Relationships Matter: Reconstructing the Organizational and Social Structure of a Ransomware Gang
Unknown
Black Hat USA 2024 · Day 1 · Briefing
Overview
In "Relationships Matter: Reconstructing the Organizational and Social Structure of a Ransomware Gang," Jean Camp and Dalia Manatova present a compelling argument for a paradigm shift in how the cybersecurity industry perceives and counters e-crime. Moving beyond the often-glamorized image of the "sophisticated attacker," the speakers advocate for understanding cybercrime groups not merely as collections of individuals or technical attack chains, but as complex, resilience-maximizing business organizations with intricate social structures. This talk underscores that the efficacy of defensive strategies hinges on a deeper comprehension of these groups' internal dynamics, including their hierarchies, communication patterns, and cultural guidelines.

Key moments
- 0:00 Introduction: Viewing e-crime as organizations
- 0:45 Reframing e-crime: Boring, standardized organizations
- 1:30 E-crime social systems: informal hierarchies and communication
- 3:25 Analytical tools: linguistics, social network analysis, mapping
- 4:00 Cybercrime groups as resilient business organizations/APTs
- 5:15 Three dimensions of e-crime organizational resilience
- 8:50 Hierarchy, structure, specialization as resilience indicators
Relationships Matter: Reconstructing the Organizational and Social Structure of a Ransomware Gang
Speakers: Jean Camp, Professor; Dalia Manatova, Doctoral Researcher, Ostrom Fellow at Indiana University
Conference: Black Hat USA
YouTube: https://www.youtube.com/watch?v=2hx4oq_kaI8
Overview
In "Relationships Matter: Reconstructing the Organizational and Social Structure of a Ransomware Gang," Jean Camp and Dalia Manatova present a compelling argument for a paradigm shift in how the cybersecurity industry perceives and counters e-crime. Moving beyond the often-glamorized image of the "sophisticated attacker," the speakers advocate for understanding cybercrime groups not merely as collections of individuals or technical attack chains, but as complex, resilience-maximizing business organizations with intricate social structures. This talk underscores that the efficacy of defensive strategies hinges on a deeper comprehension of these groups' internal dynamics, including their hierarchies, communication patterns, and cultural guidelines.
The core of their presentation challenges the conventional focus on purely technical aspects of cyberattacks. Instead, Camp and Manatova propose applying established organizational theories and analytical tools—specifically linguistic analysis, social network analysis (SNA), and organizational mapping—to dissect the inner workings of e-crime syndicates. By treating these groups as any other enterprise, defenders can gain invaluable insights into their true operational resilience, identify critical vulnerabilities beyond technical exploits, and develop more targeted and sustainable disruption strategies. This approach promises a more holistic and effective method for threat management, ultimately enhancing the ability to counter persistent and evolving cyber threats.
The significance of this perspective lies in its potential to transform how organizations prioritize and respond to threats. Recognizing that an e-crime group's "attack chain" is essentially its "task management" allows for a more strategic assessment of its capabilities and vulnerabilities. This talk is crucial for security professionals, intelligence analysts, and policymakers seeking to move beyond reactive incident response towards proactive, intelligence-driven disruption of cybercriminal enterprises. By understanding the social fabric and organizational resilience of these adversaries, the industry can better anticipate their moves, identify points of failure, and ultimately diminish their long-term survival and operational capacity.
Background
▶ Watch: Introduction: Viewing e-crime as organizations (0:00)
The traditional narrative surrounding e-crime often casts attackers as either lone geniuses or highly advanced, anonymous entities executing "sophisticated attacks." While such actors certainly exist, Camp and Manatova contend that a significant portion of modern e-crime, particularly large-scale operations like ransomware gangs, is far more mundane and structured. They describe much of today's e-crime as "boring," "incredibly tedious," and standardized, akin to a call center operation. This perspective highlights a critical disconnect: the cybersecurity industry frequently focuses on the technical novelty of an attack, overlooking the underlying organizational machinery that enables its persistence and scale.
Prior research has extensively explored e-crime communities as marketplaces, analyzing how goods and services are bought and sold, and how arbitration mechanisms function within these illicit forums. This body of work has provided valuable insights into the economic underpinnings of cybercrime. However, Camp and Manatova argue that this view, while important, is incomplete. It often fails to account for the internal dynamics that govern these communities as organizations. They emphasize that these groups are not just ad-hoc collections of individuals transacting business; they possess defined (or emerging) roles, tasks, and social systems, much like legitimate corporations.
The problem, as articulated by the speakers, is that defenders often conceptualize an "advanced persistent threat" (APT) primarily through its technical capabilities and attack vectors. This technical lens, while necessary, can obscure the equally critical organizational dimensions that dictate an APT's long-term survival and resilience. Cybercrime groups, particularly ransomware gangs, are not merely "profit-maximizing" entities; they are resilience-maximizing organizations. They invest in structures, communication protocols, and social cohesion that allow them to withstand disruptions, adapt to new challenges, and continue operating even after significant setbacks. Without understanding these organizational traits—such as internal hierarchies, informal social connections, reputation systems, and cultural guidelines—defenders risk misjudging the true nature of a threat and implementing ineffective countermeasures. The analogy of an academic department functioning despite the absence of a Dean, yet collapsing if the Dean's secretary is sick, powerfully illustrates how informal roles and relationships can be more critical to an organization's functioning than formal titles. This underscores the necessity of moving beyond surface-level observations to uncover the true operational backbone of cybercriminal enterprises.
Key Findings
▶ Watch: E-crime social systems: informal hierarchies and communication (1:30)
The central insight and primary contribution of this talk is the re-framing of cybercrime groups as resilience-maximizing business organizations. This perspective shifts the focus from merely analyzing technical attack chains to understanding the intricate social and organizational structures that underpin an adversary's operational longevity and effectiveness.
The speakers highlight several key findings that emerge from this organizational lens:
- Cybercrime Groups are Business Organizations: They operate with structures, roles, and tasks that mirror legitimate businesses. Their "attack chain" is, from their perspective, simply "task management." This implies a level of standardization, process, and division of labor often underestimated by defenders.
- Resilience is a Core Objective: Unlike the common assumption that cybercriminals are purely profit-maximizing or reputation-maximizing, Camp and Manatova assert that these groups prioritize resilience. Their structures and social systems are designed for long-term survival and the ability to continue functioning despite law enforcement actions or defensive measures. This resilience manifests in three dimensions: the ability to execute attacks, long-term organizational survival, and the capacity to adapt and continue functioning as an organization rather than just following directives.
- Existence of Formal and Informal Social Systems: E-crime communities possess both formal hierarchies and critical informal social systems. These include natural connections, reputations, and patterns of communication that dictate how things really work, often overriding formal organizational charts. Understanding these informal networks is crucial for identifying key influencers or bottlenecks.
- Specialization and Structure Influence Threat Level: The talk posits that the level of hierarchy, organization, structure, and specialization within a group are critical indicators of its potential to become an advanced persistent threat (APT). However, a crucial caveat is that the "biggest e-crime organization doesn't mean they're the most dangerous to you." A smaller, highly specialized, and resilient group might pose a more significant and persistent threat than a larger, less organized one.
- Goals Driven by Culture and Relationships: While organizations may have stated goals, their actual operations are often governed by "formal or informal or cultural guidelines" that are "often driven by who you know." This highlights the importance of understanding the social fabric and cultural norms within a group, as these can dictate actions and priorities more than explicit mission statements.
These findings collectively suggest that a deep understanding of an e-crime group's internal architecture—its organizational design, social dynamics, and operational resilience—is paramount for developing effective countermeasures that aim for systemic disruption rather than merely temporary technical setbacks.
Technical Deep Dive
▶ Watch: Analytical tools: linguistics, social network analysis, mapping (3:25)
The technical deep dive proposed by Camp and Manatova does not involve traditional cybersecurity technicalities like malware analysis or exploit development. Instead, it focuses on the application of social science methodologies as technical tools to dissect the human and organizational layers of cybercrime. The core tools presented are linguistic analysis, social network analysis (SNA), and organizational mapping. These methods, when applied to available data such as forum posts, chat logs, dark web marketplace interactions, and leaked communications, can provide a "different way to view the threats and risks that you face."
Linguistic Tools form the first pillar of this analytical framework. This involves scrutinizing the language used within e-crime communities to infer internal structures, roles, expertise, and cultural norms. This could encompass:
- Jargon and Slang Analysis: Identifying unique terminology, code words, or technical slang used by group members. The evolution or adoption of specific jargon can indicate specialization, group identity, or shifts in operational focus. For example, specific terms for tools, targets, or payment methods can reveal a group's technical sophistication and operational practices.
- Communication Patterns: Analyzing the style, tone, and formality of communication. Do members use formal requests or informal directives? Is there a consistent communication protocol, or is it ad-hoc? These patterns can hint at established hierarchies, leadership styles, or the presence of informal power brokers.
- Role Inference: Specific vocabulary or phrases might be consistently used by individuals performing certain tasks. For instance, discussions around infrastructure setup might come from a "sysadmin" role, while negotiation tactics might indicate a "ransom negotiator." Linguistic cues can help categorize individuals into functional roles even without explicit titles.
- Cultural Indicators: Language can reveal cultural guidelines, shared values, or unstated rules of engagement within the group. This includes expressions of trust, reputation, conflict resolution, or even humor, providing insights into the group's cohesion and internal governance.
Social Network Analysis (SNA) is the second crucial component. SNA involves mapping the relationships and interactions between individuals within a cybercrime group to uncover its underlying social structure. This goes beyond identifying who knows whom to understand the nature and strength of these connections.
- Node and Edge Representation: Individuals (users, handles, IP addresses) are represented as nodes, and their interactions (messages, transactions, mentions, endorsements) are represented as edges. The direction and weight of edges can indicate the flow of information or influence.
- Centrality Measures: Algorithms like degree centrality, betweenness centrality, and eigenvector centrality can identify key individuals.
- Degree centrality measures direct connections, indicating popularity or communication volume.
- Betweenness centrality identifies individuals who act as bridges between different parts of the network, suggesting critical control over information flow.
- Eigenvector centrality identifies individuals connected to other well-connected individuals, indicating influence.
- Community Detection: Algorithms can group nodes into clusters or communities, revealing subgroups, specialized cells, or factions within the larger organization. These clusters might represent different functional teams (e.g., initial access brokers, ransomware developers, money launderers) or geographically distinct operations.
- Hierarchy Mapping: SNA can reveal both formal and informal hierarchies. While a formal hierarchy might be explicitly stated, SNA can expose the true power dynamics by showing who initiates conversations, who is consistently deferred to, or whose messages carry the most weight. The example of the "Dean's secretary" highlights how a low-ranking formal role can have high centrality in terms of operational workflow.
- Resilience Assessment: By analyzing network topology, defenders can identify critical nodes whose removal would most severely disrupt the organization. A decentralized, highly connected network might be more resilient than a centralized one with single points of failure.
Organizational Mapping integrates insights from linguistic analysis and SNA to reconstruct the functional structure and task management of the e-crime group. This involves:
- Role Assignment: Based on linguistic cues and network position, individuals can be assigned tentative roles (e.g., developer, financier, recruiter, negotiator, infrastructure operator).
- Task Flow Reconstruction: By correlating communication and observed activities (e.g., discussions about specific attack stages), the "attack chain" can be understood as the group's "task management." This helps in understanding who is responsible for what, how tasks are handed off, and where bottlenecks might occur.
- Identifying Specialization: The degree of specialization within the group can be mapped. Highly specialized groups might be more efficient but potentially more vulnerable if a key specialist is removed.
- Goal Discrepancy Analysis: Comparing stated goals (e.g., forum mission statements) with actual operational patterns derived from communications can reveal discrepancies driven by informal guidelines or social dynamics. This helps in understanding the true motivations and priorities that govern the group's actions.
By combining these methodologies, defenders can move beyond a purely technical understanding of cyber threats to a nuanced appreciation of the human and organizational factors that drive cybercriminal resilience. This comprehensive view allows for the identification of not just technical vulnerabilities, but also critical social and organizational weak points that, when exploited, can lead to more lasting disruption.
Demo / Proof of Concept
▶ Watch: Three dimensions of e-crime organizational resilience (5:15)
The talk primarily focused on the theoretical framework and methodological approach for analyzing ransomware gangs as organizations, rather than demonstrating a specific tool or proof of concept. The speakers laid the groundwork for how linguistic analysis, social network analysis, and organizational mapping could be applied to reconstruct the social and organizational structures of e-crime groups. While no live demo was presented, the presentation itself served as a conceptual proof of concept, illustrating the analytical power and defensive implications of this interdisciplinary approach. The emphasis was on the why and what of this analytical shift, setting the stage for future practical applications and tool development in this domain.
Defensive Implications
▶ Watch: Hierarchy, structure, specialization as resilience indicators (8:50)
The organizational lens offered by Camp and Manatova provides profound implications for defensive strategies, moving beyond reactive technical mitigations to proactive, intelligence-driven disruption. Understanding e-crime groups as resilience-maximizing business organizations fundamentally changes how defenders should approach threat management.
- Shift from Technical to Organizational Disruption: Defenders typically focus on disrupting the technical components of an attack chain – patching vulnerabilities, blocking malware, taking down infrastructure. While essential, this talk suggests that such actions may only offer temporary relief if the underlying organization is highly resilient. Instead, efforts should also target the organizational and social structures that enable repeated attacks and adaptation. This means identifying critical roles, communication hubs, and informal leaders whose removal or disruption would cripple the group's ability to coordinate and operate, rather than just forcing them to spin up new infrastructure.
- Strategic Resource Allocation: Not all e-crime groups pose the same level of persistent threat. By applying organizational mapping and resilience analysis, defenders can better assess which groups are truly advanced persistent threats due to their internal structure, specialization, and adaptive capacity. This allows for more strategic allocation of limited defensive resources, prioritizing groups that demonstrate high organizational resilience and pose the greatest long-term danger, even if they are not the "biggest" in terms of attack volume.
- Enhanced Intelligence Gathering: The methodologies presented – linguistic tools, social network analysis, and organizational mapping – become critical intelligence assets. Defenders should actively collect and analyze data from dark web forums, chat logs, and other open-source intelligence (OSINT) to:
- Identify Key Individuals: Pinpoint not just the technical experts, but also the "Dean's secretary" equivalent – individuals who, regardless of formal title, are critical to the organization's daily functioning and cohesion.
- Uncover True Power Dynamics: Distinguish between formal hierarchies and informal influence networks. Understanding who truly drives decisions and controls information flow is crucial for effective disruption.
- Predict Adaptive Behaviors: By observing communication patterns and cultural guidelines, defenders can better anticipate how a group might react to a takedown, a new defense, or internal conflicts, allowing for more proactive counter-measures.
- Targeting Social and Economic Vulnerabilities: Beyond technical vulnerabilities, organizational analysis reveals social and economic weak points. Disrupting trust within a group, exposing internal conflicts, or targeting financial flows that are critical to their internal reward systems can be more effective than simply blocking an IP address. For instance, if a group relies heavily on a specific reputation system for trust, undermining that system could cause internal fragmentation.
- Inform Law Enforcement and Policy: The insights gained from this approach can directly inform law enforcement operations, guiding arrests and prosecutions to target individuals who are most critical to the organization's resilience. It can also shape policy decisions regarding international cooperation, sanctions, and cyber diplomacy by providing a clearer picture of the adversary's operational models and potential points of systemic pressure. Understanding how e-crime groups manage their "tasks" can help law enforcement understand how to disrupt their "operations" effectively.
- Developing Counter-Narratives and Deterrence: A deep understanding of a group's internal culture, motivations, and social dynamics can enable the development of more effective counter-narratives or psychological operations. This could involve sowing discord, reducing trust, or highlighting the risks and low rewards for members, thereby undermining their organizational cohesion and recruitment efforts.
In essence, the defensive implication is a call to adopt a holistic, interdisciplinary approach to cybersecurity. By integrating insights from social sciences with traditional technical expertise, defenders can develop more nuanced, strategic, and ultimately more effective methods for dismantling and deterring cybercriminal organizations, moving beyond merely patching holes to fundamentally weakening the adversary's operational foundation.
Key Takeaways
- E-crime groups are complex, resilience-maximizing business organizations: They are not merely sophisticated individual attackers but structured entities with internal roles, tasks, and social systems designed for long-term survival.
- Understanding social and organizational structures is crucial for effective threat management: Relying solely on technical analysis overlooks critical factors that determine an adversary's persistence and adaptive capacity.
- Linguistic analysis, social network analysis (SNA), and organizational mapping are vital tools: These methodologies provide a non-traditional yet powerful lens for dissecting internal hierarchies, communication patterns, and power dynamics within cybercriminal groups.
- An organization's size does not always correlate with its danger or resilience: A smaller, highly structured, and specialized group might pose a more significant and persistent threat than a larger, less organized one.
- Disrupting informal networks and key individuals can be more effective than purely technical takedowns: Identifying and neutralizing "critical nodes" within the social and organizational structure can lead to more lasting disruption than simply blocking malware or taking down infrastructure.
- The "attack chain" for defenders is the "task management" for attackers: Shifting perspective to understand cybercriminals' operational processes as a business workflow enables more targeted and strategic defensive actions.
About the Speaker(s)
Jean Camp is a distinguished Professor, recognized for her significant contributions to the field. Her expertise and standing are underscored by the honors she has received from prestigious organizations such as IEEE, the ACM (Association for Computing Machinery), and the AAAS (American Association for the Advancement of Science). She brings a deep academic perspective to the study of e-crime, advocating for interdisciplinary approaches to complex security challenges.
Dalia Manatova is a Doctoral Researcher and an Ostrom Fellow at Indiana University. Her work focuses on applying social science methodologies, including discourse and social network analysis, to understand large-scale e-crime organizations. As a doctoral researcher, she contributes cutting-edge academic insights into the structural and social dynamics of cybercriminal groups, aiming to inform more effective threat intelligence and defense strategies.