What is criminal infrastructure-as-a-service?¶
Criminal infrastructure-as-a-service is the provision of hosting, proxies, malware delivery, access, communications or other operational resources for criminal use.
Evidential caution: that the provider, customer and end offender are always the same person or organisation.
What this means¶
They may be separate.
Services may provide:
servers;
domains;
proxies;
botnets;
phishing kits;
malware loaders;
access credentials;
stolen data storage;
communication channels;
payment processing.
the service role;
the provider account;
the customer account;
the resource supplied;
payment;
access records;
communications;
linked victims;
whether the service was knowingly criminal or merely abused.
A customer may buy one part of the operation and combine it with other services.
The same infrastructure service may support many unrelated incidents.
Likewise, a reseller may sit between provider and end user.
Criminal services may be advertised publicly, privately or through referral networks. Preserve marketplace listings, service rules, support chats, customer panels and payment instructions where lawful. These records may clarify whether the provider merely supplied neutral infrastructure or deliberately designed and supported criminal use.
Service customers may receive technical support, replacement infrastructure or abuse-handling advice. Such interactions may be relevant to provider knowledge and customer control, but they should be preserved and interpreted in context.
Where the same service supports several victims, preserve customer-specific identifiers and resource assignments. Shared branding or infrastructure should not cause separate customer campaigns to be treated as one offender operation without supporting links. The operational takeaway is:
Map service provider, reseller, customer and end-user roles separately, and attribute knowledge and control at the level supported by communications, financial and technical records.
================================================================================
What to check or do next¶
- Investigators should identify:
- Do not attribute every customer’s acts to the service operator without evidence of knowledge, control or participation.