Politics

Cybercrime is for everyone

The Column – Cyber ​​Security Week

For years we have portrayed the cybercriminal as a sleepless teenager locked in a dark room. Then he became a serious professional and then an entrepreneur. Today KillSec arrives and manages to be all three things at the same time. On September 30, an international operation hit the group: three arrests, eight searches, servers and domains seized, over 110 terabytes of stolen data placed under control of the authorities. Approximately one thousand attempted attacks worldwide are attributed to the group, at least five hundred of which are considered successful.

So far, unfortunately, nothing so new. The part that forces us to change our perspective comes when we discover that the alleged main administrator of the criminal network is sixteen years old. Be careful with your words: he is a suspect, not a convict, and we don’t know how personally sophisticated he was. Precisely for this reason I would avoid the shortcut of the “sixteen-year-old hacker genius”, but perhaps the interesting question, or rather I should say the confirmation, is another: what if to lead a piece of cybercrime it was no longer necessary to be a genius?

KillSec, according to available reconstructions, functioned as a Ransomware-as-a-Service. In practice there was a core group that developed and maintained the tools and infrastructure, and there were affiliates who used them to target victims, sharing the proceeds. There were distinct roles: administrator, developer, negotiator, affiliate. There was even a price list: access to the program, deposit, percentage on redemptions. Not a gang in the romantic sense of the word, but a small criminal enterprise with a platform, internal customers, quality control and margins.

The issue becomes even clearer when looking at how they entered organizations. No laser beams against the firewall, but the usual arsenal: phishing, known vulnerabilities, attacks against exposed services and poorly protected access. In several cases, all that was needed was data left in poorly configured cloud storage and therefore publicly accessible. On the one hand ransomware-as-a-service, cryptocurrencies, dark web and artificial intelligence. On the other, someone who left a door open. Fate, as often happens, encounters the wrong configuration.

Then there is artificial intelligence. Investigators say KillSec used it to build and maintain ransomware infrastructure and to target potential victims. We know this, but not which models it used, how much of the code was generated by AI, nor whether the systems acted autonomously or as assistants to the operators. So no “AI-driven ransomware”: that would be a more spectacular phrase than the facts, which, in any case, are already interesting enough.

The point is that AI is part of a process that began before it. Cybercrime has progressively transformed expertise into a service. You buy a piece from those who develop the malware. Another one from those who sell access. The vulnerabilities are already documented. Tools circulate in forums. The platform manages victims and negotiations. Now a further part can be delegated to artificial intelligence systems. Expertise does not disappear: it is broken down, distributed and above all it becomes available on request.

This is the big confirmation that KillSec leaves behind. The age of the suspect is striking because sixteen is or should be sixteen. The problem is not to find out whether a guy is exceptionally good, but rather to understand how little anyone who wants to put together skills developed by others, purchasable services and tools that further lower the cognitive cost of the attack must now know.

We’ve spent twenty years wondering how good hackers were, but this news confirms that we’re entering an era where the right question is how easy it has become to buy, assemble or delegate what you once had to learn.

When experience also becomes available on demand, talent stops being a barrier to entry.