Denis Maslennikov, Senior Malware Analyst, Kaspersky Lab
15.06.2011, 23rd Annual FIRST Conference, Vienna, Austria
The Underground Economy and Ecosystem of SMS Based Cybercrime Denis - - PowerPoint PPT Presentation
The Underground Economy and Ecosystem of SMS Based Cybercrime Denis Maslennikov, Senior Malware Analyst, Kaspersky Lab 15.06.2011, 23 rd Annual FIRST Conference, Vienna, Austria Agenda SMS based threats Ransomware SMS Trojans The
Denis Maslennikov, Senior Malware Analyst, Kaspersky Lab
15.06.2011, 23rd Annual FIRST Conference, Vienna, Austria
Agenda
| June 15, 2011 PAGE 2 | 23rd Annual FIRST Conference
Lottery
| June 15, 2011 PAGE 3 | 23rd Annual FIRST Conference
How much have users lost?
| June 15, 2011 PAGE 4 | 23rd Annual FIRST Conference
Ransomware
In a nutshell
| June 15, 2011 PAGE 6 | 23rd Annual FIRST Conference
Ransomware
In a nutshell
| June 15, 2011 PAGE 7 | 23rd Annual FIRST Conference
Ransomware
Variety
| June 15, 2011 PAGE 8 | 23rd Annual FIRST Conference
Ransomware
Variety
| June 15, 2011 PAGE 9 | 23rd Annual FIRST Conference
Ransomware
Variety
| June 15, 2011 PAGE 10 | 23rd Annual FIRST Conference
Ransomware
Variety
| June 15, 2011 PAGE 11 | 23rd Annual FIRST Conference
Ransomware
Variety
| June 15, 2011 PAGE 12 | 23rd Annual FIRST Conference
Ransomware
Variety
| June 15, 2011 PAGE 13 | 23rd Annual FIRST Conference
Ransomware
Variety
| June 15, 2011 PAGE 14 | 23rd Annual FIRST Conference
Ransomware
Variety
| June 15, 2011 PAGE 15 | 23rd Annual FIRST Conference
Psychological tricks
| June 15, 2011 PAGE 16 | 23rd Annual FIRST Conference
What do they want?
| June 15, 2011 PAGE 17 | 23rd Annual FIRST Conference
Deblocker
| June 15, 2011 PAGE 18 | 23rd Annual FIRST Conference
Deblocker
| June 15, 2011 PAGE 19 | 23rd Annual FIRST Conference
Deblocker service statistics
| June 15, 2011 PAGE 20 | 23rd Annual FIRST Conference
Source: Kaspersky Lab
SMS Trojans
In a nutshell
| June 15, 2011 PAGE 22 | 23rd Annual FIRST Conference
Statistics
| June 15, 2011 PAGE 23 | 23rd Annual FIRST Conference
50 100 150 200 250 300 350 2006 2007 2008 2009 2010 2011
3 11 116 212 345 336
Source: Kaspersky Lab
Statistics
| June 15, 2011 PAGE 24 | 23rd Annual FIRST Conference
8% 5% 3% 84%
Symbian Windows Mobile Android J2ME
Source: Kaspersky Lab
Primitive: Trojan-SMS.J2ME.Konov
| June 15, 2011 PAGE 25 | 23rd Annual FIRST Conference
Advanced: Trojan-SMS.J2ME.VScreener
| June 15, 2011 PAGE 26 | 23rd Annual FIRST Conference
‘Video player’
Again
| June 15, 2011 PAGE 27 | 23rd Annual FIRST Conference
‘Video player’
Again
| June 15, 2011 PAGE 28 | 23rd Annual FIRST Conference
SEO and mobile malware
| June 15, 2011 PAGE 29 | 23rd Annual FIRST Conference
SEO and mobile malware
| June 15, 2011 PAGE 30 | 23rd Annual FIRST Conference
The root of all evil
Trojan-SMS.J2ME.Konov
| June 15, 2011 PAGE 32 | 23rd Annual FIRST Conference
Trojan-SMS.J2ME.Konov
| June 15, 2011 PAGE 33 | 23rd Annual FIRST Conference
Mobile
$10 or $6 per SMS
Trojan-SMS.J2ME.Konov
| June 15, 2011 PAGE 34 | 23rd Annual FIRST Conference
Mobile
Content provider 4460 5537
Trojan-SMS.J2ME.Konov
| June 15, 2011 PAGE 35 | 23rd Annual FIRST Conference
Mobile
Content provider 4460 5537
Trojan-SMS.J2ME.Konov
| June 15, 2011 PAGE 36 | 23rd Annual FIRST Conference
Mobile
Content provider 4460 5537 Subtenant with ID 1290 ‘epbox’ renter ‘epbox’
& 5537 ‘epbox 1290’ on 4460 & 5537
Who are ‘epbox’ and ‘epbox 1290’
| June 15, 2011 PAGE 37 | 23rd Annual FIRST Conference
‘epbox’ renter ‘epbox 1290’ subtenant
Who are ‘epbox’ and ‘epbox 1290’
| June 15, 2011 PAGE 38 | 23rd Annual FIRST Conference
‘epbox’ renter ‘epbox 1290’ subtenant Affiliate network
Affiliate A
Who are ‘epbox’ and ‘epbox 1290’
| June 15, 2011 PAGE 39 | 23rd Annual FIRST Conference
‘epbox’ renter ‘epbox 1290’ subtenant Affiliate network
Affiliate C Affiliate B Affiliate A ‘epbox N’ subtenant ‘epbox M’ subtenant
The root of all evil
| June 15, 2011 PAGE 40 | 23rd Annual FIRST Conference
The root of all evil
| June 15, 2011 PAGE 41 | 23rd Annual FIRST Conference
The root of all evil
| June 15, 2011 PAGE 42 | 23rd Annual FIRST Conference
No sensitive data! Affiliate ID ‘epbox 1290’
Typical affiliate website
| June 15, 2011 PAGE 43 | 23rd Annual FIRST Conference
Typical affiliate website
| June 15, 2011 PAGE 44 | 23rd Annual FIRST Conference
Typical affiliate website
| June 15, 2011 PAGE 45 | 23rd Annual FIRST Conference
Referrer check Remote server Affiliate ID
Typical affiliate website
| June 15, 2011 PAGE 46 | 23rd Annual FIRST Conference
SMS Trojan with affiliate ID Referrer check JAR constructor Remote server Affiliate ID
Typical affiliate website
| June 15, 2011 PAGE 47 | 23rd Annual FIRST Conference
SMS Trojan with affiliate ID Referrer check JAR constructor Remote server Affiliate ID Thousands of websites!
Ransomware
Same situation
| June 15, 2011 PAGE 48 | 23rd Annual FIRST Conference
Ransomware
Same situation
| June 15, 2011 PAGE 49 | 23rd Annual FIRST Conference
…and lottery results :)
Underground economy
Revenue sharing
| June 15, 2011 PAGE 51 | 23rd Annual FIRST Conference
Infected phone/PC Mobile
Content provider The affiliate
Affiliate
Underground economy
Revenue sharing
| June 15, 2011 PAGE 52 | 23rd Annual FIRST Conference
Infected phone/PC Mobile
Content provider The affiliate
Affiliate
31-50% of SMS price SMS
Underground economy
Revenue sharing
| June 15, 2011 PAGE 53 | 23rd Annual FIRST Conference
Infected phone/PC Mobile
Content provider The affiliate
Affiliate
31-50% of SMS price 1-5% of SMS price SMS
Underground economy
Revenue sharing
| June 15, 2011 PAGE 54 | 23rd Annual FIRST Conference
Infected phone/PC Mobile
Content provider The affiliate
Affiliate
31-50% of SMS price 1-5% of SMS price 40-67% of SMS price SMS 1-5% of SMS price
$$$
| June 15, 2011 PAGE 55 | 23rd Annual FIRST Conference
$$$
| June 15, 2011 PAGE 56 | 23rd Annual FIRST Conference
‘…10 people were arrested…’ ‘…malware which blocks PC…’
$$$
| June 15, 2011 PAGE 57 | 23rd Annual FIRST Conference
‘…10 people were arrested…’ ‘…malware which blocks PC…’ ‘…half a year…’ ‘…SMS as ransom…’
$$$
| June 15, 2011 PAGE 58 | 23rd Annual FIRST Conference
‘…10 people were arrested…’ ‘…malware which blocks PC…’ ‘…half a year…’ ‘…SMS as ransom…’ ‘…1 billion rubles…’
Calculations
| June 15, 2011 PAGE 59 | 23rd Annual FIRST Conference
‘Death penalty’
| June 15, 2011 PAGE 60 | 23rd Annual FIRST Conference
Final score
| June 15, 2011 PAGE 61 | 23rd Annual FIRST Conference
Ransomware
| June 15, 2011 PAGE 63 | 23rd Annual FIRST Conference
Ransomware
| June 15, 2011 PAGE 64 | 23rd Annual FIRST Conference
Ransomware
| June 15, 2011 PAGE 65 | 23rd Annual FIRST Conference
A long time ago…
| June 15, 2011 PAGE 66 | 23rd Annual FIRST Conference
Porn SMS senders
‘Nooit spijt’ case
| June 15, 2011 PAGE 67 | 23rd Annual FIRST Conference
Porn SMS senders
‘Nooit spijt’ case
| June 15, 2011 PAGE 68 | 23rd Annual FIRST Conference
‘Dating’ apps
| June 15, 2011 PAGE 69 | 23rd Annual FIRST Conference
‘Dating’ apps
| June 15, 2011 PAGE 70 | 23rd Annual FIRST Conference
‘Dating’ apps
| June 15, 2011 PAGE 71 | 23rd Annual FIRST Conference
‘Dating’ apps
| June 15, 2011 PAGE 72 | 23rd Annual FIRST Conference
Countries
| June 15, 2011 PAGE 73 | 23rd Annual FIRST Conference
What should we do?
| June 15, 2011 PAGE 75 | 23rd Annual FIRST Conference
Denis Maslennikov, Senior Malware Analyst, Kaspersky Lab Denis.Maslennikov@kaspersky.com, @hEx63
15.06.2011, 23rd Annual FIRST Conference, Vienna, Austria