Cocky malware firms post job ads online
By Reuters and Barry Collins
Posted on 3 Feb 2010 at 08:18
Arrogant malware writers are posting job vacancies online in a bid to attract new recruits, according to a leading security company.
Two companies that are hiring - at least on a contractor basis - advertise online, claims Kevin Stevens, a threat intelligence analyst for SecureWorks, who presented findings on the organisations at the Black Hat cybersecurity conference outside Washington.
What they are seeking is people who are willing to take malicious code they provide and link it to something that people will click on - such as a picture of Britney Spears getting out of her car. These people then collect a fee for each 1,000 times that the malware is downloaded.
One site, for example, pays $180 for each 1,000 times that malware is downloaded onto a US computer but less for PCs elsewhere. It refuses to pay for any downloads to Russian PCs, causing Stevens and others to strongly suspect that it, like other similar sites, is based in Russia.
"We pay your wages via the following systems: Fethard, WebMoney, Wire, e-gold, Western Union (WU), MoneyGram, Anelik and ePassporte, and PayPal," the site states.
Stevens says it's impossible to tell how many computers were infected via these companies but put the number in the millions.
It's hard to separate theft arising from these websites from other sorts of internet crime but the FBI tallied $264 million in losses from internet crime reported by individuals in 2008. The report for 2009 has yet to be released.
The cybercrime problem has become worse over the past three years as consumers and companies alike increasingly expose valuable data such as credit card numbers and banking information on the internet.
From around the web
Apply with covering letter & CV
Interesting - presumably the malware company is happy to take pseudonyms for their employees?
Anyone going to give them their real name, address & date of birth, etc?
By greemble on 3 Feb 2010 ![]()
Why couldn't wages be paid into your bank account?
Just send them your bank sort code and account number.
Oh, hang on...
By JohnGray7581 on 3 Feb 2010 ![]()
And why shouldn't malicious code writers be paid?
As long as there are holes in the security of websites and operating systems that need to be highlighted I say get the holes found and filled
By daz_ryan on 3 Feb 2010 ![]()
advertisement
- Laptop bag reviews: nine tested
- Sony VAIO T Series Ultrabook review: first look
- Revealed: the military standards and robots HP uses to test its laptops
- Windows 8: multi-monitors and double standards?
- Why is TalkTalk's year-old porn filter suddenly big news?
- Why are laptop screens so far behind mobiles?
- HP EliteBook Folio review: first look
- The shoebox-sized all-in-one printer
- Forget the Ultrabook: here comes the HP Sleekbook
- HP Spectre XT review: first look
- Why you have to be left in the dark on OS patches
- Publishing your email address isn't a security disaster
- Why antivirus is fighting a losing battle in your office
- Four year olds used to steal their parents' data
- An acceptable use policy for your kids
- Paying for your crimes with Bitcoin
- Pavement hacking: What it is and how to avoid it
- Google's risky pre-loaded pages
- Mac under attack: how secure is Apple's OS?
- Has your browser been hijacked?
advertisement
