Cybercriminal Business Model in Latin America Coders develop malware Web designers create phishing pages Advertisers promote products on forums and IRC channels Carders buy either the malware or “phishing kit” Third parties receive payments for products sold Carders spread malware or links to phishing sites via spam Affected users’ personal credentials are stolen Mules get part of the payment while the rest goes to carders; mules can get products in exchange for receiving payments, too Mules receive payment for stolen data Buyers avail of their choice of data Carders sell stolen user data on forums, IRC channels, and social networking sites Source: Trend Micro PiceBOT Cybercriminals in OAS Member States are increasingly succeeding in custom designing and building their own crimeware kits. In December 2012, PiceBOT, a new crimeware kit that costs US$140, was introduced in Latin America. The malware associated with PiceBOT steals financial information from unsuspecting users and was developed in the region. PiceBOT has heralded a new era of sophistication in cyberthreats in the Americas and the Caribbean. More and more, malware will be homegrown and used against governments, the private sector, and citizens. The increased prevalence of crimeware kits that employ new malicious codes means that more than ever, security systems need to remain updated, administrators need to identify and patch vulnerabilities, and in general increased efforts need to be made to maintain parity with cybercriminals. PAGE 16 | Latin American and Caribbean Cybersecurity Trends and Government Responses

Select target paragraph3