Watch Your Back: Identifying Cybercrime Financial Relationships in Bitcoin through Back-and-Forth Exploration
Gibran Gómez, Pedro Moreno-Sanchez, Juan Caballero
Abstract
Cybercriminals often leverage Bitcoin for their illicit activities. In this work, we propose back-and-forth exploration, a novel automated Bitcoin transaction tracing technique to identify cybercrime financial relationships. Given seed addresses belonging to a cybercrime campaign, it outputs a transaction graph, and identifies paths corresponding to relationships between the campaign under study and external services and other cybercrime campaigns. Back-andforth exploration provides two key contributions. First, it explores both forward and backwards, instead of only forward as done by prior work, enabling the discovery of relationships that cannot be found by only exploring forward (e.g., deposits from clients of a mixer). Second, it prevents graph explosion by combining a tagging database with a machine learning classifier for identifying addresses belonging to exchanges. We evaluate back-and-forth exploration on 30 malware families. We build oracles for 4 families using Bitcoin for C&C and use them to demonstrate that back-and-forth exploration identifies 13 C&C signaling addresses missed by prior work, 8 of which are fundamentally missed by forward-only explorations. Our approach uncovers a wealth of services used by the malware including 44 exchanges, 11 gambling sites, 5 payment service providers, 4 underground markets, 4 mining pools, and 2 mixers. In 4 families, the relations include new attribution points missed by forward-only explorations. It also identifies relationships between the malware families and other cybercrime campaigns, highlighting how some malware operators participate in a variety of cybercriminal activities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 16a8ad63-25d1-49f0-930a-fb51bd0e4facCited by top-tier papers8
- Cybercrime Bitcoin Revenue Estimations: Quantifying the Impact of Methodology and CoverageGibran Gómez, Kevin van Liebergen, Juan CaballeroCCS 2023 · 10 citations
- Detecting and Understanding the Promotion of Illicit Goods and Services on TwitterHongyu Wang, Ying Li, Ronghong Huang, Xianghang MiWWW 2025 · 6 citations
- Evasion Under Blockchain SanctionsEndong Liu, Mark Ryan, Liyi Zhou, Pascal BerrangWWW 2026 · 1 citation
- Ctrl+Alt+Deceive: Quantifying User Exposure to Online ScamsPlaton Kotzias, Michalis Pachilakis, Javier Aldana-Iuit, Juan Caballero et al.NDSS 2025
- Ghost Clusters: Evaluating Attribution of Illicit Services through Cryptocurrency TracingKelvin Lubbertsen, Michel van Eeten, Rolf van WegbergUSENIX Security 2025
Builds on4
- Acing the IOC Game: Toward Automatic Discovery and Analysis of Open-Source Cyber Threat IntelligenceXiaojing Liao, Kan Yuan, XiaoFeng Wang, Zhou Li et al.CCS 2016 · 308 citations
- Tracking Ransomware End-to-endDanny Yuxing Huang, Maxwell Matthaios Aliapoulios, Vector Guo Li, Luca Invernizzi et al.S&P 2018 · 208 citations
- Cybercriminal Minds: An investigative study of cryptocurrency abuses in the Dark WebSeunghyeon Lee, Changhoon Yoon, Heedo Kang, Yeonkeun Kim et al.NDSS 2019 · 100 citations
- BlockSci: Design and applications of a blockchain analysis platformHarry A. Kalodner, Malte Möser, Kevin Lee, Steven Goldfeder et al.USENIX Security 2020
Related papers
- Demystifying Bitcoin Address Behavior via Graph Neural NetworksZhengjie Huang, Yunyang Huang, Peng Qian, Jianhai Chen et al.ICDE 2023 · 16 citations
- BEAGLE: Forensics of Deep Learning Backdoor Attack for Better DefenseSiyuan Cheng, Guanhong Tao, Yingqi Liu, Shengwei An et al.NDSS 2023
- Chainlet Orbits: Topological Address Embedding for BlockchainPoupak Azad, Baris Coskunuzer, Murat Kantarcioglu, Cuneyt Gurcan AkcoraKDD 2025
- Combating Dependence Explosion in Forensic Analysis Using Alternative Tag Propagation SemanticsMd Nahid Hossain, Sanaz Sheikhi, R. SekarS&P 2020 · 179 citations
- Forecasting Malware Capabilities From Cyber Attack Memory ImagesOmar Alrawi, Moses Ike, Matthew Pruett, Ranjita Pai Kasturi et al.USENIX Security 2021 · 32 citations
