Security Bytes

Feb 2 2010   1:36PM GMT

Chinese hacker says most are not skilled coders



Posted by: Robert Westervelt
hacking tools and techniques, hacking groups

Automated tools fuel rise in less savvy hackers. How much do they really profit?

The New York Times managed to track down and interview a China-based hacker, offering a glimpse into what it says is a thriving hacking community there. The headline says “Hacking for Fun and Profit in China’s Underworld.” But there’s no real evidence of profit.

David Barboza’s description of the hacker, who goes by the name Majia, lives up to the old-school hacker stereotype: He’s young. He seems to be in it for the fame and he lives in a dingy apartment. He has a government job by day and at night spends long hours checking the statistics on his automated tools and time seeking out website vulnerabilities to crack into business websites in China and other countries to steal sensitive data or to install a malicious script to expand the scope of his automated attack tool’s reach. He claims to be making a lot of money. But then Barboza tells us this:

Majia lives with his parents, and his bedroom has little more than a desktop computer, a high-speed Internet connection and a large closet. The walls are bare.

Barboza found a very active community of hackers, willing to share and trade information. But the hacker Majia admits that today most hackers aren’t very skilled at all. We’ve been reporting on SearchSecurity about the rising level of automated attack tools making it relatively easy for non-technical people to become cybercriminals.

Last summer new research emerged painting a picture of the economics driving many underground black hat hacker communities. Security researchers Cormac Herley and Dinei Florencio found that there are far too many people attempting to make money phishing for passwords, account numbers and other sensitive data. While the picture isn’t exactly crystal clear and their work centered around automated phishing tools, it appears that a majority of the money being made in cybercriminal activity are by a handful of individuals. It’s like a pyramid scheme. The most skilled hackers are at the top. They create and sell (also rent) the automated tools to the minions below them. Those in the lower levels of the pyramid are often exposed to data stealing malware themselves. There’s a lot of infighting. There’s a lot of grandstanding. Most hackers need to prove themselves as legitimate.

“Some people probably try it for a while, don’t make much, and then wander off to try something else,” Herley told me at the time. “Breathless stories about ‘easy money’ probably ensures enough new entrants to keep the phenomenon going.”

More research needs to be done to get a clearer picture. Security researchers Billy Rios and Nitesh Dhanjani, who infiltrated the underground phishing market in 2008, agreed with the main points of Herley and Florencio’s assessment: The total annual losses associated with phishing at $61 million. Much less than the $3.2 billion estimated by Gartner Inc.

Unless he’s investing his earnings in a retirement fund, the hacker Majia is far from the top of the hacking pyramid. That’s why he’s living with his parents in a dingy apartment in one of China’s poorest neighborhoods.

Comment on this Post


You must be logged-in to post a comment. Log-in/Register

Spsdel01  |   Jan 16 2011   2:14PM GMT

This is nice to hear from you. Wow its good. STD symptoms


 

Spsdel01  |   Feb 3 2011   1:39PM GMT

This is the best one to read, thanks a lot. shingles contagious


 

Rgmoon  |   Mar 16 2011   6:52AM GMT

It is very important for us to know about hackers. Because we are now able to understand the software related problems. Thanks for providing this service for us. I hope you will keep you efforts.
puget sound business journal


 

Ahmadferi  |   Mar 21 2011   4:05AM GMT

Simply, admirable what you have done here. It is pleasing to look you express from the heart and your clarity on this significant content can be easily looked. Remarkable post and will look forward to your future update.

ravel shoes | large size ladies shoes


 

Campbellz  |   Mar 22 2011   4:55AM GMT

I think this is one of the most important information for me. And i’m glad reading your article. But wanna remark on some general things, The site style is great, the articles is really excellent : D. Good job, cheers. iphone 5 case


 

Rea  |   Mar 22 2011   5:10AM GMT

Aw, this was a really great post. In theory I’d like to write like this also - taking time and real effort to make a good article… but what can I say… I procrastinate alot and never seem to get something done. justin bieber songs


 

Mardhois  |   Mar 22 2011   6:10AM GMT

Hrmm that was weird, my comment got eaten. Anyway I wanted to say that it’s nice to know that someone else also mentioned this as I had trouble finding the same info elsewhere. This was the first place that told me the answer. Thanks. Central News World | Breaking News Trends | Download Windows Firewall


 

Aguswazza  |   Mar 22 2011   6:14AM GMT

I would like to thank you for the efforts you have made in writing this article.blogger trix


 

1993  |   Mar 22 2011   6:25AM GMT

I really believe this really is post is very essential end up being endorsed to all anyone who has enjoyed within this years. due to the fact some times similar to this everyone requirements the existence of any information about technologies along with almost all it’s improvement. so when together with things technologies could also often be served.

Browser exploit kit probe highlights need for patching, vigilance | Hairstyles


 

Denada  |   Mar 22 2011   7:23AM GMT

I hope all website will never hacked by untrusted people. Thanks for share this ideas. Really like it.

Warm Regard
Chicken Fried Steak & Flank Steak Recipes


 

Nyotnyot  |   Mar 22 2011   9:36AM GMT

Sure they don’t have a special facility with high-tech equipment; they operate from small apartments. Don’t underestimate them - they are hardcore hackers who claim that “no web site is 100% safe”. love song and car reviews


 

Mannul  |   Mar 22 2011   2:59PM GMT

thank’s your sharing information , your post is good .

Popular news information in world


 

Didik  |   Mar 23 2011   5:21AM GMT

Thanks for taking the time to discuss this, I feel strongly about it and love learning more on this topic. If possible, as you gain expertise, would you mind updating your blog with more information? It is extremely helpful for me

itsecuritys | ipad prices


 

Thebaligetaway  |   Mar 23 2011   6:27AM GMT

Those in the lower levels of the pyramid are often exposed to data stealing malware themselves. There’s a lot of infighting. There’s a lot of grandstanding. Most hackers need to prove themselves as legitimate.

visit us at Bali Holiday Packages and find your unique information in Alternative article directory


 

Arazone  |   Mar 23 2011   8:06PM GMT

I must admit that this is one great insight. It surely gives a company the opportunity to get in on the ground floor and really take part in creating something special and tailored to their needs.
private loans consolidation|private student loan consolidation


 


Bondan13  |   Mar 26 2011   12:34PM GMT

probably the cause google is not shown in China because its a hacker
loan insurance
collar for cat


 


Arazone  |   Mar 30 2011   8:54PM GMT

This is my first time i visit here. I found so many entertaining stuff in your blog, especially its discussion. From the tons of comments on your articles, I guess I am not the only one having all the enjoyment here! Keep up the good work.
tv shows


 

Digitaltechnology  |   Apr 20 2011   11:41PM GMT

hahahahah i agree but im not hacker digital technology


 

Erwjan  |   Apr 29 2011   3:34AM GMT

Nice review of the subject , I was looking to understand this matter further and found this information to be informative :)


 

Rgmoon  |   May 9 2011   6:41AM GMT

If the Chinese hackers said this, it might be true. I am not completely agree but it looks there must be some reality. However, we will be able to know the actual situation after sometime, hope so.
Craigslist Reno