Close Menu
NewsFile GH
  • Home
  • Local News
  • Politics
  • Business
  • Sports
  • Showbiz
  • Odd News
  • Opinion
What's Hot

Forex gains reflect policy efficiency, not IMF ‘intervention’ – Adongo

Gabriella Tetteh warns NPP: Internal squabbles could cost your party its relevance

Breaking: Former MASLOC CEO Sedina Tamakloe detained in Nevada, USA, awaiting extradition

Facebook X (Twitter) Instagram
Trending
  • Forex gains reflect policy efficiency, not IMF ‘intervention’ – Adongo
  • Gabriella Tetteh warns NPP: Internal squabbles could cost your party its relevance
  • Breaking: Former MASLOC CEO Sedina Tamakloe detained in Nevada, USA, awaiting extradition
  • “You can’t fail an economy you didn’t run” – Atta Akyea defends Bawumia
  • Mahama names advisory team on the economy to drive stability, exports and the 24-Hour Economy
  • IGP promotes 35 officers for role in Adabraka gold robbery arrests
  • Supreme Court sets clear guidelines for distribution of marital property in divorce cases
  • Ghana, Japan strengthen diplomatic and economic ties at bilateral talks
Facebook X (Twitter) Instagram
NewsFile GH
Demo
  • Home
  • Local News

    Supreme Court sets clear guidelines for distribution of marital property in divorce cases

    January 16, 2026

    Health Minister reforms pharmacy licensing to improve access across Ghana

    January 15, 2026

    Chiefs, communities, and councils: A renewed push for inclusive local governance

    January 15, 2026

    Intelligence-led operation nets six in Juaso robbery and rape case

    January 15, 2026

    Government vows stronger measures against assault on journalists

    January 14, 2026
  • Politics

    Gabriella Tetteh warns NPP: Internal squabbles could cost your party its relevance

    January 16, 2026

    “You can’t fail an economy you didn’t run” – Atta Akyea defends Bawumia

    January 16, 2026

    David Asante rebuts Mahama’s remarks; credits his leadership for GPCL turnaround

    January 15, 2026

    President Mahama committed to scrapping ex Gratia – Kwakye Ofosu

    January 15, 2026

    Over 500 CHPS compounds advancing to strengthen community-level healthcare delivery

    January 15, 2026
  • Business

    Forex gains reflect policy efficiency, not IMF ‘intervention’ – Adongo

    January 16, 2026

    Mahama names advisory team on the economy to drive stability, exports and the 24-Hour Economy

    January 16, 2026

    NPA CEO leads management team on working visit to TOR

    January 15, 2026

    Mahama sets up Advisory Group on Economy; membership includes Sam Jonah, Dr Kwabena Duffour et al

    January 15, 2026

    Airbus confirms Ghana’s order for helicopters; says returning with ‘defined focus’

    January 15, 2026
  • Sports

    Ghana get Cameroon, Mali & Cape Verde in WAFCON 2026 draw

    January 15, 2026

    Rosenior proud of Chelsea’s bravery despite Carabao Cup setback

    January 15, 2026

    Arbeloa takes charge as Madrid sack Xabi Alonso as manager

    January 12, 2026

    Semenyo named Man of the Match after scoring on Man City debut

    January 10, 2026

    African pride continues as Yaya Touré blesses Semenyo’s historic Manchester City move

    January 9, 2026
  • Showbiz

    Tourism ministry appeal to Emirates to showcase Ghanaian culture, heritage and tourism onboard flights

    January 15, 2026

    Gabrielle Union shares an emotional Ghana journey marked by history, spirituality and ancestral connection at River of No Return

    January 15, 2026

    Tourism minister urges diaspora partnerships to turn Ghana into a year-round tourism destination

    January 13, 2026

    Ghana Tourism Authority highlights strategic marketing efforts for December in GH 2025

    January 12, 2026

    Event organisers get funding, venues and backing from GTA this December – Abeiku Santana

    January 12, 2026
  • Odd News

    Nsawam Female Prison inmates showcase talents, proving rehabilitation thrives through discipline, culture and self-expression

    January 6, 2026

    Drunk raccoon found passed out on liquor store floor after breaking in

    December 3, 2025

    Search for Malaysia Airlines flight MH370 missing in 2014 to resume

    December 3, 2025

    School bans singing of KPop Demon Hunters songs

    November 17, 2025

    Why brushing teeth twice a day is not always best

    November 3, 2025
  • Opinion

    FACT CHECK: Ken Agyapong’s claim that Bawumia skipped Adenta NPP campaigns false

    January 13, 2026

    The Plate is a Right: Why access to food is not a privilege

    January 12, 2026

    From Bournemouth to the Etihad: Semenyo’s £65m leap rewrites Ghanaian football history

    January 9, 2026

    From prophecy to prosecution, Ebo Noah’s fate now rests with courts and psychiatric evaluation

    January 8, 2026

    Value for money questioned as Ghana funds multiple anti-corruption watchdogs, says Tuffour Boateng.

    January 8, 2026
NewsFile GH
Home»Tech»A guided tour of the cybercrime underground
Tech

A guided tour of the cybercrime underground

By KrobeaFebruary 23, 20177 Mins Read
Share Facebook Twitter LinkedIn Email WhatsApp Telegram Copy Link
Share
Facebook Twitter LinkedIn WhatsApp Copy Link Email

Petya ransomware
The Petya ransomware makes a computer unusable until a ransom is paid

One of the strange features of cybercrime is how much of it is public.

A quick search will turn up forums and sites where stolen goods, credit cards and data are openly traded.

But a glance into those places may not give you much idea about what is going on.

“Everyone can join as long as you speak Russian,” said Anton, a malware researcher at security firm Sentinel One, who has inhabited this underground world for more than 20 years.

“By Russian I mean the USSR, so there is Ukrainians, there is Kazakhstan, there is Belarus. The Romanians are doing all the dirty work like spam and maintenance so they are not really involved in developing malware,” he said. “But, today, is it mainly Russian? Yes.”

Those vibrant underground marketplaces have a long history and Anton adds that he tracks the malware makers to gain insights into what they might do next.

“I was there from the very early stages,” Anton told the BBC. “I guess I started at about the age of 12, when there was not much online community.

“Instead it was many channels where hackers exchanged information and exploits and kind of stuff like that,” he said.

In those early days few wanted to break the law, he said.

“Back then there was not much money involved at all,” he said. “It was only about sharing knowledge, sharing information, sharing various scripts or downloading warez – which is pirated content.”


Analysis

Tony Rowan, director of Sentinel One, which employs Anton to log what happens on crime forums and dark web marketplaces.

“It gives us an insight into the directions these communities are taking.

“We have to monitor these to understand what they are doing, the success they are having and what they are about to do next.

“You have to be prepared rather than just sit back and wait for it to happen to you. It’s essential for us to have this kind of contact because without it we are blind.”

Spam in email inbox
Responsibilities are divided up among different groups on underground forums

Rick Holland, strategy head at security firm Digital Shadows which tracks online hacker groups

“There’s a lot of criminality going on on the open web, particularly when you get into the Russian federation. They do not need to be on the dark web. Some are quite brazen and quite public whereas others have a much higher level of operational security.

“If we are tracking a criminal location and we find chatter about our clients that can be of value,” he said. “In the longer term it’s what’s coming over the horizon. What are they dialling up next?

“It’s not trivial to do something like that, it’s definitely not easy to do although I think there’s definitely value in working out what they are doing.”


The underground changed after the millennium turned and e-commerce took off. Forums popped up that talked about how to cash in via spam, phishing, malware and web attacks.

There was another big shift in 2007-08, said Anton, as the criminals sought a way to fleece people that gave better returns than the cruder techniques. The first wave, which started the modern era of cybercrime, used fake anti-virus software.

“They installed some really, really poorly written software on your machine,” he said, explaining the scam. “It looked like anti-virus but it actually does nothing.

“It tells you: ‘We just scanned your PC and we have found many problems. You need to fix it now, you need to buy this software. It only costs $35-40 (£28-32)’,” he said.

This worked better than earlier scams, said Anton, but it took a lot of effort to catch people out and get them to pay.

Often, he said, when people paid via a credit card they reversed the transaction once they found out they had been tricked. Conversion rates, meaning the number of victims who handed over cash, stayed low.

“This meant they must do something better, something more scary.”

Frightened people pay up, said Anton, adding that this drove the next evolution: lockers.

“What they do is they attack your browser and put up a big page on your main desktop, saying you were found with illegal child pornography or something very, very scary,” he said.

Computer code
The early days on the underground were all about swapping code

“People got afraid saying ‘OK, maybe one of my kids did it, maybe, I’m not sure, I’ll pay’,”.

The one-page attacks asked for more money, up to $200 (£160), and proved so successful that many police forces issued warnings that urged people not to pay.

The success, and also the publicity, forced the next stage of crimeware – ransomware, Anton explained.

“I call it an evolution because the same people that did the fake anti-virus before are doing ransomware now. And they were doing the fake police page in the years between 2010 and 2013,” he said.

Ransomware has the best conversion rate, he said, because victims cannot ignore its effects.

“It’s real damage so that you can see that your files are no longer working. And that’s the best proof for the user that he must pay,” he said.

Never stop

Its rise has also been helped by the advent of virtual currency Bitcoin, because it has few of the drawbacks of credit cards or other payment systems.

“Today you cannot talk about ransomware without mentioning Bitcoin because that’s what made this evolution come,” said Anton.

The damage is not just limited to the amount people pay. Estimates from the FBI suggest that the 992 cases of ransomware carrier Cryptowall reported during a 14-month period cost victims $18m (£14.4m). Some of the cost was in the ransom, up to $10,000 (£8,000), but this was multiplied by lost productivity, legal fees and work done to remove the infections.

It is popular, he said, because of another shift in the way that the underground is organised. In the past the groups writing the malware sent the spam, analysed the results and fleeced the victims.

Bitcoin
The advent of Bitcoin virtual cash has driven the rise of ransomware

Not any more, he said. Now, many groups writing ransomware run it as a service.

“They will give you the software with your affiliate ID so if you spread it they will know that it’s from you and you will get a payout,” he said. “You will get 70% and they will get the 30% out of each payment.”

Competition among ransomware writers means some other groups give better returns.

But, he said, those groups may be producing poorly-written malware that struggles to get past the digital defences people and businesses use.

The evolution of the underground has hit a peak with ransomware and Bitcoin, said Anton, and their combined success has kicked off a gold rush.

“It’s getting more and more people attracted to it, like from the criminal side. More and more people are starting to spread it.”

They will not stop, either, he said. “I think if you get easy money and it just keeps coming, why not continue it, right? It’s obvious.”

Source: BBC

Share. Facebook Twitter LinkedIn Email Copy Link WhatsApp

Related Posts

Tons of cashew nuts rot as Ministry imposes ban on export

March 17, 2019By newsfilegh2 Mins Read

Group targets increase in insurance for GDP

December 25, 2017By Krobea2 Mins Read

Jerusalem vote: Israel warns Ghana not to repeat ‘mistake’

December 22, 2017By Krobea2 Mins Read
Follow Us
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Recent Posts
  • Forex gains reflect policy efficiency, not IMF ‘intervention’ – Adongo
  • Gabriella Tetteh warns NPP: Internal squabbles could cost your party its relevance
  • Breaking: Former MASLOC CEO Sedina Tamakloe detained in Nevada, USA, awaiting extradition
  • “You can’t fail an economy you didn’t run” – Atta Akyea defends Bawumia
  • Mahama names advisory team on the economy to drive stability, exports and the 24-Hour Economy
  • IGP promotes 35 officers for role in Adabraka gold robbery arrests
Top Posts

Forex gains reflect policy efficiency, not IMF ‘intervention’ – Adongo

Gabriella Tetteh warns NPP: Internal squabbles could cost your party its relevance

Breaking: Former MASLOC CEO Sedina Tamakloe detained in Nevada, USA, awaiting extradition

“You can’t fail an economy you didn’t run” – Atta Akyea defends Bawumia

About Us
About Us

NewsFile Gh is a comprehensive news portal that delivers up-to-date information on a wide range of topics, including politics, business, sports, entertainment etc. It provides users with real-time news updates accessible anytime and anywhere...

Email Us: news@newsfilegh.com

Facebook X (Twitter) YouTube RSS
Recent

Forex gains reflect policy efficiency, not IMF ‘intervention’ – Adongo

Gabriella Tetteh warns NPP: Internal squabbles could cost your party its relevance

Breaking: Former MASLOC CEO Sedina Tamakloe detained in Nevada, USA, awaiting extradition

Most Popular

IS leader in Afghanistan ‘killed’

July 11, 2015

‘Oldest’ Koran found at UK university

July 22, 2015

Gunman in Mahama’s church for court today

July 28, 2015
© 2026 NewsFile GH. All Rights Reserved.
  • Home
  • Politics

Type above and press Enter to search. Press Esc to cancel.