Hack for Hire: Exploring the Emerging Market for Account Hijacking

Hack for Hire: Exploring the Emerging Market for Account Hijacking
复制标题

DOI:
10.1145/3308558.3313489
复制
发表时间:
2019-05
期刊:
The World Wide Web Conference
影响因子:
--
通讯作者:
A. Mirian;Joe DeBlasio;S. Savage;G. Voelker;Kurt Thomas
A. Mirian;Joe DeBlasio;S. Savage;G. Voelker;Kurt Thomas
中科院分区:
其他
文献类型:
--
作者:
A. Mirian;Joe DeBlasio;S. Savage;G. Voelker;Kurt Thomas

文献摘要

相似文献

电子邮件帐户对于攻击者来说是一个诱人的目标,因为它们包含的信息以及它们向其他连接的Web服务提供的信任根。虽然网络钓鱼检测、风险分析和双因素身份验证等深度防御方法有助于阻止大规模劫持,但由于涉及定制和工作,有针对性的攻击仍然是一个强大的威胁。在本文中,我们研究了一部分被称为“hack for hire”服务的目标攻击者,以了解攻击者用于访问受害者帐户的剧本。我们以买家的身份与27家英国、俄罗斯和中国的黑市服务进行了互动,其中只有5家成功攻击了我们控制的合成(尽管是真实的)身份。攻击者主要依靠量身定制的网络钓鱼消息,其复杂程度足以绕过SMS双因素身份验证。然而,尽管有能力成功地提供帐户访问,市场表现出低容量,差的客户服务,并有多个骗子。因此,我们认为零售电子邮件劫持尚未成熟到其他犯罪细分市场的水平。
Email accounts represent an enticing target for attackers, both for the information they contain and the root of trust they provide to other connected web services. While defense-in-depth approaches such as phishing detection, risk analysis, and two-factor authentication help to stem large-scale hijackings, targeted attacks remain a potent threat due to the customization and effort involved. In this paper, we study a segment of targeted attackers known as “hack for hire” services to understand the playbook that attackers use to gain access to victim accounts. Posing as buyers, we interacted with 27 English, Russian, and Chinese blackmarket services, only five of which succeeded in attacking synthetic (though realistic) identities we controlled. Attackers primarily relied on tailored phishing messages, with enough sophistication to bypass SMS two-factor authentication. However, despite the ability to successfully deliver account access, the market exhibited low volume, poor customer service, and had multiple scammers. As such, we surmise that retail email hijacking has yet to mature to the level of other criminal market segments.