Malware Finances and Operations: a Data-Driven Study of the Value Chain for Infections and Compromised Access

06/27/2023
by   Juha Nurmi, et al.
0

We investigate the criminal market dynamics of infostealer malware and publish three evidence datasets on malware infections and trade. We justify the value chain between illicit enterprises using the datasets, compare the prices and added value, and use the value chain to identify the most effective countermeasures. We begin by examining infostealer malware victim logs shared by actors on hacking forums, and extract victim information and mask sensitive data to protect privacy. We find access to these same victims for sale at Genesis Market. This technically sophisticated marketplace provides its own browser to access victim's online accounts. We collect a second dataset and discover that 91 Database Market sells access to compromised online accounts. We produce yet another dataset, finding 91 median of 7 US dollars.

READ FULL TEXT

page 4

page 8

research
03/08/2018

Issued for Abuse: Measuring the Underground Trade in Code Signing Certificate

Recent measurements of the Windows code-signing certificate ecosystem ha...
research
05/28/2020

SourceFinder: Finding Malware Source-Code from Publicly Available Repositories

Where can we find malware source code? This question is motivated by a r...
research
09/10/2022

GITCBot: A Novel Approach for the Next Generation of C&C Malware

Online Social Networks (OSNs) attracted millions of users in the world. ...
research
09/25/2020

Evasive Windows Malware: Impact on Antiviruses and Possible Countermeasures

The perpetual opposition between antiviruses and malware leads both part...
research
02/22/2018

Microsoft Malware Classification Challenge

The Microsoft Malware Classification Challenge was announced in 2015 alo...
research
11/19/2019

Volenti non fit injuria: Ransomware and its Victims

With the recent growth in the number of malicious activities on the inte...

Please sign up or login with your details

Forgot password? Click here to reset