[论文解读] A Tale of Two Markets: Investigating the Ransomware Payments Economy
本文通过 Ransomwhere——一个追踪超过 13,500 笔比特币赎金支付、总额逾 1.019 亿美元的众包追踪工具——研究了勒索软件支付经济。研究揭示了两个并行市场:商品勒索软件与勒索软件即服务(Ransomware as a Service, RaaS),其中 RaaS 展现出更高的单笔交易收入、通过混币器和欺诈性交易所更快的资金清洗速度,以及更高的运营复杂性,使得执法机构的干预难度显著增加。
Ransomware attacks are among the most severe cyber threats. They have made headlines in recent years by threatening the operation of governments, critical infrastructure, and corporations. Collecting and analyzing ransomware data is an important step towards understanding the spread of ransomware and designing effective defense and mitigation mechanisms. We report on our experience operating Ransomwhere, an open crowdsourced ransomware payment tracker to collect information from victims of ransomware attacks. With Ransomwhere, we have gathered 13.5k ransom payments to more than 87 ransomware criminal actors with total payments of more than $101 million. Leveraging the transparent nature of Bitcoin, the cryptocurrency used for most ransomware payments, we characterize the evolving ransomware criminal structure and ransom laundering strategies. Our analysis shows that there are two parallel ransomware criminal markets: commodity ransomware and Ransomware as a Service (RaaS). We notice that there are striking differences between the two markets in the way that cryptocurrency resources are utilized, revenue per transaction, and ransom laundering efficiency. Although it is relatively easy to identify choke points in commodity ransomware payment activity, it is more difficult to do the same for RaaS.
研究动机与目标
- 通过实证数据收集,理解勒索软件支付生态系统的结构与演变。
- 分析勒索软件攻击者(尤其是 RaaS 与商品市场)如何管理与清洗加密货币收益。
- 识别两类市场在赎金支付行为、交易速度与清洗策略方面的差异。
- 基于交易模式评估执法机构干预以追回赎金支付的可行性。
- 通过公开发布 Ransomwhere 追踪工具与数据集,为未来研究提供支持。
提出的方法
- 通过 Ransomwhere 公开追踪器,众包收集受害者提供的勒索软件支付信息。
- 利用区块链取证技术,分析五年间 87 名勒索软件攻击者涉及的 13,497 笔比特币交易。
- 根据运营模式与技术实践,将攻击者分类为商品勒索软件与 RaaS。
- 追踪受害者存款地址向清洗实体(如交易所、混币器)的首跳转账,以评估清洗速度与方法。
- 由于难以识别地址背后的合法实体,采用基于百分比的报告方式呈现清洗实体分布。
- 应用取证技术追踪交易流向,估算清洗效率与时间。
实验结果
研究问题
- RQ1在交易量、单笔收益与清洗速度方面,商品勒索软件与 RaaS 攻击者的勒索软件支付行为有何差异?
- RQ2商品勒索软件与 RaaS 攻击者主要使用哪些清洗机制?这些机制如何影响可追溯性?
- RQ3为何执法机构对 RaaS 攻击者的干预比对商品勒索软件运营商更为困难?
- RQ4RaaS 攻击者在多大程度上使用混币器与非 KYC 交易所来隐藏交易轨迹?
- RQ5RaaS 的运营结构如何促进更高收益的产生,并增强对干扰的抗性?
主要发现
- 自 2019 年以来,勒索软件即服务(RaaS)已成为主导模式,其单笔交易与总体收入均高于商品勒索软件。
- RaaS 攻击者采用更复杂的技术,例如为每位受害者使用唯一比特币地址,以增强匿名性并降低可追溯性。
- RaaS 攻击者资金清洗速度显著更快,通常在数小时或数天内完成,而商品勒索软件攻击者则无系统性清洗策略。
- RaaS 攻击者主要依赖混币器与欺诈性交易所(专为隐藏所有权而设计)进行清洗,而商品勒索软件攻击者更多依赖直接交易所转账,留下更多取证痕迹。
- RaaS 攻击者使用混币器与非 KYC 交易所,使得执法机构更难追回被盗资金。
- 本研究发现,商品勒索软件的瓶颈更容易被检测,但由于赎金金额较低,追回激励不足;而 RaaS 的速度与复杂性给干预带来了重大挑战。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。