Chapter 17: Cybercrime
Swanson: Criminal Investigation, 13e
IM-17 | 1
Chapter 17
Cybercrime
Objectives
1. Distinguish between computer-assisted crimes and cybercrimes.
2. Identify the two prerequisites for the emergence of cybercrime.
3. State six advantages cybercriminals have over traditional criminals.
10. Describe the use of scareware.
11. Contrast polymorphic and metamorphic viruses.
12. Explain the use of ransomware and a rogue program called CryptoLocker.
Introduction
Computer-assisted crime, such as identity theft, is discussed in Chapter 15, Larceny/Theft and
White-Collar Crime. In the crime of identity theft, the computer is a tool used to assist in the
topics.
Lecture Notes
Chapter 17: Cybercrime
Swanson: Criminal Investigation, 13e
IM-17 | 2
I. Cybercrime: An Overview
Cybercrimes, which are crimes that can either target or use a computer, a computer network, or
a networked device as a means to commit an illegal act, can impact average people, massive
corporations, national security, public utilities, election securityand can wreak havoc on
economies. This wide-ranging crime is a very costly one: it is estimated that cybercrimes caused
A. The Evolution of Cybercrime: From Teenage Hackers and Script Kiddies to
Sophisticated Criminal Organizations, International Espionage, and Cyber Terrorism
Cybercrime is an evolved state of traditional crime; it continues to mature in complexity as
well as sophistication. In the early years (1970s through 1990s), cybercriminals would direct
their attacks at consumer computers or corporate networks, conducting a myriad of
Organized crime is defined by the FBI as “any group having some manner of a formalized
structure and whose primary objective is to obtain money though illegal activities. Further,
such groups maintain their position through the use of actual or threatened violence, corrupt
public officials, graft, or extortion, and generally have a significant impact on their locales,
region, or the country as a whole.” Attack methods and examples included the following:
One of the most fascinating, complex, and dangerous realms of cybercrime occurs as part of
the deep web, a vast part of the World Wide Web not accessible through regular Internet
Chapter 17: Cybercrime
Swanson: Criminal Investigation, 13e
IM-17 | 3
Most of the information in the deep web is hidden and encrypted with a unique application
called Tor. Because users of the deep web use Tor, another synonym for the deep web is the
Tor net or Tor Network. This secretive online world remains mostly untraceable and difficult
Cyber terrorism or digital terrorism are two terms often used interchangeably and can be
defined as the premeditated, politically or ideologically motivated attack against information
II. Cybercrime Tools and Services Related to Theft and Fraud
Cybercrime tools and services are being mass marketed on the Internet. They are found on
publicly accessible web forums, such as Internet Relay Chat (IRC) as well as on the Deep Web;
the major vendors are principally located in Russia, Eastern Europe, and Malaysia.
III. Offenders
Most computer enthusiasts of the 1970s hacked into computers out of curiosity or for excitement.
Today, the overwhelming motive is for financial gain. Hackers/crackers who use their skills to
malicious or criminal intent of a black hatter, are often called gray hatters.
IV. Computer Intrusions
Computer intrusions are accomplished by the use of malware, a term derived from combining
Chapter 17: Cybercrime
Swanson: Criminal Investigation, 13e
IM-17 | 4
malicious and software. Malware is intended to (1) deny use of computers; (2) covertly gain
control over computers; (3) secretly access or intercept computer data; and (4) subvert the
operation of computers for personal profit.
This section addresses common malware intrusions; there is some inherent overlap in these
categoriesfor instance, an infostealer Trojan horse can also be categorized as spyware.
Botnets: A “herder” (“botmaster”) uses malware to hijack hundreds to tens of thousands
of computers and is able to remotely control them all, including the ability to update the
malware and to introduce other programs such as spyware. Hijacked computers are called
made possible by exploiting web browser vulnerabilities.
Viruses: At any one time, there may be as many as 16,000 viruses floating around. The
primary purpose of a virus is to replicate as many times as possible and to cause as much
mischief or damage as possible. A polymorphic virus, such as Virut, encrypts its replicant
Time, logic, and email bombs: A time bomb is programmed to “go off” at a particular time
or date, such as April Fool’s Day, Halloween, or Friday the 13th. A logic bomb is
“detonated” when a specific event occurs—for example, all personnel records are erased
when an electronic notation is made that a particular person was fired. Email bombs are
Ransomware: Also known as a cryptovirus, ransomware holds the data on a computer or
the use of the computer hostage until a payment is made.
Chapter 17: Cybercrime
Swanson: Criminal Investigation, 13e
IM-17 | 5
Spyware: Spyware is a broad term that sometimes is used to mean the same thing as
malware but more narrowly is thought of as a surveillance tool, such as the infostealer
form of a Trojan horse. A keystroke logger, referred to as a keylogger, may be the most
common form of spyware. A keylogger secretly “harvests” every keystroke that a
computer user makes and thus steals sensitive data for profit.
Rootkits: A rootkit gives an attacker “super powers” over computers—for example, the
ability to steal sensitive personal information or engage in cyber warfare or cyber
espionage.
A. Mobile Devices
A mobile device is a term used to describe any small computer device, typically small enough
to be held in the hand. Today’s mobile devices include media players, notebook computers,
and computer tablets, such as those manufactured by Samsung, Sony, HTC, LG, Motorola,
V. Investigation of Cybercrimes
A. Federal Efforts
The FBI and the U.S. Secret Service (USSS) play prominent roles in investigating computer-
assisted crimes and cybercrimes. The USSS has established Electronic Crimes Task Forces
Chapter 17: Cybercrime
Swanson: Criminal Investigation, 13e
IM-17 | 6
(ECTFs) in approximately 39 cities across the country, bringing together the expertise of
federal, state, and local agencies and representatives from industry and the academic
B. State and Local Efforts
Computer/cyber/high-technology/electronic crime units are commonly found in all larger
municipal and county agencies, although their mission, expertise, and capabilities vary
C. Legal Considerations
Federal laws pertaining to computer-assisted and cybercrimes are comprehensive, although
the corresponding state statutes vary in their sophistication and breadth.
D. Consent Searches
The general rule for consent searches is that the police can rely on a person’s actual
VI. The Crime Scene
A. Computer and Peripheral Evidence
Important evidence may be associated with many items, including tablets, computer
B. Crime Scene Processing
If the resources are available, trained and experienced computer investigators are the best
Chapter 17: Cybercrime
Swanson: Criminal Investigation, 13e
IM-17 | 7
choice for processing a cybercrime scene. In many jurisdictions this option may not exist, and
so the first responding officer will have that responsibility.
The investigator should take the following steps while securing and evaluating a cybercrime
scene:
Remove and exclude all persons from the area where evidence is to be collected.
mode.
If the computer is on, check the display for signs that files are being deleted or
overwritten, such as the words delete, format, remove, destroy, copy, move, or wipe.
If the destruction of evidence is not a concern, the immediate disconnection of power is
not recommended because information, data, and images of apparent evidentiary value
may be seen on the screen and photographedfor instance, financial documents, child
pornography, identities of coconspirators/other suspects, text documents, or chat rooms
used.
In addition to other information, the following information should be established by the
investigator:
Who owns the computers?
Who uses the computer and its related devices? What are their login names and user
account names?
Chapter 17: Cybercrime
Swanson: Criminal Investigation, 13e
IM-17 | 8
The steps to be taken when documenting the cybercrime scene are as follows:
Both in the report and by video and photography, identify the location, type of devices,
their condition, and power status. Get views of all sides, including the backs, where
cables are attached.
Record all activity and processes visible on the monitor.
Tag every cable as to where each end was attached.
Document and photograph every wireless device in the locations at which they were
found.
Document and photograph the locations of related evidence, such as printed pages of
Internet addresses, financial records, images, computer code, GPSs/maps/directions,
The following steps should be taken when collecting and transporting computers and related
devices:
Remove batteries from laptops and place tape over the power switch on all computers
and associated devices.
Place all digital evidence in antistatic packaging; do not use regular plastic bags or
other containers that can produce static electricity and condensation, both of which can
Chapter 17: Cybercrime
Swanson: Criminal Investigation, 13e
IM-17 | 9
The area of digital forensics is highly technical and should be left only to those individuals
trained and qualified in this specific area. Most data in criminal cases is derived from storage
forensics, that is, data and information retrieved from physical media connected to a
analysis. This process is easier to understand if one keeps in mind the need to verify that the
drive analyzed has not been contaminated or altered since it was seized from the suspect
(called the evidence drive):
Step 1 is to verify mathematically the contents of the evidence drive.
Step 2 is to create an exact “image,” or bit stream copy, of the evidence drive, again,
performed by the forensic software package.
In the last 5 years, several “triage” programs have been developed to assist the investigator at
the scene, particularly involving mobile devices (computer tablets and/or smartphones).