Cybercriminal Underground
Large botnet takedowns worldwide in the last few years, including that of
Esthost in 2011, have forced cybercriminals to alter their tactics. They now
endeavor to configure their own servers in data centers worldwide instead of
using hijacked servers to host their command-and-control (C&C) infrastructures,
spam tools, and other operational components. They avoid registering
host names or domains for their servers and only use Internet Protocol (IP)
addresses to avoid being indexed by search engines like Google.
In contrast to the preference for paid and proxy servers manifested by criminals
in Eastern Europe, those in Latin America prefer using free hosting services.8
Malware, C&C servers, phishing pages, and other malicious content used by the
cybercriminals in Latin America are often hosted on Dot TK or other free webhosting sites based in Eastern Europe. Cybercriminals take advantage of free
trial services to register malicious domains and steal user information. Doing so
allows access that lasts for a week at the longest, but may also be beneficial in
obscuring evidence and covering up one’s digital footprint. Crimeware kits and
the data they steal are commonly traded and shared on social networking sites.
Orkut, more than Facebook, is the leading marketplace in Latin America.
Orkut posts offering various cybercrime wares are a common sight in Latin America.
8
http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp-russianunderground-101.pdf
PAGE 14 | Latin American and Caribbean Cybersecurity Trends and Government Responses