Many activities related to cybercrime operations do not require much secrecy, such as developing websites or translating texts. This research provides indications that many users of a popular public internet marketing forum have connections to cybercrime. It does so by investigating the involvement in cybercrime of a population of users interested in internet marketing, both at a micro and macro scale. The research starts with a case study of three users confirmed to be involved in cybercrime and their use of the public forum. It provides a first glimpse that some business with cybercrime connections is being conducted in the clear.
Cybercrime Specialization: An Exposé of a Malicious Android Obfuscation-as-a-Service
Malware authors constantly obfuscate their files and defenders regularly develop new techniques to detect them. Given this cat-and-mouse game, specialized obfuscation services have appeared in the cybercrime industry. These services allow malware authors to obfuscate their code for a fee. This study investigates an automated obfuscation-as-a-service platform for Android applications and yields unique insights on the technical difficulties and business reality of those behind such a specialized service. The service investigated was found to be average in quality, mainly using known obfuscation techniques, and generating obfuscated applications that were still detected by anti-viruses. It had a small clientele of large-scale attackers who used the service to decrease anti-virus detections of highly malicious applications, thus increasing their chances of compromising devices. Depending on the price bundles considered, operators offering the service were estimated to have made a minimum revenue ranging from USD 5,100 (conservative) to USD 61,160 (optimistic) for a six-month operation. This study illustrates that even though obfuscation-as-a-service is a market niche, taking advantage of the value added from this specialization is not effortless nor easily accessible to everyone involved in cybercrime.
Uncovering Automatic Obfuscation-as-a-Service for Malicious Android Applications
This research provides the first overview of such automatic service, which takes advantage of the whole malware-as-aservice industry, providing medium quality obfuscation for the Android malware market. Although the technical obfuscations are not state-of-the-art, the service succeeds in reducing detection for malicious Android applications. We conclude that the active use of the service highlights the need for the malware market to develop better obfuscation techniques, hence the good job that the security community is doing at quickly detecting changing malware. We also conclude that this service seemed to generate enough revenue for the group, given its automatic nature and purpose. Given that automatic services like this may be a greater problem in the future of malware obfuscation, this research provides a first technical analysis of the details of such obfuscation service and the possible impact in detection results.
Geost botnet. The story of the discovery of a new Android banking trojan from an OpSec error
This paper describes an ew botnet, which we called Geost, discovered thanks to multiple OpSec mistakes made by the attackers. The mistakes included: the use of the HtBot malware’s illegal proxy network; failing to encrypt the command-and-control servers; re-using security services; trusting other attackers that practise even less operational security; and failing to encrypt chat sessions. As far as we know, the Geost botnet has hundreds of malicious domains, 13 C&C servers, approximately 800,000 victims in Russia, and potential access to several million Euros in bank accounts.
Analysis of Botnet Behavior as a Distributed System
El crecimiento vertiginoso de nuevas tecnologıas, trae aparejado el crecimiento de aplicaciones maliciosas. Estas aplicaciones hacen uso de los recursos de los dispositivos infectados para realizar actividades ilıcitas, enviar mails de forma masiva (spam) o minar para obtener criptomonedas. Para minar, se requiere grandes capacidades de cómputo Las botnets pueden ser consideradas como un tipo de de aplicación de computación distribuıda. La palabra botnet significa red de robots. Es un tipo de malware, instalado en una computadora que ha sido infectada, con la habilidad de auto propagarse hacia otras máquinas. Todas las computadoras infectadas conforman la “red de bots”, o botnet. Este tipo de malware utiliza los recursos de la computadora infectad (CPU, RAM, ancho de banda), para comunicarse con su Botnet Master, que es quien le da órdenes. El presente trabajo es un estado del arte, se analiza el comportamiento de las botnets como aplicaciones de computación distribuıda. Se considera el comportamiento a nivel de consumo de recursos de los dispositivos que son infectados por el malware, en particular los miners.
Hack me-do. Deploying an IoT Malware Laboratory to Analyze Malicious Behavior
Hack me-do. Deploying an IoT Malware Laboratory to Analyze Malicious Behavior. María José Erquiaga (Universidad Nacional de Cuyo); Sebastián García (CTU University, ATG Group)
Geost Botnet. Operational Security Failures of a New Android Banking Threat
This paper describes the rare discovery of a new Android banking botnet, named Geost, from the operational security failures of its botmaster. They made many mistakes, including using the illegal proxy network of the HtBot malware, not encrypting their Command and Control servers, re-using security services, trusting other attackers with less operational security, and not encrypting chat sessions.
Observer effect: How Intercepting HTTPS traffic forces malware to change their behavior
During the last couple of years there has been an important surge on the use of HTTPs by malware. The reason for this increase is not completely understood yet, but it is hypothesized that it was forced by organizations only allowing web traffic to the Internet. Using HTTPs makes malware behavior similar to normal connections. Therefore, there has been a growing interest in understanding the usage of HTTPs by malware. This paper describes our research to obtain large quantities of real malware traffic using HTTPs, our use of man-in-the-middle HTTPs interceptor proxies to open and study the content, and our analysis of how the behavior of the malware changes after being intercepted. The research goal is to understand how malware uses HTTPs and the impact of intercepting its traffic. We conclude that the use of an interceptor proxy forces the malware to change its behavior and therefore should be carefully considered before being implemented.
Detecting DGA malware traffic through behavioral models
Some botnets use special algorithms to generate the domain names they need to connect to their command and control servers. They are refereed as Domain Generation Algorithms. Domain Generation Algorithms generate domain names and tries to resolve their IP addresses. If the domain has an IP address, it is used to connect to that command and control server. Otherwise, the DGA generates a new domain and keeps trying to connect. In both cases it is possible to capture and analyze the special behavior shown by those DNS packets in the network. The behavior of Domain Generation Algorithms is difficult to automatically detect because each domain is usually randomly generated and therefore unpredictable. Hence, it is challenging to separate the DNS traffic generated by malware from the DNS traffic generated by normal computers. In this work we analyze the use of behavioral detection approaches based on Markov Models to differentiate Domain Generation Algorithms traffic from normal DNS traffic. The evaluation methodology of our detection models has focused on a real-time approach based on the use of time windows for reporting the alerts. All the detection models have shown a clear differentiation between normal and malicious DNS traffic and most have also shown a good detection rate. We believe this work is a further step in using behavioral models for network detection and we hope to facilitate the development of more general and better behavioral detection methods of malware traffic.





