From Ransomware Development to Performance Reviews: A Day in the Life of a Cybercriminal

Trend Micro report shows how criminal organisations come to resemble legitimate businesses as they grow 

Trend Micro Incorporated, a global cybersecurity leader,  published a new research uncovering the inner workings of cybercrime organisations. The report, Inside the Halls of a Cybercrime Business, examined the operations of small, medium, and large criminal groups. The report details a day in the lives of employees and how they operate within hierarchies that increasingly resemble legitimate businesses as the group expands. 

 

While small cybercrime groups typically consist of a few members operating under a partnership model — most of whom usually have day jobs on top of their role in the group — employees of larger organisations tend to lead lives similar to corporate workers at legitimate software companies. Large cybercrime organisations tend to have corporate-like departments such as human resources (HR) and information technology (IT), and might even have “employee-of-the-month” recognition programmes and performance reviews.

 

trend micro
From Ransomware Development to Performance Reviews: A Day in the Life of a Cybercriminal

 

Ian Felipe, Country Manager, Trend Micro Philippines shares, “The criminal underground is rapidly professionalising — groups are beginning to mimic legitimate businesses that grow in complexity as their membership and revenue increases. At the same time, many Filipino businesses are grappling with high cyber risk levels and a challenging threat landscape. In a recent survey we conducted, nearly 40% of Filipino IT leaders rated their organisation’s cyber risk levels as at the very least high, and nearly half of businesses believe that it is impossible to futureproof their cybersecurity as threats are always changing. To that extent, understanding cybercriminal operations can go a long way in helping to stay ahead of threats and enhance cyber preparedness. This report will aid investigators in the ongoing fight against cybercrime by helping them better understand the entities they are dealing with.”

 

Using examples where Trend Micro collected the most data from law enforcement and insider information, the report examined three types of cybercrime organisations based on size. 

 

Small criminal businesses (e.g., Counter Anti-Virus service Scan4You):

  • A day in the life of an employee: Members often handle multiple tasks within the group and also have a day job on top of this work
  • Typically, one management layer, 1-5 staff members, and under US$500K in annual turnover
  • Comprise the majority of criminal businesses, often partnering with other criminal entities

 

Medium-sized criminal businesses (e.g., bulletproof hoster MaxDedi):

  • A day in the life of an employee: Members work full-time for the group, managing various tasks within an eight-hour shift 
  • Typically have two management layers, 6-49 employees, and up to US$50m in annual turnover
  • They usually have a pyramid-style hierarchical structure with a single person in charge

 

Large criminal business (e.g., ransomware group Conti): 

  • A day in the life of an employee: Members work from home based on a rigid, predictable schedule, and communicate frequently with their line manager about productivity and performance — similar to remote workers at legitimate corporations
  • Typically have three management layers, 50+ staff, and over US$50m in annual turnover
  • Implement effective OPSEC and partner with other criminal organisations
  • Those in charge are seasoned cybercriminals and hire multiple developers, administrators, and penetration testers – including short-term contractors
  • They may have corporate-like departments (e.g., IT, HR) and even run employee programs, such as performance reviews

 

Knowing the size and complexity of a criminal organisation can provide critical clues to investigators, such as what types of data to hunt for. Understanding the size of targeted criminal organisations can also allow law enforcers to prioritise better which groups should be pursued for maximum impact.

 

To read a full copy of the report, please visit: https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/inside-the-halls-of-a-cybercrime-business

 

Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information. Fuelled by decades of security expertise, global threat research, and continuous innovation, Trend Micro’s cybersecurity platform protects hundreds of thousands of organisations and millions of individuals across clouds, networks, devices, and endpoints. As a leader in cloud and enterprise cybersecurity, the platform delivers a powerful range of advanced threat defence techniques optimised for environments like AWS, Microsoft, and Google, and central visibility for better, faster detection and response. With 7,000 employees across 65 countries, Trend Micro enables organisations to simplify and secure their connected world. www.TrendMicro.com.  

 

Eli

Eli has 28 years of extensive IT sales expertise in Data, voice and network security and integrating them is his masterpiece. Photography and writing is his passion. Growing up as a kid, his father taught him to use the steel bodied Pentax and Hanimex 135mm film and single-direction flash, Polaroid cameras, and before going digital, he used mini DV tape with his Canon videocam. He now shoots with his Canon EOS 30D. Photography and blogging is a powerful mixture for him.

Leave a Reply

Your email address will not be published.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Back to top button