Why them? Extracting intelligence about target selection from Zeus financial malware
Samaneh Tajalizadehkhoob, Hadi Asghari, Carlos Gañán, Michel J. G. van Eeten · Research Repository (Delft University of Technology) · 2014
Malware is used for online payment fraud that causes millions of Euros in damages each year.Not every payment service provider is equally popular among cybercriminals.This paper explores the incentives and strategies of attackers by analyzing the instructions sent to machines infected with Zeus malware between 2009-2013Q1.We investigated around 11,000 configuration files targeting 1.2 million URLs on 2,412 unique domains.We also developed metrics to rank the relative attractiveness of domains as a target.We found that attacks are concentrated: around 15% of the domains attract 90% of the attacks.Concentration is not driven just by target size.Approximating the size of the payment service provider via financial data from the FDIC and traffic rankings from Alexa, we observe that size is a threshold for getting attacked, but does not predict the intensity of attack.Attack persistence also varies widely.Half of the domains are targeted briefly (four weeks or less), which we believe is part of a process of trial--and--error to seek new targets.Surprisingly enough, even though new domains are tried continuously, a ceiling exists in the overall number of domains simultaneously attacked.This suggests bottlenecks elsewhere in the criminal value chain, e.g., in the recruitment of money mules.The ceiling remained in place even after the Zeus source code was leaked, lowering the entry barriers for new attackers.Next, we examined how inject code has evolved over time.Using a cosine similarity metric, we compared the 1.2 million inject codes, and observe that the vast majority of the inject code is repeated many times, with just 1% being never repeated.On average, across all Zeus botnets and attackers, code similarity is well over 90% from one attack to the next.This suggests code sharing, selling, or stealing among attackers.This, again, suggest low entry barriers as well as low development costs.Interestingly enough, these do not translate into growing attack levels.A more general implication of these findings could be that the underground market for malware--as--a--service, often portrayed as making attacks cheaper to execute, is not driving the attack volume or the selection of targets.Future work is needed to flesh out more precisely these mechanisms.