SEXTORTION PRESENTATION: NOCON 2014

31/10/2014
|

This morning, the first presentations of the NOCON 2014 Security Congress took place. This year, we were fortunate enough to present our study on Sextortion: Personal Impact, Professional Consequences, co-presented by Ruth Sala from Legal Consultors and myself, Selva Orejón, from onbranding and Brand Care.

The cases presented were all real and analyzed by our cyber-investigation, cybersecurity, reputation, and digital crisis team, as well as our legal analysis department.

The objective of this presentation was to convey the findings of the attack in which we analyzed the common denominators among all incidents. We analyzed the role of the Cybercriminal, their Modus Operandi, and the different phases of their attack. We also analyzed the figure of the victim, identifying the psychological, security, and legal knowledge vulnerabilities they share that lead to them being selected as targets.

In this presentation on Extortion: Cybercrime with consequences for personal and corporate reputation (the PPT goes here), four cases were analyzed:

  • From Badoo to LinkedIn
  • From amateurTV to WhatsApp
  • From bakala.org to Email
  • From Twitter to Email

[slideshare id=”40974471&doc=ok-sextorsionenlared-141031132202-conversion-gate01″]

What is NOCON?

The NOCON congress, for those who are not familiar with it, is a meeting space for professionals in Cybersecurity. The congress takes place every year at the beginning of November; it has a tradition spanning over 15 years, and each year the theme of the congress provides a space for debate on security trends. Its team is multidisciplinary, and…

Who is behind NOCON?

A team of security professionals and non-professionals with talent volunteered to make it possible to hold the event successfully year after year, led by Nicolás Castellano, a professional we are fortunate to have as a collaborator in various professional capacities: as a trainer in preventive and reactive Cybersecurity, as a digital forensics professional, and as an ethical hacker.

What presentations are at NOCON this year?

Well, this year Mercè Molist was set to open the Congress with her presentation “Once Upon a Time, a Story of Hackers,” but Chema Alonso appeared to enlighten us with his energetic speech on “I am the Best Hacker in the World.”

After his appearance, Mercè continued with the planned schedule but with a few minutes less. She was followed by Daniel O’Grady Rueda with “Design of a Hard Drive Driver for Indefectible File Systems,” and right after that, we had the Coffee Break.

Jordi Serra was next to present “Discovering Hidden Communications,” which was extremely interesting; honestly, I wish I could watch it over and over again, as there is so much to learn from it.

At 12:30 PM, Ruth and I began our presentation, and immediately afterward, we moved on to the lunch break.

There are two presentations that we will analyze in the coming days. It is not that the other presentations do not interest us, but rather that we do not have time to analyze them all, so we focus on those that most affect our business (Online Reputation and Cyber-investigation).

Tomorrow, Saturday, the second day, November 1st at 11:50 AM, the great Jose Selvi will talk to us about Hacking your CEO (essential), and right after our time slot, Vicente Diaz Aguilera, a total genius, will talk to us about something that interests us especially: Watched: Exploiting social networks to predict our behavior.

We have some knowledge of this topic 😉 and therefore we would like to contribute the theory developed by Jorge Jiménez on digital autopsy: how to predict a user’s behavior based on their network activity, not only on social networks but also on other social media (forums, blogs, and essentially, with the dump of multimedia content that is SO difficult to analyze and drives us crazy in every active listening system—little mapping behind the image, a great need for facial recognition in moving images and audio, and few good tools within reach of almost everyone—”none for now”…).

We take this opportunity to reiterate the call to action we made this morning.

The 3 major difficulties and problems we encounter in the day-to-day of Cyber-investigation

Evidently, not just us, but any data analyst who sees fit to collect, analyze, and make sense of them—to turn them into Intelligence, in short.

All the professionals I have spoken with in the last 6 years agree on this problem: the 3 major difficulties of investigation in social media

  1. Multimedia Content
    1. Facial recognition in images
    2. Recognition of moving images
    3. Audio recognition
  2. Textual content
    1. Real-time (the analysis of content uploaded to real-time based networks is not as good, even if the tools are powered by the Twitter API)
    2. Comments on News
    3. Comments on YouTube
  3. Relational construction
    1. Social networks that are difficult to analyze (dating networks)
    2. Analysis plugins for tools such as: Maltego (Badoo, Tinder, Bakala…)

Digital Identity

Methods for analyzing and
assessing online
reputation damage