The Hacker’s Bounty: How much do cybercriminals make from innocent users?
Cybercriminals could be raking in profits 20 times greater than the cost of their attacks, according to figures compiled by Kaspersky Lab experts. The research compared the cost of the most frequently used hacker tools with the money stolen in a successful malicious operation.
"Buying malware is currently not a problem, it’s easy to find them on various hacker forums, and they are relatively cheap, making them attractive. A cybercriminal following this illegal path doesn’t even need any skills – for a fixed price they can get an off-the-peg package to launch their attacks at will,” said Alexander Gostev, Chief Security Expert at Kaspersky Lab.
“As a result, users need to be especially careful to ensure they don’t lose their money or data. They should also protect their devices and all online operations performed on them, using a specialized solution such as Kaspersky Internet Security - multi-device,” Gostev added.
For example, creating a phishing page to mimic a popular social network and setting up a spam mass mailing linking to the fake site currently costs an average of $150 (P6,685.50).
However, if the users catch 100 people they can net up to $10,000 (P445,700) by selling sensitive data. The victims, in turn, lose their valuable contacts, personal photos and messages.
A mobile Trojan blocker is much more expensive. Today it costs $1,000 (P44,570) on average to buy and distribute the malware.
However, the "payoff" is also much higher. The prices that the attackers set for unblocking a smartphone vary from $10 to $200 (P445.70 to P8,914) which means that from 100 potential victims they can get up to $20,000 (P891,400).
The same sum can be earned by using encrypting ransomware but the "initial investment" will be twice as high, which is about $2,000 (P89,140).
The users’ losses will be also higher because the minimum sum of the ransom requested by the fraudsters for decrypting the data is usually $100 (P4,457).
To really hit the jackpot, fraudsters look for banking Trojans that target money directly. After spending about $3,000 (P133,710) on the malware, the exploit and a spam mailing to spread them around, cybercriminals could scoop up to $72,000 (P3,209,040). The average loss of an individual victim is $722 (P32,179.54).
*Based on current forex rate: 1$ = P44.57