Know Your Cybercriminal: Evaluating Attacker Preferences by Measuring Profile Sales on an Active, Leading Criminal Market for User Impersonation at Scale

03/06/2023
by   Michele Campobasso, et al.
0

In this paper we exploit market features proper of a leading Russian cybercrime market for user impersonation at scale to evaluate attacker preferences when purchasing stolen user profiles, and the overall economic activity of the market. We run our data collection over a period of 161 days and collect data on a sample of 1'193 sold user profiles out of 11'357 advertised products in that period and their characteristics. We estimate a market trade volume of up to approximately 700 profiles per day, corresponding to estimated daily sales of up to 4'000 USD and an overall market revenue within the observation period between 540k and 715k USD. We find profile provision to be rather stable over time and mainly focused on European profiles, whereas actual profile acquisition varies significantly depending on other profile characteristics. Attackers' interests focus disproportionally on profiles of certain types, including those originating in North America and featuring crypto resources. We model and evaluate the relative importance of different profile characteristics in the final decision of an attacker to purchase a profile, and discuss implications for defenses and risk evaluation.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/11/2023

Designing a User Contextual Profile Ontology: A Focus on the Vehicle Sales Domain

In the digital age, it is crucial to understand and tailor experiences f...
research
03/12/2018

Classifying Online Dating Profiles on Tinder using FaceNet Facial Embeddings

A method to produce personalized classification models to automatically ...
research
08/28/2022

Shedding Light on the Targeted Victim Profiles of Malicious Downloaders

Malware affects millions of users worldwide, impacting the daily lives o...
research
09/07/2020

Efficient Quantification of Profile Matching Risk in Social Networks

Anonymous data sharing has been becoming more challenging in today's int...
research
11/30/2019

Fuzzy approach on modelling cyber attacks patterns on data transfer in industrial control systems

Cybersecurity of industrial control system is a very complex and challen...
research
07/13/2020

COVID-19 infectivity profile correction

The infectivity profile of an individual with COVID-19 is attributed to ...
research
10/03/2017

Towards an Inferential Lexicon of Event Selecting Predicates for French

We present a manually constructed seed lexicon encoding the inferential ...

Please sign up or login with your details

Forgot password? Click here to reset