Skip to main content
QUICK REVIEW

[論文レビュー] Money Over Morals: A Business Analysis of Conti Ransomware

Ian W. Gray, Jack Cable|arXiv (Cornell University)|Apr 23, 2023
Advanced Malware Detection Techniques被引用数 6
ひとこと要約

本論文は、漏洩したチャットログとビットコイン取引データを用いて、コンティランサムウェア集団の最初で包括的な暗号経済的分析を提示する。手作業による666アドレスのアノテーションと、独創的な支払い分割検出手法の適用により、著者らは8390万ドル相当のおそらくランサムペイメントを同定した—これは過去の公開データセットよりも5倍以上多い。同時に、グループの運用セキュリティと金融インフラにおける深刻な脆弱性も明らかにした。

ABSTRACT

Ransomware operations have evolved from relatively unsophisticated threat actors into highly coordinated cybercrime syndicates that regularly extort millions of dollars in a single attack. Despite dominating headlines and crippling businesses across the globe, there is relatively little in-depth research into the modern structure and economics of ransomware operations. In this paper, we leverage leaked chat messages to provide an in-depth empirical analysis of Conti, one of the largest ransomware groups. By analyzing these chat messages, we construct a picture of Conti's operations as a highly-profitable business, from profit structures to employee recruitment and roles. We present novel methodologies to trace ransom payments, identifying over $80 million in likely ransom payments to Conti and its predecessor -- over five times as much as in previous public datasets. As part of our work, we publish a dataset of 666 labeled Bitcoin addresses related to Conti and an additional 75 Bitcoin addresses of likely ransom payments. Future work can leverage this case study to more effectively trace -- and ultimately counteract -- ransomware activity.

研究の動機と目的

  • ランサムウェアとしてのサービス(RaaS)としてのコンティランサムウェアの経済的および組織的分析を詳細に行う。
  • 漏洩したチャットログからの行動的ヒューリスティクスとブロックチェーン取引分析を用いて、ランサムペイメントを同定・追跡する。
  • コンティの内部ビジネス構造、役割、採用プロセス、報酬制度をマッピングする。
  • 将来的な研究および法執行機関利用を目的として、コンティに関連する666アドレスのラベル付きデータセットを公開する。
  • とりわけ、KYC準拠取引所への依存が顕著な、グループの金融インフラにおけるシステム的脆弱性を特定する。

提案手法

  • 漏洩したチャットログから得た666ビットコインアドレスを手作業でアノテートし、その機能(例:給与、償還、ランサムペイメント)を分類する。
  • ブロックチェーン取引分析を適用して、総収益、運営コスト、役割ごとの給与分配を推定する。
  • オペレータと加盟者間の共通した分割行動に基づく、ランサムペイメントを検出する新規手法を開発する。
  • クリスタル・ブロックチェーンのフォレンジックツールを用いてアドレスを関連付け、取引をクラスタリングし、追跡可能性を向上させる。
  • チャットログの定性的分析を通じて、組織的役割、採用プロセス、内部通信パターンを再構築する。
  • 既知の取引所(例:ジーニー、バイナンス)との支払いフローの照合により、高リスクで中央集権的な現金化ポイントを同定する。
Figure 1: An example of splitting. This address received 22 Bitcoin from the US-based Gemini exchange, and split into 25% and 75%. 1 Bitcoin from this address would eventually be sent to an address in the leak. Other funds were transferred to other illicit entities, such as the sanctioned exchange G
Figure 1: An example of splitting. This address received 22 Bitcoin from the US-based Gemini exchange, and split into 25% and 75%. 1 Bitcoin from this address would eventually be sent to an address in the leak. Other funds were transferred to other illicit entities, such as the sanctioned exchange G

実験結果

リサーチクエスチョン

  • RQ1どのようにして、ブロックチェーン取引パターンと行動的ヒューリスティクスを用いて、ランサムウェア運用におけるランサムペイメントを信頼性高く同定できるか?
  • RQ2コンティのランサムペイメントの実規模は何か? また、過去の公開データセットと比較するとどうなるか?
  • RQ3コンティランサムウェア集団内にはどのような内部ビジネス構造と運用役割があるのか?
  • RQ4給与支払いなどのコンティの金融慣行は、その運用セキュリティにどのような脆弱性を露呈するのか?
  • RQ5ジーニー、バイナンスのような中央集権的取引所は、ランサムウェア資金の追跡・遮断において、どの程度の重要なハブとして機能するのか?

主な発見

  • 本研究では、コンティおよびその前身にあたる8390万ドル相当のおそらくランサムペイメントを同定した—これは過去の公開データセットの5倍以上にのぼる。
  • 同定されたコンティのペイメントの90%以上が、特定されない取引所とジーニーの2つに集中しており、両者とも知りぬいた顧客確認(KYC)規制を適用している。
  • 給与やランサムペイメントをKYC準拠取引所を通じて送金するという、運用セキュリティの欠如が顕著であり、追跡可能な金融的足跡を残している。
  • 分析により、明確な役割分担、採用プロセス、報酬グレードを有する、構造化されたRaaSビジネスモデルが確認され、極めて組織化されたサイバー犯罪カルテルであることが示された。
  • 本研究では、666アドレスのラベル付きビットコインアドレスと、追加で75件のランサムペイメントアドレスのデータセットを公開し、将来的な研究および法執行機関の活動に活用できるようにした。
  • 研究結果は、組織の指導層および金融インフラ、とりわけ取引所ベースの現金化を標的とすることで、ランサムウェア運用を遮断する上で高いリターンを得られることを示している。
Figure 2: The largest discovered likely payment, of $9.5M in March 2020. The funds originated from the unlabeled cluster discussed in Section IV .
Figure 2: The largest discovered likely payment, of $9.5M in March 2020. The funds originated from the unlabeled cluster discussed in Section IV .

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。