Security News > 2023 > September > Cybercriminals use research contests to create new attack methods

Cybercriminals use research contests to create new attack methods
2023-09-01 04:00

Adversary-sponsored research contests on cybercriminal forums focus on new methods of attack and evasion, according to Sophos.

The contests mirror legitimate security conference 'Call For Papers' and provide the winners considerable financial rewards and recognition from peers and also potential jobs.

As outlined in Sophos X-Ops latest report these contests are designed to drive innovation, and when analyzed, the entries provide invaluable insight into how cybercriminals attempt to overcome security obstacles.

Early cybercrime contests involved trivia quizzes, graphic design competitions and guessing games.

Sophos X-Ops explored two prominent annual contests: one run by the Russian-language cybercrime forum Exploit, offering a total prize fund of $80,000 to the winner of its contest in 2021, and another run on the XSS forum, with a prize pool of $40,000 in 2022.

In the most recent contests, Exploit themed its competition around cryptocurrencies, while XSS opened its contest up to a range of topics from social engineering and attack vectors to evasion and scam proposals.


News URL

https://www.helpnetsecurity.com/2023/09/01/cybercriminal-forums-contests/