Money Doesn't Stink - Cybercriminal Business Insight of A New Android Botnet

No ratings

Presented at BlackHat Europe 2019 by

In mid 2018, we discovered one of the largest reported Android banking botnets known to date, that we named Geost. It was discovered when we saw one of their botmasters logging in into one of their C&C servers while using the insecure proxy network created by the HtBot malware. Computers infected with HtBot create an illegal network of proxies that are sold to customers, and our laboratory had one HtBot instance capturing the traffic. Geost resulted to be a new and very large Android Banking botnet operation targeting Russian citizens with almost 1 million victims, 15 C&C servers, thousands of domains, and thousands of malicious APK applications. This research starts with an analysis of all the OpSec failures that resulted in the discovery of Geost. Thought a treat intelligence process, we were able to know the Geost infrastructure, find domains and APKs related to it. Geost accesses all the SMS data of victims and has a direct connection to the systems of five large European banks. The operation of the botnet also includes traffic redirection and selling, data harvesting and access to premium SMS services.During the analysis, there was a breakthrough when we found a chat log of a cybercriminal entrepreneur group related to the Geost operation. This log exposed 28 people doing business for 8 months, discussing numerous projects and activities of the underground market and giving us a unique insight into how the business operation worked: the human relationships between the cybercriminals, daily routine tasks, motivational issues, money laundering, the decisions taken, and obstacles found. The criminal projects ranged from pay per install, phishing website hosting, and C&C development to malicious APKs and fake games development.This presentation shows the inner relationships of a blackmarket underground attacking group, their daily survival problems, decisions, money and struggles to make a living from malicious activities. How the hierarchy of malware development worked in the Geost botnet operation and the impact on the security of the victims. This work is unique because it shows the attackers communications in a private group and reveals a portion of how the underground cybercriminal business operates in relation with technical details of the malware. For them, operating a botnet was just one more job, and they showed no regrets or concerns about where the money is coming from, nor recognition that they were attacking others. At the end of the day, for them, the money didn't stink.