're working from home, doing a job transferring money for legitimate businesses, but actually it's money laundering," Nish said. 

The money mules even get training though it's not "advanced stuff", said Nish. "It's questions like, if the bank asks who sent you this money, who knows to answer yes'." 

"Effectively these guys were running a human botnet of people that employed through work from home type jobs to actually do the cash out," Nish said. 

Longer term, is the future of cybercrime more or less human? 

Andrey Nikishin, future technologies projects director at Kaspersky, said getting money will always be the weakest link and will always require a person, even if cybercrime does become increasingly automated.

"The only way to do it is with money mules. All of the rest could be automated like criminals as a service," Nikishin told IT Pro on the sidelines of the conference. "But the last and most dangerous to be caught is the money mule."

Featured Resources

Application security fallacies and realities

Web application attacks are the most common vulnerability, so what is the truth about application security?

Download now

Your first step researching Managed File Transfer

Advice and expertise on researching the right MFT solution for your business

Download now

The KPIs you should be measuring

How MSPs can measure performance and evaluate their relationships with clients

Download now

Life in the digital workspace

A guide to technology and the changing concept of workspace

Download now



Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

mergers and acquisitions

Xerox threatens hostile takeover after HP rebuffs $30bn takeover

22 Nov 2019

Microsoft issues statement debunking Teams ransomware rumours

21 Nov 2019

Salesforce takes AWS relationship to the next level

19 Nov 2019

Tests show UK's 5G network is 450% faster than 4G

20 Nov 2019