Criminal Minds: World’s Most Wanted Cybercriminals Interview Insights

RSA Conference 2024 · Track Session

Overview

This talk, "Criminal Minds: World’s Most Wanted Cybercriminals Interview Insights," presented by Samantha Van Deven, delves into the fascinating and often counterintuitive phenomenon of cybercriminals engaging in public-facing media interviews. Traditionally expected to operate in the shadows, a growing number of threat actors have chosen to step into the limelight, revealing details about their lives, motivations, and operational methodologies. This presentation provides the first comprehensive public research analyzing over 50 such interviews conducted in the last decade, offering a unique sociological and criminological lens into the minds of those perpetrating digital crime.

Watch on YouTube

Visual summary for Criminal Minds: World’s Most Wanted Cybercriminals Interview Insights
Visual summary for Criminal Minds: World’s Most Wanted Cybercriminals Interview Insights

Key moments

  1. 0:00 Cybercriminals engaging in public-facing media interviews
  2. 2:00 Gap in public research on cybercriminal interviews
  3. 2:50 Analyzing crime through the Square of Crime framework
  4. 5:00 Research dataset: 57 interviews, 41 unique actors
  5. 8:00 Cybercriminal demographics and motivation for speaking out
  6. 9:20 Four main categories of cybercriminal media interviews

Criminal Minds: World’s Most Wanted Cybercriminals Interview Insights

Speakers: Samantha Van Deven, Threat Intel

Conference: RSAC 2024

YouTube: https://www.youtube.com/watch?v=00RymKSDIEM

Overview

This talk, "Criminal Minds: World’s Most Wanted Cybercriminals Interview Insights," presented by Samantha Van Deven, delves into the fascinating and often counterintuitive phenomenon of cybercriminals engaging in public-facing media interviews. Traditionally expected to operate in the shadows, a growing number of threat actors have chosen to step into the limelight, revealing details about their lives, motivations, and operational methodologies. This presentation provides the first comprehensive public research analyzing over 50 such interviews conducted in the last decade, offering a unique sociological and criminological lens into the minds of those perpetrating digital crime.

The significance of this research lies in its ability to move beyond simplistic "us vs. them" narratives and provide a more nuanced understanding of the adversary. By systematically categorizing and analyzing the qualitative data from these interviews, Van Deven uncovers patterns in how individuals initiate and persist in cybercrime, their recruitment strategies, professionalization trends, and even their moral considerations. For cybersecurity professionals, these insights are invaluable, enabling a deeper comprehension of attacker psychology, operational security practices, and potential defensive strategies that address not only technical vulnerabilities but also human and societal factors.

Ultimately, this talk argues that understanding the motivations and narratives of cybercriminals, as they choose to present them, is crucial for developing more effective mitigation measures and policies. It highlights how the interplay between law enforcement, adversaries, victims, and the public/media (the "Square of Crime" framework) influences criminal behavior and the broader cybersecurity landscape. By contextualizing these public engagements, the research offers a fresh perspective that can inform proactive defense, enhance threat intelligence, and foster a more adaptive approach to combating cybercrime.

Background

▶ Watch: Cybercriminals engaging in public-facing media interviews (0:00)

For decades, the prevailing expectation has been that cybercriminals operate with utmost secrecy, employing sophisticated operational security (OpSec) to remain anonymous and evade detection. However, the past decade has witnessed a significant deviation from this norm. Samantha Van Deven's research highlights that cybercriminals have engaged in public-facing media interviews more than 20 times after major, attention-grabbing breaches. This shift from the shadows to the limelight, where actors intentionally reveal aspects of their lives, motivations, and operations, presented a gap in public research. While individual articles might analyze specific interviews, a comprehensive, contextual, and chronological analysis of this phenomenon was lacking.

To address this, Van Deven employed a criminological framework known as the Square of Crime. This framework posits that the nature and prevalence of any crime can only be fully understood by analyzing it in the context of the crime itself and its interactions with four key elements: law enforcement (and its agencies), the adversary (the cybercriminal), the targets and victims, and the public and the media. Crime, in this view, is a product of these formal and informal interactions. Understanding why actors engage in certain actions, what makes victims vulnerable, and how public attitudes and media responses influence the landscape are critical components of this framework. Threat actors, in particular, are observed to deliberately and effectively leverage the media, often shaping narratives in response to headlines or public perception.

The research was based on a substantial dataset of 57 total interviews from 41 different unique actors across 29 media organizations. Notably, nine repeat actors were identified, indicating that some criminals perceived the benefits of public engagement to outweigh the inherent risks. Key criteria for inclusion in the study were:

  1. Public-facing written media articles: This excluded leaked internal communications (like the Conti leaks), focusing solely on content the actors intended for public consumption.
  2. Knowingly participated: The actor willingly engaged in the interview.
  3. Legitimacy substantiated: Interviewers took steps to verify the identity and authenticity of the interviewee.

The interviewees represented a diverse cross-section of the cybercriminal ecosystem, including malware and exploit developers, initial access brokers, and ransomware affiliates, operators, and admins. Interestingly, all interviewees who identified their gender were male, although the geographical distribution was varied, with actors self-identifying from multiple countries. Demographic factors indicated a relatively young age range (teens, 20s, 30s), with many leading seemingly normal lives, having attended top colleges, or working in legitimate IT jobs, underscoring the broad appeal and accessibility of cybercrime.

Interviews were categorized into four temporal phases, with the latter two being the most prevalent and increasing over time:

  • Post-arrest: Interviews conducted after apprehension, discussing reflections on their activities and morality.
  • Post-retirement: Individuals indicating a voluntary cessation of activities without consequence.
  • Post-breach: Actors speaking specifically about a single intrusion or event that made headlines, often to respond or clarify.
  • Brand Building: Interviews focused on discussing their name, operations, and opportunities, sometimes referencing major intrusions but not limited to a single event. This category showed consistent and increasing activity over the decade.

To systematically analyze the qualitative data, the interviews were collected, chronologically ordered, and then categorized into 12 distinct themes:

  1. Demography: Characteristics like age, country, and legitimate employment.
  2. Initiation: Why they first got involved in cybercrime.
  3. Persistence: Why they continued despite risks.
  4. Exiting: Reasons for leaving or wanting to leave the underground.
  5. Recruitment: Direct statements about attracting new members.
  6. Professionalization: Mimicking traditional economy structures (division of labor, specialization).
  7. Setting the Record Straight: Correcting perceived misinformation or shaping their narrative.
  8. Square of Crime: Discussions related to interactions with law enforcement, victims, or media.
  9. Morality and Sentiment: Emotionally charged discussions about good/bad, fear, confidence, excitement.
  10. Tactics, Techniques, and Procedures (TTPs): Operational details, often mapped to the MITRE ATT&CK framework.
  11. Security Recommendations: Advice offered by actors themselves on how to prevent future attacks.
  12. Continuation of Illicit Activity: Factors that drive sustained engagement.

This rigorous methodology allowed for a detached analysis, minimizing bias and increasing the validity and transparency of the findings, providing a crucial understanding of the evolving landscape of cybercrime.

Key Findings

▶ Watch: Analyzing crime through the Square of Crime framework (2:50)

The comprehensive analysis of cybercriminal interviews revealed several profound insights into the motivations, operations, and self-perception of these actors. These findings challenge conventional assumptions and offer a more granular understanding of the adversary.

One of the most striking findings was the prevalence of self-taught skills. A significant 22% of all interviewed actors discussed being self-taught, frequently referencing online video tutorials, training guides available on both the surface and dark web, and emphasizing "learning by doing." Many possessed educational backgrounds in relevant disciplines or had transitioned from legitimate IT work, leveraging transferable skills. Their continuous learning focused on topics such as pen testing, programming in various languages, cryptology, SQL and XSS injections, remote and local file inclusion (RFI/LFI) attacks, open source intelligence (OSINT), and underground intelligence gathering. This highlights the accessibility of technical knowledge that underpins sophisticated cyber operations.

The initiation into cybercrime was often driven by a confluence of socio-economic factors and personal circumstances. Common triggers included layoffs, leaving individuals with valuable skills but no legitimate employment; medical debt that seemed insurmountable; or a general feeling of being "stuck" with limited opportunities in the traditional economy. Beyond financial desperation, curiosity and a willingness to learn, coupled with the realization of the potential lucrativeness, also served as significant entry points.

Persistence in illicit activity was attributed to powerful psychological and tangible rewards. The concept of variable rewards, akin to principles seen in gaming or gambling, proved highly influential. The thrill of achieving desired outcomes, such as unexpectedly deep access into a network or the eventual success after multiple failures, created a powerful feedback loop. Beyond the initial rush, subsequent factors included a profound sense of power and influence, derived from seeing their actions make headlines and directly correlating their efforts with significant financial profits. The freedom from the traditional job market – offering seniority, flexible hours, remote work, and the promise of self-determined retirement – was a strong draw. This translated into tangible social mobility, with actors recounting journeys from poverty ("not eating for days") to becoming millionaires, providing a powerful sense of self-actualization and capability.

Recruitment emerged as a very common theme, with actors actively promoting the idea that "anyone with curiosity and determination can do it." They often sought new and younger affiliates whom they could mentor, looking for individuals with technical savviness and bright minds that might be overlooked by the traditional economy. They frequently bashed the 9-to-5 model, citing bureaucracy, lack of flexibility, and inadequate compensation as reasons to join the cyber underground. Recruitment pitches often highlighted the immense financial potential, attractive profit-sharing ratios, and direct payments to cryptocurrency wallets. Groups would often tout higher retention rates and emphasize collective decision-making, though managing members was frequently cited as difficult, leading to the "firing" of untrustworthy individuals and a preference for keeping groups small.

Targeting strategies were primarily driven by revenue and location, with a focus on large organizations due to the perceived ease of obtaining ransomware payments and navigating complex networks compared to smaller entities. Actors assessed targets' worth by leveraging stolen information found on the dark web, analyzing previous breaches, or acquiring insider information directly from compromised organizations. They also engaged in extensive open source intelligence (OSINT), staying current with cybersecurity developments to weaponize new research and vulnerabilities in their attacks.

The concept of professionalization was evident in the sophisticated organizational structures adopted by many groups. This included specialized and divided labor, with highly skilled hackers focusing on database intrusions while less skilled individuals swept compromised accounts for valuable data. Governance models, such as voting systems for target selection, further illustrated this maturity. Rapid communication and a relentless dedication to the bottom line underscored their profit-driven nature, with information on tactics and techniques frequently exchanged to maximize financial gain.

A recurring and intriguing theme was "setting the record straight," where actors actively sought to correct perceived inaccuracies in media reports or to shape their own narrative. This desire for narrative control highlights the strategic importance of public perception for these groups. Similarly, discussions around morality and sentiment revealed a complex internal landscape. While some actors were divided between scaling up operations and leaving the underground entirely, targeting hospitals and government entities was consistently one of the most divisive topics, with many affiliates explicitly prohibited from engaging in such attacks. The anonymity and depersonalization afforded by operating behind a screen often contributed to a perceived lack of remorse, reducing the "burden" by rationalizing that if they didn't commit the crime, someone else would.

Finally, the analysis underscored that trustworthiness is the most powerful currency in the cyber underground. Cybercriminals actively aspire to demonstrate their reliability to potential victims and future affiliates. Building a searchable online presence and a strong brand through interviews was seen as a rational investment to boost reputation, recruit more members, and increase the likelihood of obtaining future ransomware payments.

Technical Deep Dive

▶ Watch: Research dataset: 57 interviews, 41 unique actors (5:00)

The interviews provided valuable, albeit sometimes high-level, insights into the Tactics, Techniques, and Procedures (TTPs) employed by cybercriminals, offering a glimpse into their technical operations. While not always detailing specific exploits, the discussions revealed common approaches and tools.

For initial access, actors commonly leveraged zero-day vulnerabilities and exploited human nature through social engineering attacks. This dual approach highlights a sophisticated understanding of both technical and psychological vectors. In terms of reconnaissance and network exploration, specific scanning tools were frequently mentioned, including Masscan, Nmap, and RustScan, used for efficient port and network discovery. This indicates a reliance on widely available, effective tools, often complemented by custom enhancements.

Resource development was depicted as a collaborative and continuous process. Actors emphasized the importance of collaborating with other groups and maintaining as many trustworthy contacts as possible, often through platforms like Telegram channels. These networks facilitated the exchange of favors, information, and tools. While they often used existing red teaming tools, interviewees frequently noted that they developed custom additions or modifications on top of these tools, crafting them to better suit their specific operational needs or to fill perceived gaps. This "bits and pieces" approach to tool development suggests an adaptive and pragmatic engineering mindset.

The concept of professionalization extended deeply into technical operations. Groups often exhibited a clear division of labor based on skill sets. The most technically skilled hackers were typically responsible for gaining initial access, exploiting critical vulnerabilities, and penetrating deep into databases. In contrast, less skilled individuals might be tasked with "sweeping up" valuable data from already compromised accounts, or managing the exfiltration process. Individuals with minimal technical experience might be assigned roles focused on monetization or support, underscoring a hierarchical yet efficient operational model. This specialization allowed groups to scale their operations and maximize profit by optimizing the use of diverse talent.

Furthermore, open source intelligence (OSINT) was highlighted as a critical technical practice. Cybercriminals were described as avid consumers of security news and research, diligently staying up-to-date with the latest cybersecurity developments and vulnerabilities. They then actively weaponized this research for their attacks, integrating newly discovered flaws or techniques into their arsenal. This constant learning and adaptation demonstrate a proactive technical posture, mirroring the continuous learning expected of legitimate security professionals. The mention of actor-supplied security reports to ransomware victims further illustrates their technical understanding. These reports, often detailing how they breached the environment and providing mitigation recommendations, were sometimes framed by actors as a way to "teach companies how to properly secure their data," blurring the lines between criminal activity and perverse "security auditing."

Demo / Proof of Concept

▶ Watch: Cybercriminal demographics and motivation for speaking out (8:00)

The presented talk focused on a qualitative research analysis of existing interviews and did not include a live demonstration or a proof of concept of any specific cybercriminal tools or techniques. The content was entirely based on the synthesis of information gathered from the collected interview data.

Defensive Implications

▶ Watch: Four main categories of cybercriminal media interviews (9:20)

The insights gleaned from interviewing cybercriminals offer a critical advantage for defenders, shifting the focus from purely technical countermeasures to a more holistic understanding of the adversary. By comprehending their motivations, learning methods, and operational structures, organizations can develop more effective and adaptive defensive strategies.

Firstly, understanding that cybercriminals are predominantly self-taught and rely heavily on online tutorials, blogs, and videos (both surface and dark web) is paramount. Defenders should proactively engage with these same learning materials. Conducting digital footprint assessments from an attacker's perspective, scanning your own environments with tools like Masscan, Nmap, and RustScan as hackers do, is crucial. Security teams should be encouraged to get their "hands on the training materials that they're using" to truly understand their mindset and identify potential attack vectors they might exploit. This continuous learning, extending beyond industry certifications to include open-source intelligence and self-directed research, is vital for keeping pace with evolving TTPs.

Secondly, the emphasis on threat intelligence cannot be overstated. Cybercriminals are "avid consumers of security news" and rapidly weaponize newly discovered vulnerabilities and research. Organizations must ensure their security teams are equally diligent in staying up-to-date on the latest trends, vulnerabilities, and attack methodologies. This includes active participation in Information Sharing and Analysis Centers (ISACs) and other threat intelligence sharing communities, as well as conducting internal research to anticipate and mitigate emerging threats.

Thirdly, the findings have significant implications for security awareness training. The talk highlights the "power of the narrative" and the increasing commonplace nature of cybercrime in public discourse. Instead of abstract concepts, security awareness programs should leverage real-world examples and stories from headlines or ISAC reports. By telling compelling stories of breaches and their consequences to employees, friends, and family, and explaining mitigation steps in simple, relatable terms, organizations can foster greater engagement. The goal is to convey responsibility from a place of knowledge and confidence, trusting employees to implement basic practices like using password managers and enabling two-factor authentication (2FA), rather than instilling fear. Making employees feel "part of the solution" can significantly increase the uptake of security best practices.

Finally, the research underscores the importance of workforce management and employee well-being as a defensive measure against insider threats. The motivations for initial engagement in cybercrime often stem from disillusionment, disenfranchisement, or financial hardship (e.g., layoffs, medical debt). The dark web actively advertises for insiders, particularly code developers and AI experts, offering "quick extra cash opportunities." Organizations must prioritize rewarding talent, supporting employees, acknowledging contributions, and fostering a positive work environment to attract and retain skilled individuals. Addressing these socio-economic factors can significantly reduce the likelihood of employees turning to illicit activities, thereby mitigating a critical attack vector that cybercriminals actively exploit. By injecting these human-centric solutions into the "Square of Crime" framework, defenders can build more resilient and comprehensive security postures.

Key Takeaways

  • The "Square of Crime" in Action: Interactions between cybercriminals, victims, law enforcement, and the media significantly influence criminal behavior, including decisions to persist in or disengage from illicit activities. Understanding this interplay is crucial for holistic defense.
  • Socio-Economic Drivers: Factors like relative deprivation, lack of legitimate opportunities, and financial pressures (e.g., layoffs, medical debt) are strong initial motivators for individuals to engage in cybercrime, highlighting a need for societal solutions beyond technical ones.
  • Trustworthiness as Currency: In the cyber underground, trustworthiness is paramount. Cybercriminals actively cultivate a brand and reputation through public interviews to boost credibility, recruit affiliates, and increase the likelihood of obtaining ransomware payments.
  • Self-Taught and Adaptive Adversaries: Cybercriminals are often self-taught, leveraging online resources and continuously learning new TTPs. They are avid consumers of security news, rapidly weaponizing vulnerabilities and research, necessitating continuous learning and an "adversary mindset" for defenders.
  • Human-Centric Defense: Effective defense requires leveraging real-world narratives in security awareness training to make cybersecurity relatable and actionable. Additionally, fostering a supportive and rewarding workforce environment is critical to mitigate insider threats and prevent skilled individuals from turning to the dark web.
  • Beyond Simplistic Narratives: Moving past "us vs. them" ideologies and acknowledging the complex factors influencing cybercriminal engagement allows for more nuanced and effective policy development and mitigation strategies.

About the Speaker(s)

Samantha Van Deven is a professional working in Threat Intel. Her research and presentation at RSAC 2024, "Criminal Minds: World’s Most Wanted Cybercriminals Interview Insights," reflects her expertise in analyzing cybercriminal behavior and understanding the broader landscape of cyber threats. The presentation represents her personal insights and not necessarily those of any organization she is affiliated with.

All talks from RSA Conference 2024