论文标题
不要在陷入困境的水中钓鱼!表征以冠状病毒为主题的加密货币骗局
Don't Fish in Troubled Waters! Characterizing Coronavirus-themed Cryptocurrency Scams
论文作者
论文摘要
自2020年初以来,由于Covid-19 1920年初一直在世界各地蔓延,因此越来越多的恶意运动使Covid-19的主题大写。 Covid-199主题加密货币骗局在大流行期间越来越受欢迎。但是,我们社区对这些新出现的骗局的理解很少。在本文中,我们介绍了COVID-19的首次测量研究,主题是加密货币骗局。我们首先通过手动分析用户在线资源报告的现有骗局来创建COVID-19骗局的全面分类。然后,我们提出了一种混合方法来进行调查:1)在野外收集报告的骗局; 2)基于从可疑实体(例如域,推文等)收集的信息检测未公开的信息。我们已经收集了195个确认的Covid-19,共计195个加密货币骗局,其中包括91个令牌骗局,19个赠品骗局,9个勒索骗局,14个加密赛恶意软件骗局,9个庞氏骗局计划骗局和53个捐赠骗局。然后,我们确定了200多个与这些骗局相关的区块链地址,这导致了6,329名受害者至少3.3万美元的损失。对于每种类型的骗局,我们进一步研究了他们使用的技巧和社会工程技术。为了促进未来的研究,我们已将所有标签型骗局发布给研究界。
As COVID-19 has been spreading across the world since early 2020, a growing number of malicious campaigns are capitalizing the topic of COVID-19. COVID-19 themed cryptocurrency scams are increasingly popular during the pandemic. However, these newly emerging scams are poorly understood by our community. In this paper, we present the first measurement study of COVID-19 themed cryptocurrency scams. We first create a comprehensive taxonomy of COVID-19 scams by manually analyzing the existing scams reported by users from online resources. Then, we propose a hybrid approach to perform the investigation by: 1) collecting reported scams in the wild; and 2) detecting undisclosed ones based on information collected from suspicious entities (e.g., domains, tweets, etc). We have collected 195 confirmed COVID-19 cryptocurrency scams in total, including 91 token scams, 19 giveaway scams, 9 blackmail scams, 14 crypto malware scams, 9 Ponzi scheme scams, and 53 donation scams. We then identified over 200 blockchain addresses associated with these scams, which lead to at least 330K US dollars in losses from 6,329 victims. For each type of scams, we further investigated the tricks and social engineering techniques they used. To facilitate future research, we have released all the well-labelled scams to the research community.