Cybercriminal Underground Large botnet takedowns worldwide in the last few years, including that of Esthost in 2011, have forced cybercriminals to alter their tactics. They now endeavor to configure their own servers in data centers worldwide instead of using hijacked servers to host their command-and-control (C&C) infrastructures, spam tools, and other operational components. They avoid registering host names or domains for their servers and only use Internet Protocol (IP) addresses to avoid being indexed by search engines like Google. In contrast to the preference for paid and proxy servers manifested by criminals in Eastern Europe, those in Latin America prefer using free hosting services.8 Malware, C&C servers, phishing pages, and other malicious content used by the cybercriminals in Latin America are often hosted on Dot TK or other free webhosting sites based in Eastern Europe. Cybercriminals take advantage of free trial services to register malicious domains and steal user information. Doing so allows access that lasts for a week at the longest, but may also be beneficial in obscuring evidence and covering up one’s digital footprint. Crimeware kits and the data they steal are commonly traded and shared on social networking sites. Orkut, more than Facebook, is the leading marketplace in Latin America. Orkut posts offering various cybercrime wares are a common sight in Latin America. 8 http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp-russianunderground-101.pdf PAGE 14 | Latin American and Caribbean Cybersecurity Trends and Government Responses

Select target paragraph3