January 7, 2016 By Douglas Bonderud 2 min read

Once the domain of outsiders and tech-savvy specialists, hacking has evolved into a diverse market complete with industry verticals, specializations and intense competition that sees groups that aren’t willing to play ball kicked to the curb as more malleable services take their place.

According to Business Insider, in fact, the rise of user-friendly viruses and exploit kits so simple almost anyone could turn to a life of digital ill repute has sparked a kind of customer service war among cybercriminals. Malicious actors face off to offer better support, quicker response times and even money-back guarantees for underhanded activities. It’s official: Things have gotten very, very strange out there.

Card-Carrying Cybercriminals

As noted by Business Insider, one of the first market segments to roll out cybercrime support were the carders — criminals who steal and sell credit card information and the attached personal data. It started around 15 years ago with a major crackdown on carding services, which in turn opened the market for smaller, startup offerings.

To set themselves apart, cybercriminals offered card testing through charity donations along with money-back guarantees if cards didn’t work as advertised. The idea quickly spread to other attack verticals such as ransomware and even marketplaces like AlphaBay.

For example, ransomware creator Jeiphoos — who developed the Encryptor ransomware-as-a-service (RaaS) — inserted a comment and feature request box in his malware package and has since implemented a number of customer suggestions to improve the offering.

AlphaBay, meanwhile, now includes the same kind of seller reviews and vendor ratings users would expect to see on Amazon or eBay. In what can only be described as a kind of bizarro-world mimicry, one AlphaBay patron filed a scam report when the two packages of flour he ordered didn’t contain a Beretta pistol.

Attackers have also taken to offering ongoing support for their products, and some even provide setup services for a small fee, effectively making the moniker of cybercriminal available to anyone willing to surf the Dark Web and spend a little cash.

No Slowdown

Despite increased competition among cybercriminals, however, there’s no ceiling predicted for this market in the near future. Time reported that Hyatt Hotels recently discovered a payment processing virus on its system that could result in millions of customer cards being compromised.

NBC News, meanwhile, has a roundup of cyber predictions for 2016. From hacktivism to increased use of ransomware and the threat of a hackable Internet of Things (IoT), there are plenty of sales vectors left for malicious actors to fill and subsequently support. In short, companies should expect an uptick, not a slowdown, as the cybercriminal market looks to enhance the customer experience.

So what’s the takeaway in this strange new cybercriminal landscape? The mastermind responsible for a corporate network shutdown or retail chain hack may not be a tech wizard or prolific malware-maker but rather a disgruntled employee with a little cash, a smartphone and an ax to grind. In a way, it’s almost sad: Hacking has transitioned from a niche market shrouded in secrecy and mystique to just another e-commerce venture, one replete with scams and poor sellers.

The good news? More exploits, kits and other malware in the hands of tech novices means more data for security experts, while the focus on customer service over quick-and-quiet code exchanges makes supportive cybercriminals easier to catch in the act.

More from

AI decision-making: Where do businesses draw the line?

4 min read - "A computer can never be held accountable, therefore a computer must never make a management decision."- IBM Training Manual, 1979Artificial intelligence (AI) adoption is on the rise. According to the IBM Global AI Adoption Index 2023, 42% of enterprises have actively deployed AI, and 40% are experimenting with the technology. Of those using or exploring AI, 59% have accelerated their investments and rollouts over the past two years. The result is an uptick in AI decision-making that leverages intelligent tools…

When ransomware kills: Attacks on healthcare facilities

4 min read - As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients’ lives are literally on the line.Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during…

AI and cloud vulnerabilities aren’t the only threats facing CISOs today

6 min read - With cloud infrastructure and, more recently, artificial intelligence (AI) systems becoming prime targets for attackers, security leaders are laser-focused on defending these high-profile areas. They’re right to do so, too, as cyber criminals turn to new and emerging technologies to launch and scale ever more sophisticated attacks.However, this heightened attention to emerging threats makes it easy to overlook traditional attack vectors, such as human-driven social engineering and vulnerabilities in physical security.As adversaries exploit an ever-wider range of potential entry points…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today