Go back

How does AI change the economics of cybercrime?

18m 30s

How does AI change the economics of cybercrime?

In this episode of the AI Security Brief, hosts Dustin Childs and Johnny Hand discuss with Bob McCartle, director of cybercrime research at Trend AI, how agentic AI is reshaping cybercrime. Bob explains that while generative AI answers questions, agentic AI acts on behalf of users, making it a real game-changer. Cybercriminals have long operated a modular service industry, and agentic AI allows them to replace services and APIs with agents that can converge and automate entire attack ecosystems. Bob outlines three rules of cybercrime adoption: criminals seek an easy life, adopt new tech only if ROI beats current methods, and evolve rather than revolutionize. The ransomware era, once highly profitable, is declining, creating a perfect storm for criminals to embrace agentic AI. Defenders should expect a massive volume increase in attacks and must deploy AI agents to absorb the first wave, reserving senior humans for complex triage. Bob advises security leaders to read strategic reports and evaluate vendors based on genuine agentic workflows, not just AI marketing hype. He recommends resources like Trend AI’s vibe crime report and the news.aatf.ai feed to stay informed. The conversation underscores that agentic AI is accelerating cybercrime’s evolution, requiring defenders to adapt with similar automation.

Transcription

3646 Words, 20235 Characters

English
[MUSIC] You're listening to the CyberWire network, powered by N2K. [MUSIC] So I think actually, a Gen2Gai is genuinely the real game gender here, right? If you look at the cybercrime industry for the last 10, 15 years, it's arguably the best example of the service industry in the world, even more so than cloud computing and so on, because you just replace all of those services or APIs with an agent. And you just pull agents together, they converge among themselves effectively, and you have this cybercrime automated ecosystem that can run itself. [MUSIC] Welcome to the AI Security Brief, where we're unpacking emerging AI threats, vulnerability research, and the strategic decision security leaders are making right now to get ahead of the next wave of cybercrimes. [MUSIC] I'm Dustin Childs. And I'm Johnny Hand, and today's episode surfaces a critical point for me. Not only is AI making existing attacks faster, but the entire structure of how cybercrime operates is being rebuilt around it. And it is quite a profitable industry too. Yeah, definitely is. And to explore the evolution of cybercrime, we sat down with Bob McCartle, the director of cybercrime research at Trend AI. Now, Bob has spent two decades tracking cybercriminals, so he has a front row seat on how a gentick AI is reshaping cybercrime. Yeah, what really struck me in this conversation is how Bob frames what's happening. I mean, this isn't just AI makes fishing emails better, which it does, but this is about an entire criminal service economy. One that is already more sophisticated than most people realize and how a gentick AI is giving it a new engine. Yeah, we talked about the three rules of cybercrime adoption also. And why a gentick AI hits differently than generative AI. Also, what defenders can actually do to get ahead of the cybercriminals? Bob does not disappoint. If you're a security or technology leader looking to understand where the threat landscape is evolving, this conversation is for you. Let's dive in. Yeah, so Bob, I mean, your work from what I understand is in a lot of crime and doing take downs, working with Elias. And your talk is about vied crime. But before we get into that, explain to me what vied coding is, because some people think it's like a really bad thing. Some people think it's a good thing, neutral, whatever. What is vied coding to you? So, vied coding, I think it gets a bit of a bad rep, because in some situations, it's people who are not traditional code or suddenly being able to develop things. But essentially, it's just coding, changing from a language you had to learn, be it Python or something like that. To affect if you've been able to code in your language of choice, whether that's French, German, English, whatever it is, you just simply describe the problem you're trying to solve and work back and forth with an AI to actually solve it. It's quite interesting, like, new development. But that must make it easier, because as a defender, I know one of the big things that I did was I tried to make it so expensive, because given enough time and resources, anything could be breached, right? So, I tried to make it so expensive that the attacker would essentially ignore me and move on. But it sounds like with vied coding, you can take a pretty generic person and get them to a point where they can be a criminal without having a lot of skills, is that correct? So, I think there's two parts to be in a criminal, right? One is the technical skills you're going to need. And yes, it absolutely lowers the barrier for entry for that type of thing, right? Because anybody can get access to the tools or build them themselves, or the actual tool prices will drop because anybody can build them. The second side to be in a criminal however is the actual ethics and morals and so on, right? So, if you, for example, are, you know, hacker or teenage hacker and you break into a server somewhere and you're poking around, and you might get that joy out of like, hey, I've actually been able to technically accomplish this. But if you didn't go to the level of installing ransomware and infecting misery and so on and somebody, that's completely different moral compass than the person who's just doing it for, you know, creativity and things like that. So, that's the bit that AI doesn't affect, right? That moral compass part. I do want to dig in a little bit on the momentum that's happening right now and just the language and the speed of which agenteic AI is taking off. And how is that translating with cybercrime? Like, what are some of those like second and third effects that are having? Are you seeing that in your research with cybercriminals at the pace that we're doing it from a defensive perspective or even just like automation and using agenteic tools to take those task actions? Yeah, so I think actually agenteic AI is genuinely the real game gender here, right? For cybercriminals in particular. So, if you just look at pure generative AI or people who be listening in and are familiar with, you know, you're at chat, GPs or claws or whatever, that's very good at answering questions, right? You ask a question, you get an answer back or you write the whole paper for you, whatever. But it doesn't really do something on your behalf. And that doing something on your behalf that agenteic gives us is the real game gender. Because if you look at the cybercrime industry for the last 10, 15 years, it's arguably the best example of a service industry in the world, even more so than cloud computing and so on. And that gives it's incredible flexibility where you can just stitch together these different APIs and services from criminals. But that is perfectly then set up for agenteic because you just replace all of those services or APIs with an agent. And now you just pull agents together, they converse among themselves effectively and you have this like cybercrime automated ecosystem that can run itself. It's an interesting perspective because I think for many people when they're looking into, you know, maybe they're the lens that they view cybercriminals or even criminals in general, they're not often thinking about how sophisticated they can be. And I love the fact that you just hit on how they're even better in many cases than we are at like building out these services and providing them. So let's take a step back for a second because you've been doing threat research and cybercriminals for many years. I'd love to hear kind of that journey over the last maybe decade into the last few years as you've kind of waited into the water at the pace we have in research with AI, agenteic AI and these capabilities around cybercrime. - So I've been kind of working in cybercrime research and also like APT nation state research and things for about two decades now. And you see over that time, like these major waves coming along. And the longer you're doing this, you realize some of these waves are senti-sicktical. They're kind of happening over and over again. The technology's different, but the course scam, the core attack, the business is effectively the same thing. It's just the new technology gets laid on top. So you had, you know, for a long time, you had in quite a lot of innovation in cybercrime then we came to kind of ransomware era that we've all kind of lived through over the last while which arguably actually killed innovation in the cybercrime space. - Interesting. - Because it suddenly went from, you know, before now we had things like banking attacks and phishing and so on. But ransomware made so much money that it was very hard for any new ideas to take off because if you're making a million a month from doing ransomware and some new, technically more interesting attack comes along, but it's untried, it's not tested and so on. Why would you even bother doing it? Just keep getting a million dollar, you know, check every single month. So it actually stifled creativity. And now we're at the point where there's just kind of perfect storm happening. Industry generally knows how to solve the ransomware problem. At this point, right, or if you don't at this stage in your industry, you're in trouble, right? There's no rules, the solution's out there. So they're struggling with that. Like payment rates are ransomware but the lowest have ever been. And at the same time you've got this rising technology, NEI, which is said as like perfectly set up with a gentegei for cybercrime. And cybercrime laws by nature tend to be technical and interested in new technology, right? From a pure just like, oh, that's cool, right? So this perfect storm is happening where at one side they have to change because their industry is slowing down. And then tradition, you transform the technology coming along and they're like, let's jump on this and see what happens. I know at RSA, you presented on vibe crime and I think it's an interesting title. And you talk about these three core principles or laws of cybercrime adoption. Can you just expand that a little bit for us and get us to understand what you're presenting there? Sure. So when we see open in our industry, we see, you know, researchers like myself or colleagues and then we're companies and they will come up with new attacks and criminals could work like this. But what they're actually doing is they're thinking like hackers not like criminals, right? So they're thinking like there's a technical way you can break into this, you know, or like any, you probably see there's an vulnerability world as well, right? Yes, yes. But then when it comes to the criminals, you have to think like, what's the business here? Can I make more money than I used to make? And so on. And we've over time we found that criminals evolved a little bit slower than people think to do because you only evolve when you have to or when there's a really good opportunity out there to make even more money than you currently make it. So we've found out that three rules that we call internally that the three rules have been a cyber criminal and we, I think we published them in a paper recently. So the first one was very simple. Criminals want an easy life. Right, that's the entire point of being a criminal. Otherwise you would be working in a real job doing real things. They move a good way of explaining that to us. Yes, exactly, right? The second thing is, if there's any new technology out there without a Gen2K AI or whatever it is that you want to adopt, the return of investment from it has to be better than everything else in the market. Otherwise again, what's the point? Why would you adopt it? And the third rule we see them do is cyber criminal evolution, if cyber criminal change is very much evolution, it's not revolution. So they just take what was working and it's like, oh, this isn't working quite as well as it used to. Can we tweak this a little bit? Okay, we're back on track again. Right? So they'll only the very largest criminal organizations have really ever had like R&D teams where they sink costs in the hope that it pays off now. in the future, like what we do in our industry, right? So it doesn't happen that often. So those three together help you understand a lot about how cybercriminals will adopt certain new technologies and how to build it. - What should defenders do to understand the barrier to entry has been brought down for these criminals? Oh, what is some real advice that we could take away to know that cyber, the cost of cybercrime is plummeting? - Yeah, so if you think about the cost of cybercrime is plummeting, so what's that kind of do, right? First of all, because we said they don't adapt to brand new schemes unless you really have to. So the first thing you're gonna do is just crank the volume up to 11 on everything that they're currently doing. So more fishing, more ransomware, more malware, more everything else, which is a little bit boring to say, right, but that's what they will do first. And then things like deep fakes and so on. So the first thing you have to do as defenders is, you know how to defend against these things, right? At least, hopefully, you know how to defend against these things at this point. But what you're gonna be doing is if you were struggling with the volume before, you haven't seen anything yet. It could be 100x, right? In terms of the volume coming at you. So if your old model was we look at, you know, one in 10 of the alerts on our network and our stock processes and so on, that's just not gonna scale, right? Unless you hire a whole bunch of extra people. So what you're gonna honestly have to have is you need agents to fight the agents for at least at the bottom layer, right? Let's just remove the layer one, layer two of a tax set of the picture. And then you have your senior humans who go in, okay, right? I know what's going on here in triage, you know, and so on. So I would advise anyone, genuinely, like, you know, every single product and the entire security space at this point has got AI something inside it, right? It's kind of almost like joke at this point. Look at the ones who genuinely are talking about agentec workflows and things like agentec themes and socks and so on and they get it. They get the actual issue, quiz them on that, right? Ask them about it. What are you are honestly doing? And if they can't answer those questions beyond like AI is madrigan, it's a black box, and it's awesome, then stay away, right? Because you need that to remove that first, but wave of information coming at you. Well, help me, especially as a former security leader, you know, as a CISO that worked in organizations, I always like look at threat research and different reports that are published and I often walk away saying, okay, what can I do with this? So for me, when you talk about the cyber criminals really getting ready to really ramp that up, the challenge that I see is that we have so much AI hype going on. So for those security leaders that are listening that are going, okay, well, how do I break through that noise? How do I understand as an example, like what AI-based security tools really are agentec really will help me navigate the coming wave of cyber crime? So of a couple of tips in that area, the first thing is for anyone listening, you have to realize that this kind of AI revolution, I had genuine ears of revolution, is exponential in its kind of scale, right? And luckily everybody listening in, unless we have a bunch of three-year-olds on here have lived through COVID, right? So they didn't know what something it exponential feels like, right? And I'll just give an example, right? The number one way that you navigate something like that is understand the information and understanding the trend that's happening, not just the individual day's data points, right? So you can go, okay, I think I know where this is going next week, I think I know where it's going six months time, and you can wrap it accordingly, right? So like, if you imagine back just for play out the analogy and then we'll get back to the answer, it's March 2020, first of March, I think there's like a thousand cases around the world or something, right? And if that's where you freeze your knowledge and you're like, okay, that's how the world is. 15 days later, eight times as many cases. 30 days later, 50 times as many cases. And that's how AI works. So that when we are at the bleeding edge of AI and we're testing out things and so on, and when we talk to people who are maybe a month behind in their knowledge, well, we're talking about sounds like science fiction to them. They're like, we don't want any of that future stuff that you're talking about. Tell me what's happening now. I was like, this is happening now. You just haven't read this yet, right? This is actually yesterday's news, I'm telling you. So when we bring that then into advice, it's read the more strategic publications from the research community, not so much the threat of the day we found this, it's super cool and so on. The security industry will always publish each day the corner case because it's interesting. In the same way that nobody publishes anymore, it's like, ransomware effect to people today. It's like, we know, of course it's it, right? It's only the anomalies the people are going to report on. So if you can read the more strategic reports and at least maybe two per month at the stage just to keep up with it, you'll be able to see through these the hype of the day and see the actual trend that you need to care about. Gotcha. Are there any recommendations that you love? Yeah, so genuinely, actually, I have two that'll give you. One, honestly, that the reports coming out of Trend AI and our team, so the vibe crime report that we put out is still a very, still very, very relevant. It's a few months old now, but we built it to be strategic, right, that you can learn from. There's also actually a site that I use every single day. It came from an internal team, actually, a Trend AI, but we published it external for anybody to use. It's news.aatf.ai. And it just does a roundup of all the AI news of the day into an Ours as feed. It's just subscribed to. And it gives you that daily dose of, this is what happened in the world today. I think that's already critical for keeping up the date with what's going on because a single day is news is like weeks of news in the past. Yeah, absolutely. That's great advice. I appreciate that. And thank you so much for sharing your research with us today. I was actually talking to our say. It was a really great presentation. It's very important, very eye-opening work. And we can't wait to have you back on the show again to terrify us with your latest research into the criminal organizations and the criminal mind. Anytime. [MUSIC PLAYING] OK. The three rules Bob shared is stuck with me. New technology only gets adopted if the ROI beats what they are already doing. And change in cybercrime world is evolutionary and not revolutionary. Yeah, and here comes a real agente AI, which is almost purpose-built for the way criminal operations are already structured. It offers that repeatable framework for a quick return. The service economy point is the one I keep coming back to. These groups have operated like a dark web version of cloud infrastructure for years. They're modular and specialized. Agente AI doesn't just disrupt that. It accelerates it. And I think that really is the key takeaway of the day. Go ahead. Well, the volume of attacks is about to increase in a way that breaks the current model for most security teams. So if you're triaging one in 10 alerts today and that feels hard, Bob's point is you haven't seen anything yet. The only real answer is using AI on the defensive side to absorb that first wave. So your experience, folks, can focus on what really matters. And that means being deliberate about which tools you're betting on. Not does this vendor have AI? Because every vendor is claiming that they have AI right now. But do they generally understand agente workflows? Can they operate at the volume of what's coming? Those are the questions we're asking. I totally agree. A huge thank you to Bob McCartle for his time and for sharing his insights on the evolving nature of cybercrime. Links to the vibe crime report and the AATF daily news feed are in the show notes. Both are very much worth adding to your reading list. Couldn't agree more. And that does it for our first episode of the AI Security Brief. We want to thank you for joining us. And we hope this conversation has you thinking a little bit differently about security. If it does, please consider subscribing and leave it as a review. Let us know what you thought. And so you don't miss what's next. The AI Security Brief is mixed and produced by Elliott Peltzman with original music by Omnia Jinx. Our executive producer is Jennifer Iben with content strategy by Maion Plow, Shannon Murphy, and Melanie Gilaunt. Additional production help by Liz Stokes, video editing, by Bridget Creeky Wilde, and Cerelle Joppy. Thanks so much for listening. Thanks, and we'll see you next time on the AI Security Brief. [MUSIC PLAYING]

Podcast Summary

Key Points:

  1. Agentic AI is a true game-changer for cybercrime, enabling automated ecosystems where agents replace services and APIs.
  2. Cybercriminals operate like a sophisticated service industry, and agentic AI is purpose-built to enhance this model.
  3. Vibe coding lowers technical barriers to entry, allowing non-coders to create tools, but does not affect moral compass.
  4. Cybercrime adoption follows three rules
  5. The ransomware era stifled innovation, but a perfect storm of declining profits and rising AI is driving criminals to adopt agentic AI.
  6. Defenders must use AI agents to handle the expected 100x increase in attack volume, freeing senior humans for triage.
  7. Security leaders should focus on strategic reports and tools with genuine agentic workflows, not just AI hype.

Summary:

In this episode of the AI Security Brief, hosts Dustin Childs and Johnny Hand discuss with Bob McCartle, director of cybercrime research at Trend AI, how agentic AI is reshaping cybercrime. Bob explains that while generative AI answers questions, agentic AI acts on behalf of users, making it a real game-changer. Cybercriminals have long operated a modular service industry, and agentic AI allows them to replace services and APIs with agents that can converge and automate entire attack ecosystems.

Bob outlines three rules of cybercrime adoption: criminals seek an easy life, adopt new tech only if ROI beats current methods, and evolve rather than revolutionize. The ransomware era, once highly profitable, is declining, creating a perfect storm for criminals to embrace agentic AI. Defenders should expect a massive volume increase in attacks and must deploy AI agents to absorb the first wave, reserving senior humans for complex triage.

Bob advises security leaders to read strategic reports and evaluate vendors based on genuine agentic workflows, not just AI marketing hype. ai feed to stay informed. The conversation underscores that agentic AI is accelerating cybercrime’s evolution, requiring defenders to adapt with similar automation.

FAQs

Vibe coding is coding where you describe a problem in natural language (like English) and work back and forth with an AI to solve it, lowering the barrier for non-traditional coders.

Generative AI answers questions, but agentic AI acts on your behalf. This allows cybercriminals to replace services and APIs with agents that converse and automate an entire crime ecosystem.

First, criminals want an easy life. Second, any new technology must offer a better return on investment than current methods. Third, cybercriminal change is evolutionary, not revolutionary—they tweak what works.

Cybercrime has operated like a service industry for years, with modular, specialized services (like APIs) that can be stitched together, making it more sophisticated than many legitimate industries.

AI will dramatically increase the volume of existing attacks like phishing and ransomware, potentially 100x, overwhelming current security teams that struggle with alert triage.

Security leaders should use AI defensively to absorb the first wave of attacks, focus on tools with genuine agentic workflows, and read strategic reports (like Trend AI's or news.aatf.ai) to understand trends, not daily anomalies.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.