In many ways, the COVID-19 pandemic has been a boon to cybercriminals: With unprecedented numbers of people working from home and anxious for news about the virus outbreak, its hard to imagine a more target-rich environment for phishers, scammers and malware purveyors. In addition, many crooks are finding the outbreak has helped them better market their cybercriminal wares and services. But its not all good news: The Coronavirus also has driven up costs and disrupted key supply lines for many cybercriminals. Heres a look at how theyre adjusting to these new realities.
One of the more common and perennial cybercriminal schemes is reshipping fraud, wherein crooks buy pricey consumer goods online using stolen credit card data and then enlist others to help them collect or resell the merchandise.
Most online retailers years ago stopped shipping to regions of the world most frequently associated with credit card fraud, including Eastern Europe, North Africa, and Russia. These restrictions have created a burgeoning underground market for reshipping scams, which rely on willing or unwitting residents in the United States and Europe derisively referred to as reshipping mules to receive and relay high-dollar stolen goods to crooks living in the embargoed areas.
A screen shot from a user account at Snowden, a long-running reshipping mule service.
But apparently a number of criminal reshipping services are reporting difficulties due to the increased wait time when calling FedEx or UPS (to divert carded goods that merchants end up shipping to the cardholders address instead of to the mules). In response, these operations are raising their prices and warning of longer shipping times, which in turn could hamper the activities of other actors who depend on those services.
Thats according to Intel 471, a cyber intelligence company that closely monitors hundreds of online crime forums. In a report published today, the company said since late March 2020 it has observed several crooks complaining about COVID-19 interfering with the daily activities of their various money mules(people hired to help launder the proceeds of cybercrime).
One Russian-speaking actor running a fraud network complained about their subordinates (money mules) in Italy, Spain and other countries being unable to withdraw funds, since they currently were afraid to leave their homes, Intel 471 observed. Also some actors have reported that banks customer-support lines are being overloaded, making it difficult for fraudsters to call them for social-engineering activities (such as changing account ownership, raising withdrawal limits, etc).
Still, every dark cloud has a silver lining: Intel 471 noted many cybercriminals appear optimistic that the impending global economic recession (and resultant unemployment) will make it easier to recruit low-level accomplices such as money mules.
Alex Holden, founder and CTO of Hold Security, agreed. He said while the Coronavirus has forced reshipping operators to make painful shifts in several parts of their business, the overall market for available mules has never looked brighter.
Reshipping is way up right now, but there are some complications, he said.
For example, reshipping scams have over the years become easier for both reshipping mule operators and the mules themselves. Many reshipping mules are understandably concerned about receiving stolen goods at their home and risking a visit from the local police. But increasingly, mules have been instructed to retrieve carded items from third-party locations.
The mules dont have to receive stolen goods directly at home anymore, Holden said. They can pick them up at Walgreens, Hotel lobbies, etc. There are a ton of reshipment tricks out there.
But many of those tricks got broken with the emergence of COVID-19 and social distancing norms. In response, more mule recruiters are asking their hires to do things like reselling goods shipped to their homes on platforms like eBay and Amazon.
Reshipping definitely has become more complicated, Holden said. Not every mule will run 10 times a day to the post office, and some will let the goods sit by the mailbox for days. But on the whole, mules are more compliant these days.
KrebsOnSecurity recently came to a similar conclusion: Last months story, Coronavirus Widens the Money Mule Pool, looked at one money mule operation that had ensnared dozens of mules with phony job offers in a very short period of time. Incidentally, the fake charity behind that scheme which promised to raise money for Coronavirus victims has since closed up shop and apparently re-branded itself as the Tessaris Foundation.
Charitable cybercriminal endeavors were the subject of a report released this weekby cyber intel firm Digital Shadows, which looked at various ways computer crooks are promoting themselves and their hacking services using COVID-19 themed discounts and giveaways.
Like many commercials on television these days, such offers obliquely or directly reference the economic hardships wrought by the virus outbreak as a way of connecting on an emotional level with potential customers.
The illusion of philanthropy recedes further when you consider the benefits to the threat actors giving away goods and services, the report notes. These donors receive a massive boost to their reputation on the forum. In the future, they may be perceived as individuals willing to contribute to forum life, and the giveaways help establish a track record of credibility.
Brians Club one of the undergrounds largest bazaars for selling stolen credit card data and one that has misappropriated this authors likeness and name in its advertising recently began offering pandemic support in the form of discounts for its most loyal customers.
It stands to reason that the virus outbreak might depress cybercriminal demand for dumps, or stolen account data that can be used to create physical counterfeit credit cards. After all, dumps are mainly used to buy high-priced items from electronics stores and other outlets that may not even be open now thanks to the widespread closures from the pandemic.
If that were the case, wed also expect to see dumps prices fall significantly across the cybercrime economy. But so far, those price changes simply havent materialized, says Gemini Advisory, a New York based company that monitors the sale of stolen credit card data across dozens of stores in the cybercrime underground.
Stas Alforov, Geminis director of research and development, said theres been no notable dramatic changes in pricing for both dumps and card data stolen from online merchants (a.k.a. CVVs) even though many cybercrime groups appear to be massively shifting their operations toward targeting online merchants and their customers.
Usually, the huge spikes upward or downward during a short period is reflectedby a large addition of cheap records that drive the median price change, Alforov said, referring to the small and temporary price deviations depicted in the graph above.
Intel 471 said it came to a similar conclusion.
You might have thought carding activity, to include support aspects such as checker services, would decrease due to both the global lockdown and threat actors being infected with COVID-19, the company said. Weve even seen some actors suggest as much across some shops, but the reality is there have been no observations of major changes.
Interestingly, the Coronavirus appears to have prompted discussion on a topic that seldom comes up in cybercrime communities i.e., the moral and ethical ramifications of their work. Specifically, there seems to be much talk these days about the potential karmic consequences of cashing in on the misery wrought by a global pandemic.
For example, Digital Shadows said some have started to question the morality of targeting healthcare providers, or collecting funds in the name of Coronavirus causes and then pocketing the money.
One post on the gated Russian-language cybercriminal forum Korovka laid bare the question of threat actors moral obligation, the company wrote. A user initiated a thread to canvass opinion on the feasibility of faking a charitable cause and collecting donations. They added that while they recognized that such a plan was cruel, they found themselves in an extremely difficult financial situation. Responses to the proposal were mixed, with one forum user calling the plan amoral, and another pointing out that cybercrime is inherently an immoral affair.
Tags: alex holden, Coronavirus, COVID-19, Gemini Advisory, Intel 471, money mules, reshipping mules, Snowden, Stas Alforov
This entry was posted on Thursday, April 30th, 2020 at 2:20 pmand is filed under Ne'er-Do-Well News, Other, Web Fraud 2.0.You can follow any comments to this entry through the RSS 2.0 feed.You can skip to the end and leave a comment. Pinging is currently not allowed.
Continued here:
How Cybercriminals are Weathering COVID-19 - Krebs on Security
- Coronavirus Scam Alert: Watch Out For These Risky COVID-19 Websites And Emails - Forbes [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- COVID19: Broome County Executive expected to sign executive orders on virus - WBNG-TV [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Houston-based company ready to test COVID-19 'vaccine candidate,' but doesn't have the funds - KHOU.com [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- COVID19 Mesa County Public Health [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Coronavirus Disease 2019 (COVID-19) | SCDHEC [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Coronavirus disease 2019 - Wikipedia [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Hackers are jumping on the COVID-19 pandemic to spread malware - TechCrunch [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- COVID-19 can last a few days on surfaces, according to new experiment findings - ABC News [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- The Guardian view on the UKs Covid-19 response: confused and hesitant - The Guardian [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- The COVID-19 Coronavirus Pandemic Highlights The Importance Of Scientific Expertise - Forbes [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- WHO Expert: Aggressive Action Against Coronavirus Cuts Down On Spread : Goats and Soda - NPR [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- 2 new cases of COVID-19 at Chicago schools - WGN TV Chicago [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Will Gargling with Salt Water or Vinegar 'Eliminate' the COVID-19 Coronavirus? - Snopes.com [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Worried about dying from COVID-19? You might be a millennial | TheHill - The Hill [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Startups developing tech to combat COVID-19 urged to apply for fast-track EU funding - TechCrunch [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Why do dozens of diseases wax and wane with the seasonsand will COVID-19? - Science Magazine [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- WHO, UN Foundation and partners launch first-of-its-kind COVID-19 Solidarity Response Fund - World Health Organization [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Covid-19: PM to address nation tonight - New Straits Times [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- COVID-19: Where every sport lies after mass disruption - RTE.ie [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- COVID-19: Facts, myths and hypotheses | TheHill - The Hill [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Hong Kong Has Largely Survived COVID-19. Can New York and The US Do It Too? - BuzzFeed News [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- UPDATE: Case of COVID-19 confirmed in Wilson County - WITN [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Is This Train Car Carrying 'COVID-19'? - Snopes.com [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Coronavirus pandemic: facts, updates and what to do about COVID-19 - The Verge [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- DHS: 34 people test positive for COVID-19 in Wisconsin - WBAY [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- COVID-19 by the numbers; plus key resources to help you stay informed - Berkeleyside [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- The Covid-19 puzzles that scientists are still trying to answer - The Guardian [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- What's the COVID-19 end game? - The San Diego Union-Tribune [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- The Covid-19 coronavirus is not the flu. Its worse. - Vox.com [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Phones Could Track the Spread of Covid-19. Is It a Good Idea? - WIRED [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- NIH Reports First Known Employee with COVID-19 Infection - National Institutes of Health [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Newborn tests positive for COVID-19 in London - Livescience.com [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Covid-19: Malaysia's pandemic action plan activated for the coronavirus - The Star Online [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- How Bad Will The COVID-19 Coronavirus Epidemic Get In The U.S.? Health Experts Weigh In - Forbes [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Can People Who Recover from COVID-19 Become Reinfected? - Snopes.com [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- THE LATEST: 41 test positive for COVID-19 in the state - WFSB [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Twelve new cases of COVID-19 announced in Illinois; bringing total to 105 - KWQC-TV6 [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Eagle County outlines shift for COVID-19 testing, Vail Health shifts operations - Vail Daily News [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- 7th positive COVID-19 case announced in Hawaii, all cases related to travel - KHON2 [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Canada tightens borders over coronavirus will it curb COVID-19s spread? - Global News [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- As health care workers prepare for COVID-19, medical students pitch in on the homefront - Minnesota Public Radio News [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Coronavirus First positive case of COVID-19 confirmed in Geauga County Kaylyn Hlavaty 7:58 AM - News 5 Cleveland [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- 2nd presumptive case of COVID 19 reported in Bell County - KWTX [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- New confirmed cases of COVID-19 in Wisconsin - WKOW [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Hawaii National Guard ready to step in against spread of COVID-19 - KHON2 [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Alberta orders all classes cancelled, daycares closed as COVID-19 cases rise to 56 in the province - Global News [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Has Italy Stopped Treating the Elderly in the COVID-19 Pandemic? - Snopes.com [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Coronavirus testing: Information on COVID-19 tests according to state health departments - NBCNews.com [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Working from home because of COVID-19? Here are 10 ways to spend your time - Science Magazine [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Two positive COVID-19 cases announced in Fairbanks, bringing Alaska's confirmed total to 3 - Anchorage Daily News [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- 8 more positive cases of COVID-19 brings Michigan total to 33 - FOX 2 Detroit [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- COVID-19: Who Is Infectious? - Forbes [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- The Guardian view on the latest Covid-19 steps: a recipe for isolation - The Guardian [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Government publishes updated COVID-19 industry guidance - GOV.UK [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- NIH clinical trial of investigational vaccine for COVID-19 begins - National Institutes of Health [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Expanding Colorado's COVID-19 Testing Capacity Proves Frustrating to Polis, Doctors And The Public - Colorado Public Radio [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Microsoft Bing launches interactive COVID-19 map to provide pandemic news - The Verge [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Coronavirus tips: How to slow the spread of COVID-19 with hand-washing, social distance - USA TODAY [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- See Which Countries are Flattening their COVID-19 Curve - Visual Capitalist [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- With launch of COVID-19 data hub, the White House issues a call to action for AI researchers - TechCrunch [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- COVID-19 - Cabinet for Health and Family Services [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Coronavirus Disease 2019 (COVID-19) | AustinTexas.gov [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- First COVID-19 case in Waterbury is confirmed - Waterbury Republican American [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Covid-19 reveals the alarming truth that many children cant wash their hands at school - The Guardian [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Statement on COVID-19 Panel Discussion Notes That Were Attributed to UCSF - UCSF News Services [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Covid-19 coronavirus testing in the US has been absurdly sluggish. That puts us at risk. - Vox.com [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Regal is closing all theaters until further notice over COVID-19 fears - TechCrunch [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Amazon limiting shipments to certain types of products due to COVID-19 pandemic - TechCrunch [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Coralville company to produce millions of kits to test for COVID-19 - KCRG [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Number of COVID-19 cases in Erie County rises to 11, new case confirmed in Wyoming County - WIVB.com - News 4 [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Coronavirus tips and symptoms: What everyone should know about getting the new coronavirus - Vox.com [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Tech giants are getting creative to manage the COVID-19 crisis - The Verge [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- COVID-19: Mental health in the age of coronavirus - UN News [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- White House provides an update on COVID-19 testing in the U.S., says theres been a dramatic ramp - TechCrunch [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Covid-19: How long does the coronavirus last on surfaces? - BBC News [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Hospital in Boston will be converted into Covid-19 treatment center - STAT [Last Updated On: March 18th, 2020] [Originally Added On: March 18th, 2020]
- 78 cases of COVID-19 confirmed in Tennessee - NewsChannel5.com [Last Updated On: March 18th, 2020] [Originally Added On: March 18th, 2020]
- COVID 19: Tennessee confirmed cases reaches 52, Dept of Health releases age ranges of those infected - Clarksville Now [Last Updated On: March 18th, 2020] [Originally Added On: March 18th, 2020]
- Housing associations under pressure to offer Covid-19 rent holidays - The Guardian [Last Updated On: March 18th, 2020] [Originally Added On: March 18th, 2020]
- Sacramento woman dead from COVID-19 attended church with others who have virus - KCRA Sacramento [Last Updated On: March 18th, 2020] [Originally Added On: March 18th, 2020]