Why cybercrime will always need humans

Kaspersky finds robots won't ever replace hackers completely

Forget automation, cybercrime still needs a human touch. 

With robotics and automation taking over researchers believe as many as five million jobs could disappear by 2020 it may seem as though high-tech jobs risk losing the personal touch. 

Consider the Metel cybercrime gang, revealed yesterday at Kaspersky's Security Analyst Summit, currently taking place in Tenerife.

Advertisement - Article continues below

The banking fraud group targets spear-phishing emails at employees of financial firms, in order to get access to payment processing computers. But rather than simply transfer funds to digital accounts, Metel sends its colleagues in crime to bank machines in person, where they take money out using a specific card.

Then, hackers who are watching for the card number to pop up on the payment processing computer click to cancel the transaction they actually sit there, clicking like mad, said researcher Sergey Golovanov, a Kaspersky researcher.

That highlights one problem with cybercrime that automation cannot seem to help with - laundering the cash. Indeed, another infamous hack shows how one group of cybercriminals also turned to human labour to attempt to solve that problem.

The hackers behind the Shylock attacks which spread via Skype needed help laundering the cash they had stolen, so they advertised for help online, said Adrian Nish, head of cyber intelligence systems at BAE, also speaking at the Kaspersky show. 

Advertisement - Article continues below
Advertisement - Article continues below

Nish showed a screenshot of a job ad for an "e-commerce representative". The requirements were odd: applicants would need internet access, no criminal record, and a verified PayPal account. 

"What they're doing is recruiting people who may think they're working from home, doing a job transferring money for legitimate businesses, but actually it's money laundering," Nish said. 

The money mules even get training though it's not "advanced stuff", said Nish. "It's questions like, if the bank asks who sent you this money, who knows to answer yes'." 

"Effectively these guys were running a human botnet of people that employed through work from home type jobs to actually do the cash out," Nish said. 

Longer term, is the future of cybercrime more or less human? 

Andrey Nikishin, future technologies projects director at Kaspersky, said getting money will always be the weakest link and will always require a person, even if cybercrime does become increasingly automated.

"The only way to do it is with money mules. All of the rest could be automated like criminals as a service," Nikishin told IT Pro on the sidelines of the conference. "But the last and most dangerous to be caught is the money mule."

Featured Resources

The case for a marketing content hub

Transform your digital marketing to deliver customer expectations

Download now

Fast, flexible and compliant e-signatures for global businesses

Be at the forefront of digital transformation with electronic signatures

Download now

Why CEOS should care about the move to SAP S/4HANA

And how they can accelerate business value

Download now

IT faces new security challenges in the wake of COVID-19

Beat the crisis by learning how to secure your network

Download now


mobile security

Parachute's Superlock feature keeps your phone recording in an emergency

2 Jun 2020

K2View innovates in data management with new encryption patent

28 May 2020
cyber security

Governments urged to work together to stop health care cyber attacks

26 May 2020
video conferencing

Zoom 5.0 adds 256-bit encryption to address security concerns

23 Apr 2020

Most Popular


Apple confirms serious bugs in iOS 13.5

4 Jun 2020

The UK looks to Japan and South Korea for 5G equipment

4 Jun 2020

Tycoon ransomware discovered using Java image files to target software firms

5 Jun 2020