Open Research will be updating the system on Monday, 25 May 2026, from 8:15 to 8:45 AM. We apologise for any inconvenience caused.

From Money Mules to Chain-Hopping: Targeting the Finances of Cybercrime

dc.contributor.authorMoiseienko, Anton
dc.contributor.authorKraft, Olivier
dc.date.accessioned2025-05-28T03:49:07Z
dc.date.available2025-05-28T03:49:07Z
dc.date.issued2018
dc.date.updated2023-10-29T07:16:21Z
dc.description.abstractThis paper examines money-laundering techniques used by cyber-criminals and proposes measures that should be taken by UK policymakers, law enforcement agencies and regulated businesses to make it more difficult for such activities to go undetected. Cybercrime has become a major category of financially motivated crime. It generates proceeds that in some cases amount to hundreds of millions of pounds. Moreover, it engenders a bustling underground economy where stolen data and services that facilitate cybercrime are traded. Money forms a key part of cyber-criminals’ motivation to engage in criminality. It is also their vulnerability. Since financially motivated crime inevitably involves money laundering, which refers to any use of the proceeds of crime, anti-money laundering (AML) measures can be used to target cyber-criminals. Financial investigation can be used to trace transactions and identify their beneficiaries. Criminal prosecution can target money launderers who help cyber-criminals transfer and use the proceeds of crime. Based on a review of publicly available information and interviews with subject-matter experts, this paper proposes ways of further strengthening these financial efforts against cybercrime. Scope of the Paper Cybercrime is a broad concept. This paper focuses specifically on the proceeds from hacking, malware infections (including ransomware) and distributed denial of service (DDOS) attacks. These are enabled by the existence of an underground criminal economy of services that facilitate cybercrime. In view of this, the paper also covers the proceeds of ancillary services that range from the provision of hacking, malware or DDOS attacks ‘as a service’ to money-laundering services. Generation of Cyber-Criminal Proceeds Since the form and amount of the proceeds often determine how they will be laundered, it is necessary to consider how cyber-criminals generate proceeds. This happens in a variety of ways, including: • Taking over a bank customer’s account or interfering with inter-bank payments, typically via Society for Worldwide Interbank Financial Telecommunication (SWIFT) intrusions, which leads to unauthorised electronic transfers of fiat currency (government-issued money such as US dollars or British pounds). • Hacking ATMs or attacking banks’ card-processing systems, which generates proceeds in cash. Attacks on card processing involve the deactivation of withdrawal and overdraft limits on cards held by criminals. • Ransomware extortion, ‘cryptojacking’1 or theft of cryptocurrency, which all depend on cryptocurrency, such as bitcoin. The market in ancillary services is also dominated by cryptocurrency due to the perceived anonymity of transactions.
dc.description.sponsorshipThis item was commisioned by Royal United Services Institute
dc.format.mimetypeapplication/pdfen_AU
dc.identifier.issn2397-0278
dc.identifier.urihttps://hdl.handle.net/1885/733754340
dc.language.isoen_AUen_AU
dc.provenanceThis work is licensed under a Creative Commons Attribution – Non-Commercial – No-Derivatives 4.0 International Licence.
dc.publisherRoyal United Services Institute for Defence and Security Studies
dc.rights© 2018 Royal United Services Institute for Defence and Security Studies
dc.rights.licenseCreative Commons Attribution – Non-Commercial – No-Derivatives 4.0 International Licence
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/4.0/
dc.sourceRUSI Occasional Paper
dc.titleFrom Money Mules to Chain-Hopping: Targeting the Finances of Cybercrime
dc.typeReport (Commissioned)
dcterms.accessRightsOpen Access
local.bibliographicCitation.issueNovember 2018
local.bibliographicCitation.lastpage80
local.bibliographicCitation.placeofpublicationLondon, England
local.bibliographicCitation.startpage1
local.contributor.affiliationMoiseienko, Anton, ANU College of Law, ANU
local.contributor.affiliationKraft, Olivier, The Royal United Services Institute (RUSI)
local.contributor.authoruidMoiseienko, Anton, u1106830
local.description.notesImported from ARIES
local.identifier.absfor480499 - Law in context not elsewhere classified
local.identifier.absseo230403 - Criminal justice
local.identifier.ariespublicationu5706852xPUB171
local.identifier.essn2397-0286
local.type.statusPublished Version

Downloads