Unveiling Dynamics and Patterns: A Comprehensive Analysis of Spreading Patterns and Similarities in Low-Labelled Ransomware Families
Francesco Zola, Mikel Gorricho, Jon Ander Medina, Lander Segurola,, Raul Orduna-Urrutia

TL;DR
This paper analyzes Bitcoin transaction graphs of low-labelled ransomware families to identify payment patterns and similarities, revealing potential common control mechanisms and aiding in understanding ransomware evolution and operations.
Contribution
It introduces a novel method for analyzing address behaviors in transaction graphs to detect similarities among ransomware strains, enhancing understanding of their operational mechanisms.
Findings
Ransomware families can connect with millions of addresses rapidly.
Multiple-step analysis is often needed to understand connections.
Behaviors can effectively reveal similarities among different strains.
Abstract
Ransomware has become one of the most widespread threats, primarily due to its easy deployment and the accessibility to services that enable attackers to raise and obfuscate funds. This latter aspect has been significantly enhanced with the advent of cryptocurrencies, which, by fostering decentralisation and anonymity, have transformed this threat into a large-scale outbreak. However, recent reports indicate that a small group of individuals dominate the ransomware ecosystem and try to obfuscate their activity using multiple strains characterised by a short time to live. This scenario suggests that different strains could share mechanisms in ransom collection, fund movement, and money laundering operations. For this reason, this study aims to analyse the address-transaction graphs generated in the Bitcoin network by low-labelled ransomware families. Our goals are to identify payment…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Cybercrime and Law Enforcement Studies · Spam and Phishing Detection
