作者
Athanasios Avgetidis, Omar Alrawi, Kevin Valakuzhy, Charles Lever, Paul Burbage, Angelos D Keromytis, Fabian Monrose, Manos Antonakakis
发表日期
2023
研讨会论文
32nd USENIX security symposium (USENIX Security 23)
页码范围
5307-5324
简介
Password Stealers (Stealers) are commodity malware that specialize in credential theft. This work presents a large-scale longitudinal study of Stealers and their operators. Using a commercial dataset, we characterize the activity of over 4, 586 distinct Stealer operators through their devices spanning 10 different Stealer families. Operators make heavy use of proxies, including traditional VPNs, residential proxies, mobile proxies, and the Tor network when managing their botnet. Our affiliation analysis unveils a stratified enterprise of cybercriminals for each service offering and we identify privileged operators using graph analysis. We find several Stealer-as-a-Service providers that lower the economical and technical barrier for many cybercriminals. We estimate that service providers benefit from high-profit margins (up to 98%) and a lower-bound profit estimate of $11, 000 per month. We find high-profile targeting like the Social Security Administration, the US House of Representatives, and the US Senate. We share our findings with law enforcement and publish six months of the dataset, analysis artifact, and code.
引用总数
学术搜索中的文章
A Avgetidis, O Alrawi, K Valakuzhy, C Lever, P Burbage… - 32nd USENIX security symposium (USENIX Security …, 2023