USENIX Security2021Top-tier venue
Having Your Cake and Eating It: An Analysis of Concession-Abuse-as-a-Service
Zhibo Sun, Adam Oest, Penghui Zhang, Carlos E. Rubio-Medrano, Tiffany Bao, Ruoyu Wang, Ziming Zhao, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn
Abstract
Concession Abuse as a Service (CAaaS) is a growing scam service in underground forums that defrauds online retailers through the systematic abuse of their return policies (via social engineering) and the exploitation of loopholes in company protocols. Timely detection of such scams is difficult as they are fueled by an extensive suite of criminal services, such as credential theft, document forgery, and fake shipments. Ultimately, the scam enables malicious actors to steal arbitrary goods from merchants with minimal investment. In this paper, we perform in-depth manual and automated analysis of public and private messages from four large underground forums to identify the malicious actors involved in CAaaS, carefully study the operation of the scam, and define attributes to fingerprint the scam and inform mitigation strategies. Additionally, we surveyed users to evaluate their attitudes toward these mitigations and understand the factors that merchants should consider before implementing these strategies. We find that the scam is easy to scale-and can bypass traditional anti-fraud efforts-and thus poses a notable threat to online retailers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 94977a9c-acc5-4452-98a7-4e365ece3752Cited by top-tier papers5
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- All Your Shops Are Belong to Us: Security Weaknesses in E-commerce PlatformsRohan Pagey, Mohammad Mannan, Amr M. YoussefWWW 2023 · 10 citations
- Understanding and Analyzing Appraisal Systems in the Underground MarketplacesZhengyi Li, Xiaojing LiaoNDSS 2024
- The Dark Side of E-Commerce: Dropshipping Abuse as a Business ModelArjun Arunasalam, Andrew Chu, Muslum Ozgur Ozmen, Habiba Farrukh et al.NDSS 2024
- SoK: A Privacy Framework for Security Research Using Social Media DataKyle Beadle, Kieron Ivy Turk, Aliai Eusebi, Mindy Tran et al.S&P 2025
Builds on8
- Fast, Lean, and Accurate: Modeling Password Guessability Using Neural NetworksWilliam Melicher, Blase Ur, Sean M. Segreti, Saranga Komanduri et al.USENIX Security 2016 · 331 citations
- Data Breaches, Phishing, or Malware?: Understanding the Risks of Stolen CredentialsKurt Thomas, Frank Li, Ali Zand, Jacob Barrett et al.CCS 2017 · 248 citations
- PhishFarm: A Scalable Framework for Measuring the Effectiveness of Evasion Techniques against Browser Phishing BlacklistsAdam Oest, Yeganeh Safaei, Adam Doupé, Gail-Joon Ahn et al.S&P 2019 · 129 citations
- Resident Evil: Understanding Residential IP Proxy as a Dark ServiceXianghang Mi, Xuan Feng, Xiaojing Liao, Baojun Liu et al.S&P 2019 · 80 citations
- Towards Measuring and Mitigating Social Engineering Software Download AttacksTerry Nelms, Roberto Perdisci, Manos Antonakakis, Mustaque AhamadUSENIX Security 2016 · 70 citations
Related papers
- Impersonation-as-a-Service: Characterizing the Emerging Criminal Infrastructure for User Impersonation at ScaleMichele Campobasso, Luca AllodiCCS 2020 · 24 citations
- Doxing-as-a-Service: Demystifying the Chinese Online Doxing EcosystemYiran Gao, Pengcheng Xia, Liu Wang, Tianming Liu et al.WWW 2026
- Scalable Detection of Promotional Website Defacements in Black Hat SEO CampaignsRonghai Yang, Xianbo Wang, Cheng Chi, Dawei Wang et al.USENIX Security 2021 · 27 citations
- WARDEN: Multi-Directional Backdoor Watermarks for Embedding-as-a-Service Copyright ProtectionAnudeex Shetty, Yue Teng, Ke He, Qiongkai XuACL 2024
- Lurking Malice in the Cloud: Understanding and Detecting Cloud Repository as a Malicious ServiceXiaojing Liao, Sumayah A. Alrwais, Kan Yuan, Luyi Xing et al.CCS 2016 · 16 citations
