Today’s Malware and Virus infections are not created for fun. They are operated by organized groups of people with a definite purpose and established orders.
In a recent report, top security vendor Symantec had studied this underground economy and listed the top selling and advertised products. The report has some very interesting observations and it is surprising to know that sensitive data like Credit Card information is available for as low as $0.85.
The underground economy is an evolving and self-sustaining black market where underground economy servers, or black market forums, are used for the promotion and trade of stolen information and services. This information can include government-issued identification numbers such as Social Security numbers (SSNs), credit card numbers, debit card information, user accounts, email address lists, and bank accounts. Services include cashiers, scam page hosting, and job advertisements such as for scam developers or phishing partners.
Following are the top selling products and services in malware infection economy.
Cash out—a withdrawal service where purchases are converted into true currency. This could be in the form of online currency accounts or through money transfer systems and typically, the requester is charged a percentage of the cashout value as a fee.
Bank account credentials—may consist of name, bank account number (including transit andbranch number), address, and phone number. Online banking logins and passwords are often soldas a separate item.• Cash out—a withdrawal service where purchases are converted into true currency. This could be in theform of online currency accounts or through money transfer systems and typically, the requester ischarged a percentage of the cashout value as a fee.
Credit card information—includes credit card number and expiry date. It may also contain the cardholder name, Credit Verification Value 2 (CVV2) number, PIN, billing address, phone number, and company name (for a corporate card). CVV2 is a three or four-digit number on the credit card and used for card-not-present transactions such as Internet or phone purchases. This was created to add an extra layer of security for credit cards and to verify that the person completing the transaction was in fact, in possession of the card.
Email accounts—includes user ID, email address, password. In addition, the account may contain personal information such as addresses, other account information, and email addresses in the contact list.
Email addresses—consists of lists of email addresses used for spam or phishing activities. The email addresses can be harvested from hacking databases, public sites on the Internet, or from stolen email accounts. The sizes of lists sold can range from 1 MB to 150 MB.
Full identities—may consist of name, address, date of birth, phone number, and government-issued number. It may also include extras such as driver’s license number, mother’s maiden name, email address, or “secret” questions/answers for password recovery.
Mailers—an application that is used to send out mass emails (spam) for phishing attacks. Examples of this are worms and viruses.
Proxies—Proxy services provide access to a software agent, often a firewall mechanism, which performs a function or operation on behalf of another application or system while hiding the details involved, allowing attackers to obscure their path and make tracing back to the source difficult or impossible. This can involve sending email from the proxy, or connecting to the proxy and then out to an underground IRC server to sell credit cards or other stolen goods.
Shell scripts—used to perform operations such as file manipulation and program execution. They can also be used as a command line interface for various operating systems.
Complete Report-pdf, 4MB]













May 7th, 2010 at 4:52 pm
It is scary how easy and cheap it is to buy people’s personal and financial information. I knew that this market existed, but this is the first time I see the price of such information. It’s also alarming to see an increase in the transactions.
Thanks for sharing
August 4th, 2010 at 10:16 pm
Thanks, wow the stats says it all.
August 15th, 2010 at 11:09 am
Once they have your details they can access so much more it’s scary!
September 5th, 2010 at 6:36 am
We started to a software as Bayilik Franchise Software. This article gave help us for improve our program. We will send our program for your ideas.
November 14th, 2010 at 10:42 am
thank you so much for such a great subject its so hard to find such a very usful and greatful informations it took me a loon to find such a very good matrial thank you so much indeed
November 19th, 2010 at 1:27 am
EXE Errors Fix is your complete one-stop resource for EXE error-related information and solution. With the largest collection of Windows EXE errors and problems, EXE Errors Fix offers you the best solutions to fix any EXE errors.
December 17th, 2010 at 10:54 am
it is done by some people who done it regularly. thanks for ur info. aware of it.
March 1st, 2011 at 4:09 am
PCDriverUpdate.org also recommends driver update software to automatically download, update and fix your device driver problems. Take Auto Device Driver Update for a Spin to keep your PC and its programs properly.
June 29th, 2011 at 5:20 am
We support all businesses alike who provide quietly links and material around web design.