Impersonation-as-a-Service: Characterizing the Emerging Criminal Infrastructure for User Impersonation at Scale
Michele Campobasso, Luca Allodi
Abstract
In this paper we provide evidence of an emerging criminal infrastructure enabling impersonation attacks at scale. Impersonation-as-a-Service (IMPaaS) allows attackers to systematically collect and enforce user profiles (consisting of user credentials, cookies, device and behavioural fingerprints, and other metadata) to circumvent risk-based authentication system and effectively bypass multi-factor authentication mechanisms. We present the IMPaaS model and evaluate its implementation by analysing the operation of a large, invite-only, Russian IMPaaS platform providing user profiles for more than 260,000 Internet users worldwide. Our findings suggest that the IMPaaS model is growing, and provides the mechanisms needed to systematically evade authentication controls across multiple platforms, while providing attackers with a reliable, up-to-date, and semi-automated environment enabling target selection and user impersonation against Internet users as scale.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 62921e63-ae98-4e83-8425-425926895258Cited by top-tier papers12
- Is Real-time Phishing Eliminated with FIDO? Social Engineering Downgrade Attacks against FIDO ProtocolsEnis Ulqinaku, Hala Assal, AbdelRahman Abdou, Sonia Chiasson et al.USENIX Security 2021 · 42 citations
- FAMOS: Robust Privacy-Preserving Authentication on Payment Apps via Federated Multi-Modal Contrastive LearningYifeng Cai, Ziqi Zhang, Jiaping Gui, Bingyan Liu et al.USENIX Security 2024 · 6 citations
- Stayin' Alive: How Global Stolen Data Markets Thrive on TelegramTina Marjanov, Taro Tsuchiya, Konstantinos Ioannidis, Jack Hughes et al.USENIX Security 2026 · 2 citations
- Ready Raider One: Exploring the Misuse of Cloud Gaming ServicesGuannan Liu, Daiping Liu, Shuai Hao, Xing Gao et al.CCS 2022 · 2 citations
- SoK: Digging into the Digital Underworld of Stolen Data MarketsTina Marjanov, Alice HutchingsS&P 2025
Builds on5
- Data Breaches, Phishing, or Malware?: Understanding the Risks of Stolen CredentialsKurt Thomas, Frank Li, Ali Zand, Jacob Barrett et al.CCS 2017 · 248 citations
- Who Are You? A Statistical Approach to Measuring User AuthenticityDavid Freeman, Sakshi Jain, Markus Dürmuth, Battista Biggio et al.NDSS 2016 · 151 citations
- Clinical Computer Security for Victims of Intimate Partner ViolenceSam Havron, Diana Freed, Rahul Chatterjee, Damon McCoy et al.USENIX Security 2019 · 118 citations
- Detecting and Characterizing Lateral Phishing at ScaleGrant Ho, Asaf Cidon, Lior Gavish, Marco Schweighauser et al.USENIX Security 2019 · 113 citations
- Economic Factors of Vulnerability Trade and ExploitationLuca AllodiCCS 2017 · 82 citations
Related papers
- Know Your Cybercriminal: Evaluating Attacker Preferences by Measuring Profile Sales on an Active, Leading Criminal Market for User Impersonation at ScaleMichele Campobasso, Luca AllodiUSENIX Security 2023
- Phish in Sheep's Clothing: Exploring the Authentication Pitfalls of Browser FingerprintingXu Lin, Panagiotis Ilia, Saumya Solanki, Jason PolakisUSENIX Security 2022
- Having Your Cake and Eating It: An Analysis of Concession-Abuse-as-a-ServiceZhibo Sun, Adam Oest, Penghui Zhang, Carlos E. Rubio-Medrano et al.USENIX Security 2021 · 16 citations
- A Study of Multi-Factor and Risk-Based Authentication AvailabilityAnthony Gavazzi, Ryan Williams, Engin Kirda, Long Lu et al.USENIX Security 2023
- Pre-hijacked accounts: An Empirical Study of Security Failures in User Account Creation on the WebAvinash Sudhodanan, Andrew PaverdUSENIX Security 2022
