Dark Matter: Uncovering the DarkComet RAT Ecosystem
Brown Farinholt, Mohammad Rezaeirad, Damon McCoy, Kirill Levchenko
摘要
Remote Access Trojans (RATs) are a persistent class of malware that give an attacker direct, interactive access to a victim's personal computer, allowing the attacker to steal private data, spy on the victim in real-time using the camera and microphone, and verbally harass the victim through the speaker. To date, the users and victims of this pernicious form of malware have been challenging to observe in the wild due to the unobtrusive nature of infections. In this work, we report the results of a longitudinal study of the DarkComet RAT ecosystem. Using a known method for collecting victim log databases from DarkComet controllers, we present novel techniques for tracking RAT controllers across hostname changes and improve on established techniques for filtering spurious victim records caused by scanners and sandboxed malware executions. We downloaded 6,620 DarkComet databases from 1,029 unique controllers spanning over 5 years of operation. Our analysis shows that there have been at least 57,805 victims of DarkComet over this period, with 69 new victims infected every day; many of whose keystrokes have been captured, actions recorded, and webcams monitored during this time. Our methodologies for more precisely identifying campaigns and victims could potentially be useful for improving the efficiency and efficacy of victim cleanup efforts and prioritization of law enforcement investigations. CCS CONCEPTS • Security and privacy → Malware and its mitigation.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper6
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard 等USENIX Security 2017 · 被引用 2,003 次
- The Spyware Used in Intimate Partner ViolenceRahul Chatterjee, Periwinkle Doerfler, Hadas Orgad, Sam Havron 等S&P 2018 · 被引用 167 次
- Cleaning Up the Internet of Evil Things: Real-World Evidence on ISP and Consumer Efforts to Remove MiraiOrçun Çetin, Carlos Gañán, Lisette Altena, Takahiro Kasama 等NDSS 2019 · 被引用 57 次
- To Catch a Ratter: Monitoring the Behavior of Amateur DarkComet RAT Operators in the WildBrown Farinholt, Mohammad Rezaeirad, Paul Pearce, Hitesh Dharmdasani 等S&P 2017 · 被引用 48 次
- Schrödinger's RAT: Profiling the Stakeholders in the Remote Access Trojan EcosystemMohammad Rezaeirad, Brown Farinholt, Hitesh Dharmdasani, Paul Pearce 等USENIX Security 2018 · 被引用 22 次
相关 Paper
- All your (data)base are belong to us: Characterizing Database Ransom(ware) AttacksKevin van Liebergen, Gibran Gómez, Srdjan Matic, Juan CaballeroNDSS 2025
- An Empirical Study of Data Disruption by Ransomware AttacksYiwei Hou, Lihua Guo, Chijin Zhou, Yiwen Xu 等ICSE 2024 · 被引用 10 次
- Investigating Package Related Security Threats in Software RegistriesYacong Gu, Lingyun Ying, Yingyuan Pu, Xiao Hu 等S&P 2023
- C3PO: Large-Scale Study Of Covert Monitoring of C&C Servers via Over-Permissioned Protocol InfiltrationJonathan Fuller, Ranjita Pai Kasturi, Amit Kumar Sikder, Haichuan Xu 等CCS 2021 · 被引用 6 次
- Lessons Learned from Operating a Large Network TelescopeAlexander Männel, Jonas Mücke, K. C. Claffy, Max Gao 等SIGCOMM 2025 · 被引用 9 次
