Measurement of the Usage of Web Clips in Underground Economy
Qinyu Hu, Songyang Wu, Wenqi Sun, Zhushou Tang, Chaofan Chen, Zhiguo, Ding, Xiaomei Zhang

TL;DR
This study investigates the ecosystem of malicious Web Clips used in cyber crimes on iOS devices, revealing their main participants, usage patterns, and mitigation strategies to aid cybersecurity efforts.
Contribution
The paper provides a detailed analysis of the abused Web Clips ecosystem, including participant roles, technical features, and detection evasion tactics, which is novel in understanding this underground activity.
Findings
SSL certificates are predominantly used for signing malicious Web Clips.
Content categories include gambling, fraud, and pornography.
Web Clips are mainly propagated via instant messaging and live streaming platforms.
Abstract
In this paper, we study the ecosystem of the abused Web Clips in underground economy. Through this study, we find the Web Clips is wildly used by perpetrators to penetrate iOS devices to gain profit. This work starts with 1,800 user complaint documents about cyber crimes over Web Clips. We firstly look into the ecosystem of abused Web Clips and point out the main participants and workflow. In addition, what is the Web Clips used for is demystified. Then the main participants, including creators, distributors, and operators are deeply studied based on our dataset. We try to reveal the prominent features of the illicit Web Clips and give some mitigation measures. Analysis reveals that 1) SSL certificate is overwhelmingly preferred for signing Web Clips instances compared with certificate issued by Apple. The wildly used SSL certificates can be aggregated into a limited group. 2) The…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCybercrime and Law Enforcement Studies · Spam and Phishing Detection · Crime, Illicit Activities, and Governance
