Why cybercrime will always need humans

Kaspersky finds robots won't ever replace hackers completely

Hand casting a shadow over a keyboard

Forget automation, cybercrime still needs a human touch. 

With robotics and automation taking over researchers believe as many as five million jobs could disappear by 2020 it may seem as though high-tech jobs risk losing the personal touch. 

Consider the Metel cybercrime gang, revealed yesterday at Kaspersky's Security Analyst Summit, currently taking place in Tenerife.

The banking fraud group targets spear-phishing emails at employees of financial firms, in order to get access to payment processing computers. But rather than simply transfer funds to digital accounts, Metel sends its colleagues in crime to bank machines in person, where they take money out using a specific card.

Then, hackers who are watching for the card number to pop up on the payment processing computer click to cancel the transaction they actually sit there, clicking like mad, said researcher Sergey Golovanov, a Kaspersky researcher.

That highlights one problem with cybercrime that automation cannot seem to help with - laundering the cash. Indeed, another infamous hack shows how one group of cybercriminals also turned to human labour to attempt to solve that problem.

The hackers behind the Shylock attacks which spread via Skype needed help laundering the cash they had stolen, so they advertised for help online, said Adrian Nish, head of cyber intelligence systems at BAE, also speaking at the Kaspersky show. 

Nish showed a screenshot of a job ad for an "e-commerce representative". The requirements were odd: applicants would need internet access, no criminal record, and a verified PayPal account. 

"What they're doing is recruiting people who may think they're working from home, doing a job transferring money for legitimate businesses, but actually it's money laundering," Nish said. 

The money mules even get training though it's not "advanced stuff", said Nish. "It's questions like, if the bank asks who sent you this money, who knows to answer yes'." 

"Effectively these guys were running a human botnet of people that employed through work from home type jobs to actually do the cash out," Nish said. 

Longer term, is the future of cybercrime more or less human? 

Andrey Nikishin, future technologies projects director at Kaspersky, said getting money will always be the weakest link and will always require a person, even if cybercrime does become increasingly automated.

"The only way to do it is with money mules. All of the rest could be automated like criminals as a service," Nikishin told IT Pro on the sidelines of the conference. "But the last and most dangerous to be caught is the money mule."

Featured Resources

Modern governance: The how-to guide

Equipping organisations with the right tools for business resilience

Free Download

Cloud operational excellence

Everything you need to know about optimising your cloud operations

Watch now

A buyer’s guide to board management software

How the right software can improve your board’s performance

The real world business value of Oracle autonomous data warehouse

Lead with a 417% five-year ROI

Download now

Recommended

TikTok phishing campaign tried to scam over 125 influencer accounts
social media

TikTok phishing campaign tried to scam over 125 influencer accounts

18 Nov 2021
Smart luggage is not so smart when it comes to cyber security
cyber security

Smart luggage is not so smart when it comes to cyber security

15 Nov 2021
Europol reveals how ransomware gangs are evolving to evade capture
cyber crime

Europol reveals how ransomware gangs are evolving to evade capture

12 Nov 2021
The Okta digital trust index
Whitepaper

The Okta digital trust index

11 Nov 2021

Most Popular

How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

6 Jan 2022
How to speed up Windows 11
Microsoft Windows

How to speed up Windows 11

7 Jan 2022
Solving cyber security's diversity problem
Careers & training

Solving cyber security's diversity problem

5 Jan 2022