Tracking Ransomware End-to-end
Danny Yuxing Huang, Maxwell Matthaios Aliapoulios, Vector Guo Li, Luca Invernizzi, Elie Bursztein, Kylie McRoberts, Jonathan Levin, Kirill Levchenko, Alex C. Snoeren, Damon McCoy
Abstract
Ransomware is a type of malware that encrypts the files of infected hosts and demands payment, often in a cryptocurrency such as Bitcoin. In this paper, we create a measurement framework that we use to perform a large-scale, two-year, end-to-end measurement of ransomware payments, victims, and operators. By combining an array of data sources, including ransomware binaries, seed ransom payments, victim telemetry from infections, and a large database of Bitcoin addresses annotated with their owners, we sketch the outlines of this burgeoning ecosystem and associated third-party infrastructure. In particular, we trace the financial transactions, from the moment victims acquire bitcoins, to when ransomware operators cash them out. We find that many ransomware operators cashed out using BTC-e, a now-defunct Bitcoin exchange. In total we are able to track over $16 million in likely ransom payments made by 19,750 potential victims during a two-year period. While our study focuses on ransomware, our methods are potentially applicable to other cybercriminal operations that have similarly adopted Bitcoin as their payment channel.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers25
- Cybercriminal Minds: An investigative study of cryptocurrency abuses in the Dark WebSeunghyeon Lee, Changhoon Yoon, Heedo Kang, Yeonkeun Kim et al.NDSS 2019 · 100 citations
- Plug and Prey? Measuring the Commoditization of Cybercrime via Online Anonymous MarketsRolf van Wegberg, Samaneh Tajalizadehkhoob, Kyle Soska, Ugur Akyazi et al.USENIX Security 2018 · 97 citations
- Survivalism: Systematic Analysis of Windows Malware Living-Off-The-LandFrederick Barr-Smith, Xabier Ugarte-Pedrero, Mariano Graziano, Riccardo Spolaor et al.S&P 2021 · 73 citations
- Malla: Demystifying Real-world Large Language Model Integrated Malicious ServicesZilong Lin, Jian Cui, Xiaojing Liao, XiaoFeng WangUSENIX Security 2024 · 49 citations
- Analyzing Ground-Truth Data of Mobile Gambling ScamsGeng Hong, Zhemin Yang, Sen Yang, Xiaojing Liao et al.S&P 2022 · 29 citations
Builds on2
- UNVEIL: A Large-Scale, Automated Approach to Detecting RansomwareAmin Kharraz, Sajjad Arshad, Collin Mulliner, William K. Robertson et al.USENIX Security 2016
- BlockSci: Design and applications of a blockchain analysis platformHarry A. Kalodner, Malte Möser, Kevin Lee, Steven Goldfeder et al.USENIX Security 2020
Related papers
- Cybercrime Bitcoin Revenue Estimations: Quantifying the Impact of Methodology and CoverageGibran Gómez, Kevin van Liebergen, Juan CaballeroCCS 2023 · 10 citations
- The Ransomware Decade: The Creation of a Fine-Grained Dataset and a Longitudinal StudyArmin Sarabi, Ziyuan Huang, Chenlan Wang, Tai Karir et al.USENIX Security 2025
- Watch Your Back: Identifying Cybercrime Financial Relationships in Bitcoin through Back-and-Forth ExplorationGibran Gómez, Pedro Moreno-Sanchez, Juan CaballeroCCS 2022 · 19 citations
- Double and Nothing: Understanding and Detecting Cryptocurrency Giveaway ScamsXigao Li, Anurag Yepuri, Nick NikiforakisNDSS 2023
- BSHUNTER: Detecting and Tracing Defects of Bitcoin ScriptsPeilin Zheng, Xiapu Luo, Zibin ZhengICSE 2023 · 6 citations
