Russian IT “Brain Drain” Decentralizes Cybercrime

According to Recorded Future, Russia’s invasion of Ukraine has disrupted the vast cybercrime underground operating in the country, thanks to the mobilization of some threat actors and the migration of others.

A new report from the threat intelligence firm, Russia’s War on Ukraine Disrupts Cybercrime Ecosystemcompiled from an analysis of dark web sources.

Mobilization and migration of cybercriminals prevented cybersecurity vendors from fully recovering the volume of compromised cards to 2021 levels, with activity on the Russian-language dark web and special-access forums declining last year. claimed to have

“Anecdotally, since September 2022, we have observed a significant drop in the number of new threads and posts related to Russian-language dark web forum content, as well as the total number of all Insikt Group threat leads. ,” said Recorded Future.

“We believe that the partial mobilization order issued by Russia may have resulted in the conscription of multiple threat actors. , Estonia, Finland and Kazakhstan. We believe this explains the decline in activity on Russian-language sources since September 2022. ”

The war has also undermined solidarity among Russian-speaking threat actors as a result of disagreements over the war and support for the Putin regime. 2023 could see more leaks like the one that exposed Conti and the Trickbot group.

“This damage has established a new standard for internal instability, as evidenced by a spate of insider leaks,” the report said.

But those who hope the war will fatally undermine Russia’s cybercrime economy will likely be disappointed. claim.

We also warned of a surge in nationalist “crowdsourced” hacktivism, but its impact may be limited.

Going forward, Recorded Future warned that the Kremlin could soon absolve Russian cybercriminals of their crimes.

However, the expected increase in data breaches affecting Russia and Belarus could bring bad news for Russian organizations.

“As the Russian and Belarusian compromised databases grow, we will also see a correlation with increased compromised credentials on dark web forums targeting .ru and .by domains,” concludes the report.

“We believe this will happen because a large number of Russian databases have been leaked since the start of #OpRussia and are not yet in general circulation.”

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *