Skip to main content
QUICK REVIEW

[论文解读] Money Over Morals: A Business Analysis of Conti Ransomware

Ian W. Gray, Jack Cable|arXiv (Cornell University)|Apr 23, 2023
Advanced Malware Detection Techniques被引用 6
一句话总结

本文利用泄露的聊天记录和比特币交易数据,首次对Conti勒索病毒团伙进行了全面的密码经济分析。通过人工标注666个比特币地址,并应用一种新型的付款拆分检测方法,作者识别出约8390万美元的疑似勒索赎金——这一数额是此前公开数据集的五倍以上,同时揭示了该团伙在运营安全和金融基础设施方面存在关键漏洞。

ABSTRACT

Ransomware operations have evolved from relatively unsophisticated threat actors into highly coordinated cybercrime syndicates that regularly extort millions of dollars in a single attack. Despite dominating headlines and crippling businesses across the globe, there is relatively little in-depth research into the modern structure and economics of ransomware operations. In this paper, we leverage leaked chat messages to provide an in-depth empirical analysis of Conti, one of the largest ransomware groups. By analyzing these chat messages, we construct a picture of Conti's operations as a highly-profitable business, from profit structures to employee recruitment and roles. We present novel methodologies to trace ransom payments, identifying over $80 million in likely ransom payments to Conti and its predecessor -- over five times as much as in previous public datasets. As part of our work, we publish a dataset of 666 labeled Bitcoin addresses related to Conti and an additional 75 Bitcoin addresses of likely ransom payments. Future work can leverage this case study to more effectively trace -- and ultimately counteract -- ransomware activity.

研究动机与目标

  • 提供对Conti勒索病毒作为勒索病毒即服务(RaaS)运营模式的详细经济与组织分析。
  • 利用链上交易分析和泄露聊天记录中的行为启发式方法,识别并追踪赎金支付。
  • 绘制Conti的内部业务结构,包括角色分工、招募流程和薪酬制度。
  • 发布一个包含666个与Conti相关的比特币地址的标注数据集,供未来研究和执法机构使用。
  • 识别其金融基础设施中的系统性漏洞,特别是对KYC合规交易所的依赖。

提出的方法

  • 从泄露的聊天记录中人工标注666个比特币地址,以分类其功能(例如:薪资、报销、赎金支付)。
  • 应用链上交易分析,估算总收入、运营成本以及各角色的薪资分配。
  • 开发一种新方法,基于运营商与从犯之间的常见拆分行为来检测赎金支付。
  • 使用Crystal Blockchain的取证工具关联地址并聚类交易,提升可追溯性。
  • 对聊天记录进行定性分析,以重建组织角色、招募流程和内部沟通模式。
  • 将支付流与已知交易所(例如:Gemini、Binance)交叉比对,识别高风险的集中式资金提取点。
Figure 1: An example of splitting. This address received 22 Bitcoin from the US-based Gemini exchange, and split into 25% and 75%. 1 Bitcoin from this address would eventually be sent to an address in the leak. Other funds were transferred to other illicit entities, such as the sanctioned exchange G
Figure 1: An example of splitting. This address received 22 Bitcoin from the US-based Gemini exchange, and split into 25% and 75%. 1 Bitcoin from this address would eventually be sent to an address in the leak. Other funds were transferred to other illicit entities, such as the sanctioned exchange G

实验结果

研究问题

  • RQ1如何利用链上交易模式和行为启发式方法可靠地识别勒索病毒运营中的赎金支付?
  • RQ2Conti的实际赎金支付规模有多大?与以往公开数据集相比如何?
  • RQ3Conti勒索病毒团伙内部的业务结构和操作角色是什么?
  • RQ4Conti的金融实践(如薪资发放)如何暴露其运营安全中的漏洞?
  • RQ5像Gemini和Binance这样的集中式交易所,在追踪和阻断勒索病毒资金方面在多大程度上构成关键杠杆点?

主要发现

  • 本研究识别出8390万美元的疑似赎金支付给Conti及其前身——这一数额是以往公开数据集中金额的五倍以上。
  • 超过90%的已识别Conti支付通过两家交易所完成:一家未识别的交易所和Gemini,这两家均执行客户身份识别(KYC)规定。
  • 该团伙因通过KYC合规交易所路由薪资和赎金支付,表现出极差的运营安全,从而留下可追踪的金融足迹。
  • 分析揭示了一个结构化的RaaS商业模式,包含明确的角色分工、招募流程和薪酬等级,表明其为高度组织化的网络犯罪集团。
  • 本研究发布了包含666个标注比特币地址及75个额外赎金支付地址的数据集,供未来研究和执法机构使用。
  • 研究结果表明,针对组织领导者和金融基础设施(尤其是基于交易所的资金提取)实施打击,是破坏勒索病毒运营的高杠杆策略。
Figure 2: The largest discovered likely payment, of $9.5M in March 2020. The funds originated from the unlabeled cluster discussed in Section IV .
Figure 2: The largest discovered likely payment, of $9.5M in March 2020. The funds originated from the unlabeled cluster discussed in Section IV .

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。