Leveraging Bitcoin Testnet for Bidirectional Botnet Command and Control Systems
Federico Franzoni, Ivan Abellan, Vanesa Daza

TL;DR
This paper demonstrates how Bitcoin Testnet can be used to establish a cost-free, encrypted, bidirectional command and control channel for botnets, posing a significant threat to cybersecurity.
Contribution
It introduces a novel protocol leveraging Bitcoin Testnet for bidirectional, encrypted botnet C&C communication, overcoming previous limitations of cost and data transmission.
Findings
Bitcoin Testnet enables cost-free C&C channels
The protocol supports bidirectional encrypted communication
It demonstrates a realistic, hard-to-disrupt botnet control method
Abstract
Over the past twenty years, the number of devices connected to the Internet grew exponentially. Botnets benefited from this rise to increase their size and the magnitude of their attacks. However, they still have a weak point in their Command & Control (C&C) system, which is often based on centralized services or require a complex infrastructure to keep operating without being taken down by authorities. The recent spread of blockchain technologies may give botnets a powerful tool to make them very hard to disrupt. Recent research showed how it is possible to embed C&C messages in Bitcoin transactions, making them nearly impossible to block. Nevertheless, transactions have a cost and allow very limited amounts of data to be transmitted. Because of that, only messages from the botmaster to the bots are sent via Bitcoin, while bots are assumed to communicate through external channels.…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
