In recent years,with the rise of the mobile Internet,underground mobile applications primarily involved in scams,gambling,and pornography have become more rampant,requiring effective control measures.Currently,there is a lack of research on underground applications by researchers.Due to the continuous crackdown by law enforcement agencies on traditional distribution channels for these applications,the existing collection methods based on search engines and app stores have proven to be ineffective.The lack of large-scale and representative datasets of real-world underground applications has become a major constraint for in-depth research.Therefore,this study aims to address the challenge of collection of large-scale real-world underground applications,providing data support for a comprehensive in-depth analysis of these applications and their ecosystem.A method is proposed to capture underground applications based on traffic analysis.By focusing on the key distribution channels of underground applications and leveraging their characteristics of mutation and accompanying traffic,underground applications can be discovered in the propagation stage.In the test,the proposed method successfully obtained 3 439 application download links and 3 303 distinct applications.Among these apps,91.61%of the samples were labeled as malware by antivirus engine,while 98.14%of the samples were zero-days.The results demonstrate the effectiveness of the proposed method in the collection of underground applications.
As a new type of underground ecosystem, the exploitation of Abused IHMs as MalIcious sErvices (AIMIEs) is becoming increasingly prevalent among miscreants to host illegal images and propagate harmful content. However, there has been little effort to understand this new menace, in terms of its magnitude, impact, and techniques, not to mention any serious effort to detect vulnerable image hosting modules on a large scale. To fulfill this gap, this paper presents the first measurement study of AIMIEs. By collecting and analyzing 89 open-sourced AIMIEs, we reveal the landscape of AIMIEs, report the evolution and evasiveness of abused image hosting APIs from reputable companies such as Alibaba, Tencent, and Bytedance, and identify real-world abused images uploaded through those AIMIEs. In addition, we propose a tool, called Viola, to detect vulnerable image hosting modules (IHMs) in the wild. We find 477 vulnerable IHM upload APIs associated with 338 web services, which integrated vulnerable IHMs, and 207 victim FQDNs. The highest-ranked domain with vulnerable web service is baidu.com, followed by bilibili.com and 163.com. We have reported abused and vulnerable IHM upload APIs and received acknowledgments from 69 of them by the time of paper submission.
Cryptocurrencies have attracted extensive attention from malicious actors. Numerous studies have reported various cyber attacks and scams targeting this domain. This paper takes the first step to characterize the visual scams occurring within cryptocurrency wallets. Scammers exploit deceptive visual features – specifically, the omission of detailed information on the wallet’s interface such as wallet addresses, cryptocurrency tokens, and smart contract names, to confuse or mislead users. This could potentially lead users to carry out unintended transactions. By analyzing 169,680,580 transactions between December 2022 and May 2023, we identified 5,515,896 instances of fake token scams, 15,807 instances of function name scams, and 89,681,248 instances of zero transfer scams. Our analysis reveals that over 240,000 victims have been affected by these visual scam attacks, resulting in losses exceeding $43 million. These substantial figures emphasize the severity of these deceptive tactics and underline the urgent need for effective protective measures.