A Tale of Two Markets: Investigating the Ransomware Payments Economy

05/10/2022
by   Kris Oosthoek, et al.
0

Ransomware attacks are among the most severe cyber threats. They have made headlines in recent years by threatening the operation of governments, critical infrastructure, and corporations. Collecting and analyzing ransomware data is an important step towards understanding the spread of ransomware and designing effective defense and mitigation mechanisms. We report on our experience operating Ransomwhere, an open crowdsourced ransomware payment tracker to collect information from victims of ransomware attacks. With Ransomwhere, we have gathered 13.5k ransom payments to more than 87 ransomware criminal actors with total payments of more than 101 million. Leveraging the transparent nature of Bitcoin, the cryptocurrency used for most ransomware payments, we characterize the evolving ransomware criminal structure and ransom laundering strategies. Our analysis shows that there are two parallel ransomware criminal markets: commodity ransomware and Ransomware as a Service (RaaS). We notice that there are striking differences between the two markets in the way that cryptocurrency resources are utilized, revenue per transaction, and ransom laundering efficiency. Although it is relatively easy to identify choke points in commodity ransomware payment activity, it is more difficult to do the same for RaaS.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
09/27/2022

Artificial Intelligence for Cybersecurity: Threats, Attacks and Mitigation

With the advent of the digital era, every day-to-day task is automated d...
research
08/03/2018

An SDN-based Approach For Defending Against Reflective DDoS Attacks

Distributed Reflective Denial of Service (DRDoS) attacks are an immanent...
research
08/22/2022

Machine Learning-Enabled Cyber Attack Prediction and Mitigation for EV Charging Stations

Safe and reliable electric vehicle charging stations (EVCSs) have become...
research
08/14/2018

Aspirational pursuit of mates in online dating markets

Romantic courtship is often described as taking place in a dating market...
research
11/12/2019

Identifying Hidden Buyers in Darknet Markets via Dirichlet Hawkes Process

The darknet markets are notorious black markets in cyberspace, which inv...
research
06/15/2023

Identifying key players in dark web marketplaces

Dark web marketplaces have been a significant outlet for illicit trade, ...
research
08/30/2022

One Year of DDoS Attacks Against a Cloud Provider: an Overview

Distributed denial of service attacks represents one of the most importa...

Please sign up or login with your details

Forgot password? Click here to reset