Cybercriminal Business Model in Latin America
Coders develop
malware
Web designers
create phishing
pages
Advertisers
promote products
on forums and
IRC channels
Carders buy
either the
malware or
“phishing kit”
Third parties
receive payments
for products sold
Carders spread malware
or links to phishing sites via
spam
Affected users’ personal
credentials are stolen
Mules get part of the
payment while the rest
goes to carders; mules
can get products in
exchange for receiving
payments, too
Mules receive
payment for
stolen data
Buyers avail of
their choice of
data
Carders sell
stolen user data
on forums, IRC
channels, and
social networking
sites
Source: Trend Micro
PiceBOT
Cybercriminals in OAS Member States are increasingly succeeding in custom
designing and building their own crimeware kits. In December 2012, PiceBOT,
a new crimeware kit that costs US$140, was introduced in Latin America.
The malware associated with PiceBOT steals financial information from
unsuspecting users and was developed in the region. PiceBOT has heralded
a new era of sophistication in cyberthreats in the Americas and the Caribbean.
More and more, malware will be homegrown and used against governments,
the private sector, and citizens. The increased prevalence of crimeware kits that
employ new malicious codes means that more than ever, security systems need
to remain updated, administrators need to identify and patch vulnerabilities,
and in general increased efforts need to be made to maintain parity with
cybercriminals.
PAGE 16 | Latin American and Caribbean Cybersecurity Trends and Government Responses