Bad Bots and the Commoditization of Online Fraud

Bad Bots and the Commoditization of Online Fraud
Bad Bots and the Commoditization of Online Fraud

Bots and Their Uses in Online Scams and Fraud

Fraudsters will stop at nothing to exploit your websites and your customers,

and with the rapid shift to digital payments, online fraud has never been more profitable. This shift, driven by the pandemic,

truly gained momentum in 2021 as digital payments surged in popularity.In fact, compared to 2020, online payments doubled in 2021, growing by 104%. Add to that the reality that the average person has more than 100 online accounts, many of which have stored payment methods, and this has created a perfect playground for bad actors.

 

With an abundance of online accounts and transactions to attack, the techniques bad actors devise to commit online fraud are constantly evolving to maximize profits. One of the most concerning new strategies is the automation of online fraud operations. Let's take a look at some forms of automated online fraud that use bad bots.

 

Account Takeover Fraud

The most common fraudulent attack that uses bots is Account Takeover (ATO). ATO is a form of digital identity theft in which bad actors attempt to gain unauthorized access to user accounts belonging to someone else.

This attack is automated through brute force techniques, particularly credential stuffing. This technique exploits a key weakness among many online account users – password reuse across multiple websites. At least 65 percent of people reuse their passwords across multiple sites, meaning that once their credentials are compromised, all their accounts using the same password are also at risk of account takeover fraud.

It has become very easy for attackers to obtain dumps of leaked credentials online. When you combine that with the ease of access to bot infrastructure and the financial incentives behind user accounts, you can see why this attack vector has become popular and lucrative.

Any online business that uses a login page is at risk of account takeover fraud. If there is money to be made by taking over user accounts on their website,

that risk is even higher. Businesses should expect bots to relentlessly find their way to their websites through thousands of login requests around the clock, seven days a week.

Successful account takeover attacks can have a significant negative impact on customers: account lockouts, financial fraud, theft of personal information, and much more.

This impact also transfers to the business in the form of increased customer support costs, revenue loss, customer churn, damaged reputation, the risk of non-compliance with data privacy regulations, and more.

Bad actors attempting to take over employee accounts are another business risk. Using compromised employee credentials, attackers can gain access to the corporate network and deploy malware or steal sensitive data to orchestrate a more sophisticated attack on the company and its broader supply chain.

 

New Account Fraud

In this type of online fraud, bad actors use bots to automate account creation so it can be done at scale, creating an army of fake user accounts at their disposal.

Attackers can use these accounts to commit various forms of online fraud; from spam comments and inflated propaganda to promotion abuse (new user offers) and money laundering.

 

 

Credit Card Fraud

There are two methods that exploit bots in credit card fraud: card cracking and carding. Card cracking relies on the assumption that credit card information with cardholder names and primary account numbers is readily available on the dark web.

However, card-not-present fraud also requires the cardholder's CVV number, expiration date, and zip code. In this technique, a bot will spread its guesses across multiple websites, identifying these missing pieces of information within seconds. Afterward,

armed with legitimate card numbers, fraudsters can purchase products online and ship them anywhere in the world.

Carding occurs when criminals run thousands of small purchases using stolen credit card numbers in order to verify them, and then resell the verified card information to organized crime rings at a much higher price.

This results in bad merchant history, chargeback penalties, and worse. Like most transaction fraud, carding has become easier than ever – there are even step-by-step tutorials available online.

Credit card fraud damages the fraud score of affected businesses and increases customer service costs for processing fraudulent chargebacks.

It may also negatively affect conversion rates due to trust issues with credit card companies that require additional verification.

 

 

Gift Card Fraud

With the type of online fraud known as gift card cracking or gift card enumeration, bots are used to scan gift card balance pages to find gift card numbers

that contain unused balances. These can then be sold on the dark web for easy profit. GiftGhostBot is an example of this type of fraud.

 

 

Spam

Bad bots are used to heavily flood the internet with spam comments that can lead to numerous fraudulent schemes.

One example was uncovered by Threat Research in the early days of the pandemic, where bots were used to spread fake news and lure unsuspecting users to suspicious online pharmacies.

 

The Role of Client-Side Attacks in Online Fraud

A recurring feature of some automated fraud attacks is their reliance on compromised user credentials and payment information. This is where client-side attacks come into play.

Client-side attacks, also known as Magecart attacks, involve injecting malicious JavaScript into first-party code or into third-party service code (the supply chain) used on legitimate websites.

This allows fraudsters to collect sensitive personal information directly from the customer every time the customer enters their information into an online form on one of those websites.

As an example, consider a login page. A user may type in their credentials and click “Login” and successfully access their account.

What the user does not know is that at the same time, their credentials were also sent to a deceptive third party, essentially compromising them.

So fraudsters have not only been able to automate their attacks, but they have also been able to enhance them by feeding themselves information that is often obtained by abusing the same website functions – in this example, the login page.

The very same page that can later be abused by bad bot programs performing credential stuffing to break into user accounts.

It is critically important to understand that client-side attacks are data breaches for all intents and purposes. As such, the risk of non-compliance with PCI, GDPR, CCPA, and other data privacy regulations is very real. In recent years,

companies have been fined millions of dollars following breaches of sensitive user information on their websites that were compromised in Magecart attacks.

 

Bots and Their Uses in Online Scams and Fraud

 

Prevent Online Fraud

A proactive approach to preventing automated online fraud begins with good web application security hygiene. A web application and API protection (WAAP) suite

bundles the best solutions that protect your business from the edge to the database, including the key components necessary to prevent fraud:

Advanced Bot Protection protects web applications, mobile apps, and APIs from all automated threats without impacting business-critical traffic flow.

It continuously monitors internet traffic to protect every aspect of your web applications against any attempt at fraudulent activity.

By inspecting every request in real time, it determines whether it is a malicious bot, then blocks the request entirely if it is. Afterward, machine learning algorithms recognize legitimate traffic patterns to identify dangerous anomalies.

If necessary, stricter settings can be activated across critical attack vectors, such as account registration forms and login screens.

It uses a sophisticated combination of browser and JavaScript checks, device-based rate limiting, behavioral analytics, and biometric validation to stop automated online fraud.

Account Takeover Protection reduces account-based fraud by blocking automated access to credential authorization operations while providing clear visibility and context for fraud resolution.

Intuitive dashboards include vital information for fraud prevention and investigation, such as the locations and user accounts under attack, the methods used,

whether credentials are publicly available, and the number of successful account logins.

Client-Side Protection mitigates the risk of your customers' most sensitive data falling into the hands of bad actors.

It prevents supply chain fraud from client-side attacks such as formjacking,

Magecart, and other online skimming attacks. The Client-Side Protection feature automatically scans for existing and newly added services on your site,

limiting the risk of them becoming a blind spot for your security team.

The solution empowers your security team to easily determine the nature of each service and block any unauthorized service.

Read also:

Social Media Campaigns Calling for Unlimited Internet in Egypt
DDoS Brute Force Attacks – Hackers Escalate DDoS Attacks as Part of International Cyber Warfare Strategy
The Concept of Social Engineering Practiced on You Almost Daily on the Web and Social Media Platforms