Russian Cyber-Crime Market Doubled In 2011

The New Acunetix V12 Engine


It’s been quite a while since we’ve posted any news about Russia, so here’s an article which in some ways is quite scary.

The global cybercrime market is being dominated by Russian-speaking nations and their activity doubled in 2011. It’s certainly a disproportionate amount of crime when you look at their population size.

Cybercrime is a HUGE business, especially when it comes to malware and trojans targeting banking details and the follow on phishing scams.

Russian-speaking criminals grabbed more than a third of the entire global cybercrime market in 2011 as a growth in online fraud activity turned the country into a major digital crime superpower, a new report has suggested.

Russian cybercriminals earned $4.5 billion in 2011

The State and Trends of the Russian Digital Crime market 2011 from Russian security research company Group-IB estimates (using public and partner data) that the global cybercrime market reached around $12.5 billion (APS7.74 billion) in size during the year, with Russians and Russian speakers (including those outside the country) accounting for $4.5 billion of that total.

At the same time, using its own internally-collected analysis, the Russia-only cybercrime market doubled to $2.3 billion compared to 2010, a disproportionate level of activity considering the country’s modest 143 million population.

The top Russian cybercrime activity was online fraud, equivalent to almost a billion dollars in revenue, just ahead of spam on $830 million, internal market services on $230 million and DDoS on with $130 million.

As well as startling growth, the Russian cybercrime scene also saw consolidation into larger, more organised groups increasingly controlled by conventional crime mafias. There was also evidence of co-operation between these groups, and the growth of an important internal ‘crime-to-crime’ (C2C) market to support its activities.

$12.5 Billion dollars is a LOT of zeros, that was the estimate of the money lost in 2011 to cybercrime. That’s almost $2 per person for the ENTIRE population of the World, that’s what I would colloquially call a shitload of cash.

It doesn’t stop there too, it amazes me that DDoS attacks are a multi-million dollar business! In Russia alone, according to this report anyway, these crims earnt $130 million USD carrying out DDoS attacks!


Coming from a Russian-based group of researchers, the report makes fascinating reading. There is a wealth of anecdotal evidence from crime busts and malware trends that Russia is a key hub for crybercrime but hard numbers are seldom put on its inner workings or business model.

An obvious question is why Russia has become such an important country for cybercrime. Beyond the traditional explanation of the large number of relatively poorly-paid programmers in the country, Group-IB also underlines the importance of policing and local laws.

The researchers note the case of Yevgeniy Anikin and Viktor Pleschuk, who were part of the gang that stole $10 million from the Royal bank of Scotland’s WorldPay ATM system in 2008 And yet received suspended sentences from Russian courts.

“Thus, because of imperfections in Russian laws and the lack of severe penalties, stable law enforcement practice, and regular training regarding counter cybercrime measures, cybercriminals are disproportionately [not held] liable for the crimes they commit,” note the researchers.

“The cybercrime market originating from Russia costs the global economy billions of dollars every year,” said Group-IB’s CEO, Ilya Sachkov.

The lax laws when it comes to cybercrime in Russia aren’t going to help the situation, but sadly – I’m not sure if they will even care.

If you want to read the original report you can do so here:

State and Trends of the Russian Digital Crime market 2011 [PDF]

Source: Network World

Posted in: Malware, Phishing, Spammers & Scammers

, , , ,


Latest Posts:


SCADA Hacking - Industrial Systems Woefully Insecure SCADA Hacking – Industrial Systems Woefully Insecure
airgeddon - Wireless Security Auditing Script airgeddon – Wireless Security Auditing Script
Airgeddon is a Bash powered multi-use Wireless Security Auditing Script for Linux systems with an extremely extensive feature list.
Acunetix v12 - Pause & Resume Acunetix v12 – More Comprehensive More Accurate & 2x Faster
Acunetix, the pioneer in automated web application security software, has announced the release of Acunetix v12 - more comprehensive, accurate & 2x faster.
CloudFrunt - Identify Misconfigured CloudFront Domains CloudFrunt – Identify Misconfigured CloudFront Domains
CloudFrunt is a Python-based tool for identifying misconfigured CloudFront domains, it uses DNS and looks for CNAMEs which may be allowed to be associated with CloudFront distributions.
Airbash - Fully Automated WPA PSK Handshake Capture Script Airbash – Fully Automated WPA PSK Handshake Capture Script
Airbash is a POSIX-compliant, fully automated WPA PSK handshake capture script aimed at penetration testing, it is compatible with Bash and Android Shell.
XXEinjector - Automatic XXE Injection Tool For Exploitation XXEinjector – Automatic XXE Injection Tool For Exploitation
XXEinjector is an XXE Injection Tool that automates retrieving files using direct and out of band methods. Directory listing only works in Java applications.


One Response to Russian Cyber-Crime Market Doubled In 2011

  1. Hary May 3, 2012 at 10:14 pm #

    Oh God! Why its always rusian or china? Did they start new form of cold war with cybercrime?