https://www.securityweek.com/bad-bots-account-for-73-of-internet-traffic-analysis/ SECURITYWEEK NETWORK: * Cybersecurity News * Webcasts * Virtual Events ICS: * ICS Cybersecurity Conference SecurityWeek * Malware & Threats + Cyberwarfare + Cybercrime + Data Breaches + Fraud & Identity Theft + Nation-State + Ransomware + Vulnerabilities * Security Operations + Threat Intelligence + Incident Response + Tracking & Law Enforcement * Security Architecture + Application Security + Cloud Security + Endpoint Security + Identity & Access + IoT Security + Mobile & Wireless + Network Security * Risk Management + Cyber Insurance + Data Protection + Privacy & Compliance + Supply Chain Security * CISO Strategy + Cyber Insurance + CISO Conversations + CISO Forum * ICS/OT + Industrial Cybersecurity + ICS Cybersecurity Conference * Funding/M&A + Cybersecurity Funding + M&A Tracker * Cybersecurity News * Webcasts * Virtual Events * ICS Cybersecurity Conference Connect with us * * * Hi, what are you looking for? [Search ] [Search] SecurityWeekSecurityWeek SecurityWeekSecurityWeek SecurityWeek * Malware & Threats + Cyberwarfare + Cybercrime + Data Breaches + Fraud & Identity Theft + Nation-State + Ransomware + Vulnerabilities * Security Operations + Threat Intelligence + Incident Response + Tracking & Law Enforcement * Security Architecture + Application Security + Cloud Security + Endpoint Security + Identity & Access + IoT Security + Mobile & Wireless + Network Security * Risk Management + Cyber Insurance + Data Protection + Privacy & Compliance + Supply Chain Security * CISO Strategy + Cyber Insurance + CISO Conversations + CISO Forum * ICS/OT + Industrial Cybersecurity + ICS Cybersecurity Conference * Funding/M&A + Cybersecurity Funding + M&A Tracker Cybercrime Bad Bots Account for 73% of Internet Traffic: Analysis The top five categories of Bad Bot attacks are fake account creation, account takeovers, scraping, account management, and in-product abuse. [Kevin-Town] By Kevin Townsend November 16, 2023 * * * * + Flipboard + Reddit + Whatsapp + Whatsapp + Email Evaluating Bot Detection Solutions Arkose Labs has analyzed and reported on tens of billions of bot attacks from January through September 2023, collected via the Arkose Labs Global Intelligence Network. Bots are automated processes acting out over the internet. Some perform useful purposes, such as indexing the internet; but the majority are Bad Bots designed for malicious ends. Bad Bots are increasing dramatically -- Arkose estimates that 73% of all internet traffic currently (Q3, 2023) comprises Bad Bots and related fraud farm traffic. The top five categories of Bad Bot attacks are fake account creation, account takeovers, scraping, account management, and in-product abuse. These haven't changed from Q2, other than in-product abuse replacing card testing. The biggest increases in attacks from Q2 to Q3 are SMS toll fraud (up 2,141%), account management (up 160%), and fake account creation (up 23%). The top five targeted industries are technology (Bad Bots comprise 76% of its internet traffic); gaming (29% of traffic); social media (46%), e-commerce (65%), and financial services (45%). If a bot fails in its purpose, there is a growing tendency for the criminals to switch to human operated fraud farms. Arkose estimates there were more than 3 billion fraud farm attacks in H1 2023. These fraud farms appear to be located primarily in Brazil, India, Russia, Vietnam, and the Philippines. The growth in the prevalence of Bad Bots is likely to increase for two reasons: the arrival and general availability of artificial intelligence (primarily gen-AI), and the increasing business professionalism of the criminal underworld with new crime-as-a-service (CaaS) offerings. From Q1 to Q2, intelligent bot traffic nearly quadrupled. "Intelligent [bots] employ sophisticated techniques like machine learning and AI to mimic human behavior and evade detection," notes the report (PDF). "This makes them skilled at adaptation as they target vulnerabilities in IoT devices, cloud services, and other emerging technologies." They are widely used, for example, to circumvent 2FA defense against phishing. Separately, the rise of artificial intelligence may or may not relate to a dramatic rise in 'scraping' bots that gather data and images from websites. From Q1 to Q2, scraping increased by 432%. Scraping social media accounts can gather the type of personal data that can be used by gen-AI to mass produce compelling phishing attacks. Other bots could then be used to deliver account takeover emails, romance scams, and so on. Scraping also targets the travel and hospitality sectors. Scraping, it must be said, is a legally murky area. It is not specifically illegal; but if it defies a website's published terms of use, it is certainly immoral. There are services that openly offer web scraping facilities. In this case, it demonstrates the relationship between CaaS, AI, and bots (here primarily scraping). Advertisement. Scroll to continue reading. "This is a website you can use to make sure your bots aren't getting prevented by a website," Kevin Gosschalk, founder and CEO of Arkose Labs, told SecurityWeek, referring to a specific provider that will not mention. "You can purchase this software. It has enterprise support and so on. But it is purpose built to commit crime. That is what it does. And there are many other different websites like this, but they look like legitimate businesses. It is a good example of a product purpose built to commit fraud." It is also a good example of crime-as-a-service. Crime-as-a-service enables wannabe criminals who may have the intent but not the skills to engage in cybercrime. "The massive rise of CaaS has completely changed the economics for adversaries" continued Gosschalk. "It's much cheaper to attack companies and the attacks are just better because it's a dev shop that is doing the attacks instead of just individual cybercriminals." The continuing increase in the volume of Bad Bots suggests they remain profitable for the criminals. The arrival of gen-AI will improve the performance of Bad Bots, while the growth of CaaS will increase the number of Bad Bot operators; so, it will get worse. The only solution is Bad Bot detection and mitigation to limit the access of the bots to their human or system targets. If it is not profitable, they won't do it. [Kevin-Town] Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines - from The Times and the Financial Times to current and long-gone computer magazines. More from Kevin Townsend * Bad Bots Account for 73% of Internet Traffic: Analysis * Zip Raises $7.7 Million to Expand SMB Cybersecurity Business * Hacker Conversations: Chris Wysopal, AKA Weld Pond * Top 10 API Security Threats for Q3 2023 * New MacOS Malware Linked to North Korean Hackers * Federal Push for Secure-by-Design: What It Means for Developers * Whistleblowers: Should CISOs Consider Them a Friend or Foe? * The $64k Question: How Does AI Phishing Stack Up Against Human Social Engineers? Latest News * Google Adds Passkey Support to New Titan Security Key * Biden Campaign Looking for CISO * Zimbra Zero-Day Exploited to Hack Government Emails * State-Sponsored Online Spies Likely to Target Australian Submarine Program, Spy Agency Says * Bad Bots Account for 73% of Internet Traffic: Analysis * Administrator of Darkode Hacking Forum Sentenced to Prison * Threat Intel: To Share or Not to Share is Not the Question * Ransomware Group Files SEC Complaint Over Victim's Failure to Disclose Data Breach [SecurityWe] Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. [ ] [Subscribe] Webinar Beyond VPN Replacement: Other ZTNA superpowers CISOs Should Know Tuesday, August 22, 2023 Join security experts as they discuss ZTNA's untapped potential to both reduce cyber risk and empower the business. Register Webinar: Scaling Software Supply Chain Security: Driving Actionable SBOM Management with the OpenSSF S2C2F OSS Specification Thursday, September 7, 2023 Join Microsoft and Finite State for a webinar that will introduce a new strategy for securing the software supply chain. Register Expert Insights Threat Intel: To Share or Not to Share is Not the Question [Marc-Solomon_Bio] To share or not to share threat intelligence isn't the question. It's how to share, what to share, where and with whom. (Marc Solomon) Addressing the State of AI's Impact on Cyber Disinformation/ Misinformation [Rik-Ferguson] By embracing a strategy that combines technological advancements with critical thinking skills, collaboration, and a culture of continuous learning, organizations can safeguard against AI's disruptive effects. (Rik Ferguson) Offense Intended: How Adversarial Emulation Went From State Secret To Board Bullet Point [Tom-Eston-Bishop] Offensive Security does not focus on discreet attacks, singular actors, or Indicators of compromise, but understands the entirety of both sides of the battlefield. (Tom Eston) Narrowing the Focus of AI in Security [Matt-Honea] AI can truly disrupt all elements of the SOC and provide an analyst with 10x more data and save 10x more time than what currently exists. (Matt Honea) DPI: Still Effective for the Modern SOC? [Matt-Wilson_Neto] There has been an ongoing debate in the security industry over the last decade or so about whether or not deep packet inspection (DPI) is dead. (Matt Wilson) * * * * + Flipboard + Reddit + Whatsapp + Whatsapp + Email Related Content Ransomware Alerts Ransomware Alerts Cybercrime Cyber Insights 2023 | Ransomware The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions. Kevin TownsendFebruary 2, 2023 Quantum computing and the cryptopocalypse Quantum computing and the cryptopocalypse Data Protection Cyber Insights 2023 | Quantum Computing and the Coming Cryptopocalypse The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor's algorithm to crack PKI encryption. Kevin TownsendFebruary 2, 2023 Web3 and Metaverse Security Web3 and Metaverse Security Cybercrime Cyber Insights 2023 | The Coming of Web3 As it evolves, web3 will contain and increase all the security issues of web2 - and perhaps add a few more. Kevin TownsendFebruary 6, 2023 Comodo Forums Hacked via Recently Disclosed vBulletin Vulnerability Cybercrime Comodo Forums Hacked via Recently Disclosed vBulletin Vulnerability A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the... Eduard KovacsOctober 1, 2019 Neiman Marcus Says Hackers Breached Customer Accounts Cybercrime Neiman Marcus Says Hackers Breached Customer Accounts Luxury retailer Neiman Marcus Group informed some customers last week that their online accounts had been breached by hackers. Eduard KovacsFebruary 2, 2016 Zendesk Hacked After Employees Fall for Phishing Attack Cybercrime Zendesk Hacked After Employees Fall for Phishing Attack Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company's employees. Eduard KovacsJanuary 24, 2023 Dish Network Dish Network Cybercrime Dish Network Says Outage Caused by Ransomware Attack Satellite TV giant Dish Network confirmed that a recent outage was the result of a cyberattack and admitted that data was stolen. Eduard KovacsMarch 1, 2023 ChatGPT data breach ChatGPT data breach Artificial Intelligence Malicious Prompt Engineering With ChatGPT The release of OpenAI's ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad. Kevin TownsendJanuary 25, 2023 SecurityWeek * * * Popular Topics * Cybersecurity News * Industrial Cybersecurity Security Community * Virtual Cybersecurity Events * Webcast Library * CISO Forum * ICS Cybersecurity Conference * Cybersecurity Newsletters Stay Intouch * Cyber Weapon Discussion Group * RSS Feed * Security Intelligence Group * Follow SecurityWeek on LinkedIn About SecurityWeek * Advertising * Event Sponsorships * Writing Opportunities * Feedback/Contact Us News Tips Got a confidential news tip? We want to hear from you. Submit Tip Advertising Reach a large audience of enterprise cybersecurity professionals Contact Us Daily Briefing Newsletter Subscribe to the SecurityWeek Daily Briefing and get the latest content delivered to your inbox. [ ] [Subscribe] * Privacy Policy Copyright (c) 2023 SecurityWeek (r), a Wired Business Media Publication. All Rights Reserved. Close