It is no secret that cyberspace is full of threats. From cybercriminals to, why not, large technology corporations - the so-called *Big Tech -*all compete to obtain the most precious asset of the 21st century: our data.
Let’s take a closer look at some of these actors from which we must protect ourselves, and they are not few in number.
Cybercriminals have been pestering us for decades, either with phishing campaigns or by spreading malware.
However, two technologies drove the rise of cybercrime: the use of anonymous networks, such as Tor (also known as darknets), and the emergence of cryptocurrencies, such as Bitcoin.
These innovations enabled cybercriminals to communicate and trade securely, creating a cascading business in which cybercrime services were offered “as a service”.
The anonymity provided by dark networks and cryptocurrencies significantly reduced the risk of detection.
This allowed them to make a lot of money, which quickly attracted millions of new cybercriminals.
Today, cybercrime represents the biggest threat to companies.
But who are these “bad guys” from whom we must protect ourselves so much?
When we talk about them, in many cases, their evil depends on the point of view or the side we are on.
For example, state-sponsored hackers may seem malicious to us if they operate against our country’s interests.
However, we will not see them as such when they are serving our nation and looking after our interests.
Similarly, activities carried out by hackers from one nation who decide to attack the critical infrastructure of another in times of tension could sometimes be referred to as cyberterrorism.
A clear example occurred in 2007, in what is considered the first act of cyberwarfare between countries, where Russian hackers attacked Estonia and plunged the country into chaos for several days. However, Russia did not consider it appropriate to call these groups cyberterrorists, but rather patriotic hackers.
Another case of differences in perspective can be found in the activities of hacktivists. Some groups might consider them heroes for claiming important issues such as net neutrality, animal rights or climate change, even if they do so illegally.
However, there are other groups that leave no room for doubt and have a well-deserved reputation as “bad guys”, such as cybercriminalgangs and mafias operating in cyberspace.
Although I do not think it is fair to include Big Tech, these large companies that abuse, traffic with our data and spy on us indiscriminately, after seeing the abusive practices to which we are accustomed, I do not think it is unreasonable to include them in this section.
It is clear that we must also protect ourselves from them.
Except in rare cases where cybercriminals choose their victims to launch targeted attacks as part of a perfectly defined plan, in all other cases, cybercriminals choose the path that offers the least resistance.
For this reason, the vast majority of cybercrimes are aimed at launching massive campaigns against a wide range of victims, where they seek quick monetization. The success of their activities will depend on the percentage of dupes who fall for their tricks.
And pardon the expression, but yes, they are clumsy, as they tend to be people who don’t do the least to increase their cybersecurity culture.
If these cybercriminals launch a massive automated campaign to 10,000 people, trying to swindle 200€ each, with only 1% falling for the scam, we would already be talking about a profitable business of 20,000€.
This is not an insignificant figure, considering the low effort involved and the low risk due to the intrinsic properties of cyberspace: distance, speed, anonymity and the absence of borders.
Some hackers are dedicated to stealing information, while other groups buy the stolen information on darknet“black markets”, full of databases with private user information (e-mails, telephone numbers, credit cards, etc.), obtained fraudulently after computer attacks on online service companies.
There is a real cybercriminal ecosystem perfectly interlocked, where some steal, others buy and others exploit information. As I mentioned in a previous article, they are real cybercrime companies.
A clear example of these marketplaces is the case of Genesis Market, a website that operated on the darknet and was dismantled by the FBI in an international operation in 2023. This marketplace specialized in selling stolen credentials, session cookies and other data that allowed buyers to impersonate victims’ digital identities.
A year later, INTERPOL conducted Operation Synergia II, which focused on combating threats such as phishing, ransomware and information theft programs. During this operation, more than 22,000 IP addresses and malicious servers linked to cybercrime were dismantled.
It is important to note that operations against illegal markets on the darknet are complex.
One controversial example is Donald Trump’s pardon of Ross Ulbricht, creator of the Silk Road black market, after 11 years in prison.
Ulbricht was convicted in 2015 for drug trafficking, money laundering and computer crimes, but in reality, he was “only” the owner of an online platform where you could buy and sell everything anonymously using Bitcoins.
Trump criticized those who condemned Ulbricht, saying they were “the scum” and “the same lunatics who participated in the modern instrumentalization of government,” and made good on his election campaign promise to pardon him by showing his support for the libertarian movement and the world of cryptocurrencies.
But, back to our topic, it is common to hear that information and data are the oil of the 21st century, and both companies and cybercriminals know this very well.
They are willing to do anything to get their hands on a good share of the loot.
On the one hand, we have Big Tech like Google, Facebook, Apple, Microsoft, Amazon, OpenAi, Alibaba, ByteDance, etc.
Some of them collect data through telemetry implemented in their operating systems, while others obtain information when users use their services or applications. To such an extent that it could be said that some of them know their users better than they know themselves.
Imagine the amount of data that Google can collect: through its search engine, Gmail, Google Maps, YouTube and the Android operating system. Millions of terabytes of information about our tastes, searches, preferences, location, relationships, etc.
It is crucial that users are aware that everything they search for on the Internet can be associated with them. Questions such as “how to make a home-made bomb”, “how to cut cocaine”, “how to cure my breast cancer” or “how to get off a list of defaulters” can expose sensitive information about who we are, what is wrong with us or what we plan to do.
Some questions of a private and confidential nature should be avoided in search engines and artificial intelligence tools, since they are associated with us.
No one guarantees that companies will make good use of that information or that, in the future, someone will hack it and expose it, as is already happening to some AI tools.
On the other hand, cybercriminals try to collect personal information through deception or by installing Trojan malware on their victims’ devices.
This type of malware, once installed, connects discreetly to aCommand and Control ( C2) center managed by the attackers.
From there, orders are given to take control of the device’s camera, record conversations, extract photographs, videos, contacts, bank card numbers, etc., all without the victims being aware of it.
In short, the fight for control of information is being waged on multiple fronts. From targeted attacks to mass campaigns, from exploiting vulnerabilities to illegal data trading, cybercrime has reached a high level of adaptation and sophistication. Understanding the motivations and methods of these malicious actors is essential to protect ourselves in an increasingly complex and interconnected digital world.
Information is power, and cybersecurity becomes the key to preserving it.