论文标题

除了病毒之外:以冠状病毒为主题的移动恶意软件

Beyond the Virus: A First Look at Coronavirus-themed Mobile Malware

论文作者

Wang, Liu, He, Ren, Wang, Haoyu, Xia, Pengcheng, Li, Yuanchun, Wu, Lei, Zhou, Yajin, Luo, Xiapu, Sui, Yulei, Guo, Yao, Xu, Guoai

论文摘要

随着1920年代初期的Covid-19大流行出现,许多恶意演员已经开始利用这一主题。尽管一些媒体报道提到了以冠状病毒为主题的移动恶意软件的存在,但研究界缺乏对以冠状病毒为主题的移动恶意软件的景观的理解。在本文中,我们介绍了以冠状病毒为主题的Android恶意软件的首次系统研究。我们首先努力创建日常增长的COVID-19-Mobile App数据集,其中包含4,322个Covid-199主题APK样本(2,500个独特的应用程序)和611个潜在的恶意软件样本(370个独特的恶意应用程序),到11月中旬,2020年11月中旬,2020年中,我们从多个角度进行了分析,包括趋势和趋势的分析,包括趋势和属性方法。我们观察到,Covid-19的主题应用程序以及恶意应用程序几乎一旦全球爆发,几乎就开始蓬勃发展。大多数恶意应用程序使用相同的应用标识符(例如,应用程序名称,软件包名称和应用程序图标)将其伪装成良性应用程序。他们的主要目的是窃取用户的私人信息,或者使用网络钓鱼和勒索之类的技巧来获利。此外,Covid-19的恶意软件创建者中只有四分之一是很长一段时间以来一直活跃的习惯开发人员,而其中75%的人是这一大流行中的新移民。恶意开发商主要位于美国,主要针对包括英语国家,中国,阿拉伯国家和欧洲的国家。为了促进未来的研究,我们已将所有标签良好的COVID-19-19-Apps(和恶意软件)公开发布给了研究界。到目前为止,世界各地的30多家研究机构已要求我们的数据集进行COVID-19的主题研究。

As the COVID-19 pandemic emerged in early 2020, a number of malicious actors have started capitalizing the topic. Although a few media reports mentioned the existence of coronavirus-themed mobile malware, the research community lacks the understanding of the landscape of the coronavirus-themed mobile malware. In this paper, we present the first systematic study of coronavirus-themed Android malware. We first make efforts to create a daily growing COVID-19 themed mobile app dataset, which contains 4,322 COVID-19 themed apk samples (2,500 unique apps) and 611 potential malware samples (370 unique malicious apps) by the time of mid-November, 2020. We then present an analysis of them from multiple perspectives including trends and statistics, installation methods, malicious behaviors and malicious actors behind them. We observe that the COVID-19 themed apps as well as malicious ones began to flourish almost as soon as the pandemic broke out worldwide. Most malicious apps are camouflaged as benign apps using the same app identifiers (e.g., app name, package name and app icon). Their main purposes are either stealing users' private information or making profit by using tricks like phishing and extortion. Furthermore, only a quarter of the COVID-19 malware creators are habitual developers who have been active for a long time, while 75% of them are newcomers in this pandemic. The malicious developers are mainly located in US, mostly targeting countries including English-speaking countries, China, Arabic countries and Europe. To facilitate future research, we have publicly released all the well-labelled COVID-19 themed apps (and malware) to the research community. Till now, over 30 research institutes around the world have requested our dataset for COVID-19 themed research.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源