Circular Image

R.S. van Wegberg

info

Please Note

25 records found

A Comparative Analysis of Attribution in Commercial TI

Attributed cyber threat intelligence (TI) plays an important role in the effective mitigation of cyber attacks. Yet, despite the central role of attribution in policy, practice, and vendor reporting, little is known about the coverage and reliability of attribution by threat intelligence vendors. No study has systematically investigated attribution across a large set of leading TI vendors. We close this gap and provide a longitudinal comparative analysis across 13.5 million IOCs collected over the last 14 years from seven vendors. To compare IOC attribution across vendors, we normalize heterogeneous feeds and reconcile actor names using an evaluated and augmented version of MISP Threat Actor Galaxy (MISP TAG). Next, we address two questions: (i) what is the scope of actor-tracking by vendors, and (ii) how consistent is attribution among vendors? We find that the majority of actors tracked by one vendor are not tracked by the other. Furthermore, IOCs observed by multiple TI vendors are rare (1 %), illustrating that commercial TI feeds, like open-source feeds, primarily provide singleton IOCs. We also find limited overlap in IOCs for jointly tracked actors by two vendors. We measure attribution agreement among vendors with Krippendorff's α. We find mostly moderate agreement among vendors for actor attribution. By contrast, country attribution has high agreement. Our results have implications for actor-centric defenses, compliance, and geopolitical uses of attribution. ...

Understanding Practitioner Challenges in Sector CSIRTs

In this paper, we study the experiences of practitioners in sectoral Computer Security Incident Response Teams (CSIRTs)—specialized teams that mediate between national cybersecurity authorities and the sector constituency. Through interviews with 18 professionals connected to the Informatiebeveiligingsdienst (IBD-CSIRT) for Dutch local governments, we uncover tensions in how key services are valued. For vulnerability notifications, while the CSIRT staff consider them a core service, many constituents hardly mention them, and systemic gaps in information forwarding mean that crucial alerts often never arrive. We extend these insights with 5 interviews across other sector CSIRTs and a validation workshop with 7 participants, all security officers from sector CSIRTs, revealing shared challenges in balancing technical expertise with sector knowledge, building trust-based relationships, and navigating institutional bottlenecks. Our findings contribute the first systematic account of how sector CSIRT professionals understand and perform their role, highlighting the tensions in providing sector-wide support to professionals with differing security needs. ...

Investigating the Effects of the 5th Anti-Money Laundering Directive on Cryptocurrency Exchanges in the Netherlands

By converting between currencies, cryptocurrency exchanges provide access between the traditional and cryptocurrency ecosystem, making them susceptible to money laundering. The European Union extended the scope of the 5 Anti-Money Laundering Directive (AMLD5) to include cryptocurrency exchanges, requiring them to obtain a registration, conduct customer due diligence, and report unusual transactions. It is, however, unknown whether the measures introduced by the implementation of AMLD5 lead to less risk exposure and what impact it has on cryptocurrency exchanges. This paper uses a mixed-methods approach to explore the effects of the Dutch implementation of AMLD5 measures on cryptocurrency exchanges active in the Netherlands. We analyzed over 335,000 transactions and complemented them with seven qualitative interviews with Dutch cryptocurrency exchanges and the supervisory authority. We find that the Dutch implementation of AMLD5 imposed high administrative burdens and substantial fees on relatively small exchanges that do not pose high money laundering risks. This raises questions about the alignment of the goals and consequences of the regulation. ...
Conference paper (2025) - Yin Minn Pa Pa, Yuji Sekine, Yamato Kawaguchi, Tatsuki Yogo, Kelvin Lubbertsen, Rolf Van Wegberg, Michel Van Eeten, Katsunari Yoshioka
In this study, we present a 532-day longitudinal analysis of LockBit 3.0's leak site. We track 1,856 victims across multiple states-countdown, data publication, deletion, and relisting-and reconstruct a structured, three-stage extortion lifecycle: (1) pre-listing negotiation, (2) countdown negotiation, and (3) post-leak monetization. We find that 8.5 % of countdownstate victims are deleted before their data is published, suggesting private settlements. In the post-leak phase, victims with price tags exhibit significantly more variable deletion timing compared to those without, despite sharing the same median exposure. This indicates that LockBit actively manages some listings after data publication, potentially extending monetization or negotiation efforts.We also measure the operational impact of law enforcement actions-including Operation Cronos and affiliate arrests-on LockBit's infrastructure and victim activity. While the group rapidly restored services after takedowns, we observe a sustained decline in new victim onboarding, reduced infrastructure redundancy, and delayed payment behavior, suggesting long-term weakening.To our knowledge, this is the first empirical study to model a ransomware extortion lifecycle based on continuous monitoring of leak site behavior. Our findings provide actionable insights into ransomware monetization tactics, negotiation patterns, and post-takedown adaptation. ...
Intelligence services must balance values such as national security and privacy when collecting data, with each scenario involving specific contextual trade-offs. While citizens benefit from effective intelligence operations, they also risk having their rights infringed upon. This makes citizen perspectives on acceptable data collection for intelligence and national security salient, as their legitimacy is also contingent upon public support. Yet, important aspects of citizen perspectives are understudied, such as the influence of contextual factors related to the use of intelligence collection methods. This study, inspired by Nissenbaum's contextual integrity framework, uses a factorial survey experiment with vignettes among a representative sample of 1423 Dutch citizens to examine the influence of threat type, duration, data subject, collection method, data type, and data retention on public acceptance of surveillance. Additionally, the study considers the impact of respondents' trust and privacy attitudes. The findings reveal significant influence of both contextual variables – particularly threat type, data subject, and data retention – and respondent predispositions – particularly trust in institutions, trust in intelligence services' competence, and privacy concerns for others. The findings imply that more in-depth contextual knowledge among the public may foster support for intelligence activities. ...
Journal article (2024) - Sofie Royer, Jan Jaap Oerlemans, Rolf van Wegberg
The term 'deepfake' refers to artificial or 'fake' content on the internet made using 'deep learning' or 'machine learning' algorithms. This technology was immediately (ab)used to fabricate non-consensual sexual deepfakes involving celebrities and later on not-famous people. In light of the technological advancements and frequent incidents with sexual deepfakes, we assume they are here to stay. As a result, many states confronted with this issue consider the implementation of legislation criminalising sexual deepfakes.In our paper, the authors aim to provide an answer to the question 'How do sexual deepfakes proliferate online, to what extent is the non-consensual production, distribution, possession of, and/or access to sexual deepfakes of adults currently criminalised, and to what extent should it be criminalised in the future?' with a combined empirical and legal approach. To that end, they have conducted an explorative analysis of the online market for sexual deepfakes. The empirical research was focused on Telegram groups, in particular Dutch-language groups, and combined with a legal analysis of the legal frameworks on sexual deepfakes in Belgium and the Netherlands. The research shows that sexual deepfakes proliferate on the clear web and public Telegram groups. Subsequently, the authors have examined to what extent the non-consensual production, distribution, possession of, and/or access to sexual deepfakes are already criminalised and to what extent they should be criminalised. From the legal analysis they conclude that - if there is any positive obligation to criminalise sexual deepfakes of adults at all - it is limited to the production and subsequent distribution of sexual deepfakes of existing people. ...

Why Municipalities Persist in Running Vulnerable Hosts

Many organizations continue to expose vulnerable systems for which patches exist, opening themselves up for cyberattacks. Local governments are found to be especially affected by this problem. Why are these systems not patched? Prior work relied on vulnerability scanning to observe unpatched systems, notification studies on remediating them, and on user studies of sysadmins to describe self-reported patching behavior, but they are rarely used together as we do in this study. We analyze scan data following standard industry practices and detect unpatched hosts across the set of 322 Dutch municipalities. Our first question is: Are these detections false positives? We engage with 29 security professionals working for 54 municipalities to collect ground truth.

All detections were accurate. Our approach also uncovers a major misalignment between systems that the responsible CERT attributes to the municipalities and the systems the practitioners at municipalities believe they are responsible for. We then interviewed the professionals as to why these vulnerable systems were still exposed. We identify four explanations for non-patching: unaware, unable, retired and shut down. The institutional framework to mitigate cyber threats assumes that vulnerable systems are first correctly identified, then correctly attributed and notified, and finally correctly mitigated. Our findings illustrate that the first assumption is correct, the second one is not and the third one is more complicated in practice. We end with reflections on how to better remediate vulnerable hosts. ...
Journal article (2023) - Pieter Hartel, Rolf van Wegberg
Law enforcement agencies struggle with criminals using end-to-end encryption (E2EE). A recent policy paper states: “while encryption is vital and privacy and cyber security must be protected, that should not come at the expense of wholly precluding law enforcement”. The main argument is that E2EE hampers attribution and prosecution of criminals who rely on encrypted communication - ranging from drug syndicates to child sexual abuse material (CSAM) platforms. This statement - in policy circles dubbed ‘going dark’ - is not yet supported by empirical evidence. That is why, in our work, we analyse public court data from the Netherlands to show to what extent law enforcement agencies and the public prosecution service are impacted by the use of E2EE in bringing cases to court and their outcome. Our results show that in cases brought to court, the Dutch courts appear to be as successful in convicting offenders who rely on E2EE as those who do not. Our data do not permit us to draw conclusions on the effect of E2EE on criminal investigations. ...
Journal article (2023) - E. C. Oomens, R. S. van Wegberg, A. J. Klievink, M. J.G. van Eeten
In recent years, the intelligence domain has transformed and become more cyber-oriented. This has been accompanied by governance reforms of intelligence agencies’ powers and oversight mechanisms. However, opinions on key points of these reforms diverge and diverging professional opinions may affect how reforms achieve intended goals. Using Q-methodology, this article identifies and analyses four distinct viewpoints that professionals in the Dutch intelligence community hold regarding intelligence powers and oversight thereof. This study was done in the context of recent reforms in the Netherlands and also considers how views on trust, privacy, and effectiveness play a role. ...

A case study on sentencing high-tech crime in the Dutch criminal justice system

Journal article (2022) - Pieter Hartel, Rolf van Wegberg, Mark van Staalduinen
Open data promotes transparency and accountability as everyone can analyse it. Law enforcement and the judiciary are increasingly making data available, to increase trust and confidence in the criminal justice system. Due to privacy legislation, judicial open data — like court judgements — in Europe is usually anonymized. And even if the court judgement has been made public, the rest of the case file is usually not published. Therefore, the question arises to what extent criminological research into sentencing can make use of anonymized open data. We answer this question based on a case study in which we use the open data of the Dutch criminal justice system that is available on https://www.rechtspraak.nl/Uitspraken. Over the period 2015–2020, we analysed sentencing in 25,366 court judgements and investigated the relationship between sentence severity and the offender’s use of advanced Information and Communication Technology (ICT). The most important results are, firstly, that offenders who use advanced ICT are sentenced to longer custodial sentences compared to other offenders. Secondly, sentencing research with open data is found to be feasible. ...
Conference paper (2022) - Alejandro Cuevas, F.E.G. Miedema, Kyle Soska, Nicolas Christin, R.S. van Wegberg
A number of recent studies have investigated online anony- mous (“dark web”) marketplaces. Almost all leverage a “measurement-by-proxy” design, in which researchers scrape market public pages, and take buyer reviews as a proxy for ac- tual transactions, to gain insights into market size and revenue. Yet, we do not know if and how this method biases results. We build a framework to reason about marketplace mea- surement accuracy, and use it to contrast estimates projected from scrapes of Hansa Market with data from a back-end database seized by the police. We further investigate, by sim- ulation, the impact of scraping frequency, consistency and rate-limits. We find that, even with a decent scraping regimen, one might miss approximately 46% of objects – with scraped listings differing significantly from not-scraped listings on price, views and product categories. This bias also impacts revenue calculations. We find Hansa’s total market revenue to be US $50M, which projections based on our scrapes un- derestimate by a factor of four. Simulations further show that studies based on one or two scrapes are likely to suffer from a very poor coverage (on average, 14% to 30%, respectively). A high scraping frequency is crucial to achieve reliable coverage, even without a consistent scraping routine. When high-frequency scraping is difficult, e.g., due to deployed anti- scraping countermeasures, innovative scraper design, such as scraping most popular listings first, helps improve cover- age. Finally, abundance estimators can provide insights on population coverage when population sizes are unknown. ...
Conference paper (2021) - Tim M. Booij, Thijmen Verburgh, Federico Falconieri, Rolf S. van Wegberg
Dark net markets are a competitive environment. As these anonymous markets enable criminals to trade illicit goods or services, this causes vendors to operate under pseudonyms, rather than real-world identities. The constant battle between market admins and law enforcement makes the typical lifespan of a market two years. When a market disappears, active vendors migrate to other markets with the intention to continue their business, or have already pro-actively done so in an effort to ensure business continuity. To secure their reputation across markets, they can try to obtain the same pseudonym on multiple markets, but other individuals could beat them to the punch. A much safer method therefore, is to generate a PGP-key and use the public key as identification across markets. This way, vendors signal their continued trustworthy and reputable service on markets to buyers. In this paper, we leverage the use of PGP-keys to map careers of dark net market vendors. We parse and analyze scraped data from over 90 dark net markets (2011-2015), and discern 2,925 unique careers. By employing group based trajectory modelling, a type of latent class analysis, we infer three different career trajectories - differentiating ‘established’, ‘challenger’ and ‘failed’ vendor careers. We show that these trajectories are heavily unbalanced in terms of longevity and success. We find that on average 80% of careers last just four months and generate very little sales. Only a small group (∼2%) of highly successful vendors have a long and uninterrupted career that lasts years and spans multiple markets. This group is also responsible for at least 31% of the total revenue in our data. ...
Conference paper (2021) - J.W. van de Laarschot, R.S. van Wegberg
Cybercriminal entrepreneurs on online anonymous markets rely on security mechanisms to thwart investigators in at- tributing their illicit activities. Earlier work indicates that – despite the high-risk criminal context – cybercriminals may turn to poor security practices due to competing business incentives. This claim has not yet been supported through empirical, quantitative analysis on ground-truth data. In this paper, we investigate the security practices on Hansa Mar- ket (2015-2017) and measure the prevalence of poor security practices across the vendor population (n = 1, 733).
We create ‘vendor types’ based on latent profile analysis, clustering vendors that are similar regarding their experience, activity on other markets, and the amount of physical and dig- ital items sold. We then analyze how these types of vendors differ in their security practices. To that end, we capture their password strength and password uniqueness, 2FA usage, PGP adoption and key strength, PGP-key reuse and the traceability of their cash-out. We find that insecure practices are prevalent across all types of vendors. Yet, between them large differ- ences exist. Rather counter-intuitively, Hansa Market vendors that sell digital items – like stolen credit cards or malware – resort to insecure practices more often than vendors selling drugs. We discuss possible explanations, including that ven- dors of illicit digital items may perceive their risk to be lower than vendors of illicit physical items. ...
The COVID-19 pandemic introduced novel incentives for adversaries to exploit the state of turmoil. As we have witnessed with the increase in for instance phishing attacks and domain name registrations piggybacking the COVID-19 brand name. In this paper, we perform an analysis at Internet-scale of COVID-19 domain name registrations during the early stages of the virus’ spread, and investigate the rationales behind them. We leverage the DomainTools COVID-19 Threat List and additional measurements to analyze over 150,000 domains registered between January 1st 2020 and May 1st 2020. We identify two key rationales for covid-related domain registrations. Online marketing, by either redirecting traffic or hosting a commercial service on the domain, and domain parking, by registering domains containing popular COVID-19 keywords, presumably anticipating a profit when reselling the domain later on. We also highlight three public policy take-aways that can counteract this domain registration behavior. ...
Conference paper (2021) - H.L.J. Bijmans, T.M. Booij, Anneke Schwedersky, Aria Nedgabat, R.S. van Wegberg
Off-the-shelf, easy-to-deploy phishing kits are believed to lower the threshold for criminal entrepreneurs going phishing. That is, the practice of harvesting user credentials by tricking victims into disclosing these on fraudulent websites. But, how do these kits impact the phishing landscape? And, how often are they used? We leverage the use of TLS certificates by phishers to uncover possible Dutch phishing domains aimed at the financial sector between September 2020 and January 2021. We collect 70 different Dutch phishing kits in the un- derground economy, and identify 10 distinct kit families. We create unique fingerprints of these kits to measure their preva- lence in the wild. With this novel method, we identify 1,363 Dutch phishing domains that deploy these phishing kits, and capture their end-to-end life cycle – from domain registration, kit deployment, to take-down. We find the median uptime of phishing domains to be just 24 hours, indicating that phishers do act fast. Our analysis of the deployed phishing kits reveals that only a small number of different kits are in use. We dis- cover that phishers increase their luring capabilities by using decoy pages to trick victims into disclosing their credentials. In this paper, we paint a comprehensive picture of the tac- tics, techniques and procedures (TTP) prevalent in the Dutch phishing landscape and present public policy takeaways for anti-phishing initiatives.
...
Doctoral thesis (2020) - R.S. van Wegberg, M.J.G. van Eeten, A.J. Klievink
Many scientific studies and industry reports have observed the emergence of so-called cybercrime-as-a-service. The idea is that specialized suppliers in the underground economy cater to criminal entrepreneurs in need of certain capabilities – substituting specialized technical knowledge with “knowing what to buy”. The impact of this trend could be dramatic, as technical skill becomes an insignificant entry barrier for cybercrime. Forms of cybercrime motivated by financial gain, make use of a unique configuration of technical capabilities to be successful. Profit-driven cybercrimes, as they are called, range from carding to financial malware, and from extortion to cryptojacking. Given their reliance on technical capabilities, particularly these forms of cybercrime benefit from a changing crime paradigm: the commoditization of cybercrime. That is, standardized offerings of technical capabilities supplied through structured markets by specialized vendors that cybercriminals can contract to fulfill tools and techniques used in their business model. Commoditization enables outsourcing of components used in cybercrime - i.e., a botnet or cash-out solution. Thus lowering entry barriers for aspiring criminals, and potentially driving further growth in cybercrime. As many cybercriminal entrepreneurs lack the skills to provision certain parts of their business model, this incentivizes them to outsource these parts to specialized criminal vendors. With online anonymous markets - like Silk Road or AlphaBay - these entrepreneurs have found a new platform to contract vendors and acquire technical capabilities for a range of cybercriminal business models. A configuration of technical capabilities used in a business model reflects the value chain of resources. Here, not the criminal activities themselves, but the technical enablers for all these criminal activities are depicted. To create a comprehensive understanding of how businessmodels in profit-driven cybercrime are impacted by the commoditization of cybercrime, we investigate how outsourced components can fulfill technical capabilities needed in profit-driven cybercrime. This is where we use an economic lens to deliver an overview of criminal activities, resources and strategies in profit-driven cybercrime. In turn, knowing how outsourcing fulfils parts of the value chain, can help law enforcement exploit ‘chokepoints’ – i.e., use the weakest link in the value chain where criminals appear to be vulnerable. ...
Many cybercriminal entrepreneurs lack the skills and techniques to provision certain parts of their business model, leading them to outsource these parts to specialized criminal vendors. Online anonymous markets, from Silk Road to AlphaBay, have been used to search for these products and contract with their criminal vendors. While one listing of a product generates high sales numbers, another identical listing fails to sell. In this paper, we investigate which factors determine the performance of cybercrime products.
To answer this question, we analyze scraped data on the business-to-business cybercrime segments of AlphaBay (2015-2017), consist- ing of 7,543 listings from 1,339 vendors, sold at least 126,934 times. We construct new variables to capture product differentiators and price. We capture the influence of vendor characteristics by identifying five distinct vendor profiles based on latent profile analysis of six properties. We leverage these product and vendor characteristics to empirically predict the performance of cybercrime products, whilst controlling for the lifespan and type of solution. Consistent with earlier insights into carding forums, we identify prevalent product differentiators to be influencing the relative success of a product. While all these product differentiators do correlate significantly with product performance, their explanatory power is lower than that of vendor profiles. When outsourcing, the vendor seems to be of more importance to the buyers than product differentiators. ...
Journal article (2019) - Jan Jaap Oerlemans, Rolf van Wegberg
Book chapter (2019) - Pieter Hartel, Rolf van Wegberg
Online anonymous markets have been around since early 2011 and are aprominent part of today’s cybercrime ecosystem. Their popularity as markets inillicit goods has steadily grown over the years. With the rise ofmarkets like Silk Road, similar marketplaces came into existence where next todrugs, supply and demand of other products and services could meet: rangingfrom physical goods, like passports and weapons, to digital goods and services,like carding and cybercrime software. As a resultwe can witness an increasing supply of criminal product and services onstandardized digital trading platforms in the underground economy. ...
Conference paper (2018) - Rolf van Wegberg, Thijmen Verburgh
In the summer of 2017, an international policing effort - named Operation Bayonet - led by the Federal Bureau of Investigation (FBI) and the Dutch National High Tech Crime Unit (NHTCU) targeted two prominent online anonymous markets. On the one hand, the FBI succeeded in the take-down of AlphaBay, on the other hand the NHTCU took over, operated and shut down Hansa Market. By coordinating these efforts and planning these actions sequentially, both agencies expected users active on AlphaBay to make their way to Hansa Market - which at that moment was in complete control and operated by the NHTCU. To assess the effects of Operation Bayonet, we leverage measurements of the user-base of current market leader, and then safe haven: Dream Market. We investigate the effects of the operation on all newly registered vendors on Dream Market (n=220) during and shortly after Operation Bayonet by mapping their individual and historic characteristics to discern migration patterns and changes in vendor behavior. Compared to ‘simple’ take-downs, like the AlphaBay take-down, the effects of the Hansa Market shut down on vendors seem remarkably different. Vendors do not just simply move on after the Hansa Market shutdown. Few simply migrate, some take precautions like changing their username and/or PGP-key, but many start over with a clean slate - erasing their past reputation completely - and are truly ‘Lost in the Dream’ ...