How to Identify Employees Offering Corporate Access On the Dark Web

by Arnett Hailey

Not all cybersecurity threats come from anonymous, highly shielded threat actors who lurk in the darkest corners of the dark web. In fact, some of the most damaging threats come from insiders. Yet despite the unique challenges insiders present, they can be identified with a combination of dark web threat intelligence and open-source intelligence (OSINT) tools.

Insider threats are significant enough that the Cybersecurity and Infrastructure Security Agency (CISA) gives them plenty of attention. The CISA defines an insider threat as “the threat that an insider will use their authorized access, intentionally or unintentionally, to do harm.”

A typical scenario might involve a current or former employee who leverages his legitimate corporate access for financial gain by selling that access on the dark web. No doubt there are plenty of cybercriminals willing to pay good money for easy access. So how do organizations identify insider threats within their midst?

It Starts With a Handshake

Cybersecurity experts refer to the process of establishing communication between parties as a handshake. This is the first place they look in the search for insiders looking to sell access. Investigators must anticipate how an insider might advertise what he has for sale.

The experts at DarkOwl say that investigators can use OSINT tools to look for communications featuring telltale keywords. The keywords can be broken down into three categories:

  • Corporate/Brand – Keywords that include the targeted organization’s full name, ticker symbol, known acronyms, etc.
  • Technical/Access – Keywords that name specific software, systems and services, and access methods.
  • Asset/IP – Keywords naming sensitive intellectual property (IP) or the unique names of internal projects.

The most successful searches involve multiple keywords from each of the categories. If targeted keywords are found, investigators are immediately suspicious that a malicious employee is trying to sell access or sensitive information.

Moving on to Advanced Strategies

The handshake and keyword searches are just the starting point. If there is any reason to believe a company could be targeted by an insider threat, investigators move on to more advanced search strategies. OSINT tools are at the forefront of these strategies. By leveraging OSINT in partnership with proprietary tools, like DarkOwl’s platform, insiders can be identified.

Here are a couple of the more advanced strategies security investigators tend to utilize:

1. Breached Credential Monitoring

Certain OSINT tools can continuously monitor darknet locations looking for data breaches and credential dumps. If sensitive information can be linked to an employee login, that individual is immediately considered a high-priority threat.

2. Searching IAB Advertisements

Initial Access Brokers (IABs) are the primary customers for insiders looking to sell access. So security analysts target their advertisements. Advertising language can lead them to certain insiders based on the types of information they are looking to buy.

Analysts are also interested in pricing language because it can help distinguish between a casual forum discussion and communications involving an actual sale. A phrase like ‘price negotiable’ suggests that one or both parties are still shopping. But a phrase like ‘BTC only’ indicates that a sale was imminent or has already occurred.

Detection Before Mitigation

Finding insiders is crucial for the simple fact that detection precedes mitigation. Investigators need to find threats before they can stop them. Fortunately, a combination of dark web threat intelligence and proven OSINT tools makes it possible to find insider threats in the earliest possible stages.

Given how damaging insider threats can be, security analysts don’t have time to waste. They need to find insider threats as quickly as possible. Preventing the damage that would otherwise be inflicted depends on it.

Related Articles