Commentary

Alexander Wolfe
 

Trend Micro Rips Lid Off Estonian Cybercrime Hub

An important Trend Micro paper, spotlighting a cybercriminal hub operating out of Estonia, has surfaced on Slashdot. The racket here is that a seemingly legitimate Internet Service Provider is in reality the headquarters for a rogue network, which extends into Europe and the United States. The breadth of the deception outlined in the paper is scary; doubly so because cybercrime is emerging as the single biggest security threat of the next decade.

An important Trend Micro paper, spotlighting a cybercriminal hub operating out of Estonia, has surfaced on Slashdot. The racket here is that a seemingly legitimate Internet Service Provider is in reality the headquarters for a rogue network, which extends into Europe and the United States. The breadth of the deception outlined in the paper is scary; doubly so because cybercrime is emerging as the single biggest security threat of the next decade.The paper, by Trend Micro threat analysts Ben April, Feike Hacquebord, and Rainer Link, is entitled "A Cybercrime Hub." It can be downloaded as a pdf here.

Hacquebord introduces the masquerading Estonian ISP in a Trend Micro blog post. The illicit network has been in operation since 2005. "Employees administer sites that host codec Trojans and command and control servers that steer armies of infected computers," he writes.


More Global CIO Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

A bunch of daughter companies in cahoots with the illegitimate ISP were taken offline in 2008. However, the operation recovered from that blow, and today, Hacquebord writes "we count about 20 different webhosting providers where the criminal Estonian outfit has its presence. Besides this, the company own two networks in the United States."

There's more, and it's all scary stuff, so I urge you to read the Trend Micro paper (Again, it's available as a pdf here.)

In closing, I'd like to point you to my recent ByteandSwitch blog post, Cybersecurity Challenge: Is Your Network Safe? (Probably Not). In the post, I talk about cybercrime alarms being raised in regard to U.S. government IT systems.

It's my sense that, while there are certainly lapses in government systems -- many of which stem from the way such systems are acquired and upgraded -- government and military personnel seem more sensitized to the whole issue of cybercriminal gangs operating out of places like Russia and China than do people in the business world. Perhaps it makes sense that they're on heightened alert, because they're a first-level target.

Yet that doesn't mean commercial networks and systems aren't vulnerable. They are almost equally at risk, and we all know there are many, many breaches we don't hear about. (Paging the big banks.)

As I wrote on ByteandSwitch :

"This time around, I don't think the alarmists are crying wolf. The threat from organized cybercriminals is real. Also, the protection lapses of government networks are probably duplicated by most commercial setups."

Follow me on Twitter: (@awolfe58)

What's your take? Let me know, by leaving a comment below or e-mailing me directly at alex@alexwolfe.net. Like this blog? Subscribe to its RSS feed: (here)

 My videos on ( YouTube)

 Facebook 

  LinkedIn

Alex Wolfe is editor-in-chief of InformationWeek.com.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links