About | Contact Us | Register | Login
ProceedingsSeriesJournalsSearchEAI
Security and Privacy in Communication Networks. 19th EAI International Conference, SecureComm 2023, Hong Kong, China, October 19-21, 2023, Proceedings, Part II

Research Article

Ransomware as a Service: Demystifying Android Ransomware Generators

Cite
BibTeX Plain Text
  • @INPROCEEDINGS{10.1007/978-3-031-64954-7_22,
        author={Can Tu and Liu Wang and Yang Xu and Yiping Zhao and Haitao Xu and Haoyu Wang},
        title={Ransomware as a Service: Demystifying Android Ransomware Generators},
        proceedings={Security and Privacy in Communication Networks. 19th EAI International Conference, SecureComm 2023, Hong Kong, China, October 19-21, 2023, Proceedings, Part II},
        proceedings_a={SECURECOMM PART 2},
        year={2024},
        month={10},
        keywords={Ransomware Ransomware generator Ransomware as a Service Android malware},
        doi={10.1007/978-3-031-64954-7_22}
    }
    
  • Can Tu
    Liu Wang
    Yang Xu
    Yiping Zhao
    Haitao Xu
    Haoyu Wang
    Year: 2024
    Ransomware as a Service: Demystifying Android Ransomware Generators
    SECURECOMM PART 2
    Springer
    DOI: 10.1007/978-3-031-64954-7_22
Can Tu, Liu Wang, Yang Xu, Yiping Zhao, Haitao Xu, Haoyu Wang,*
    *Contact email: haoyuwang@hust.edu.cn

    Abstract

    Ransomware has become a pervasive and lucrative threat in the Android platform, prompting the emergence of Ransomware as a Service (RaaS) business model. Ransomware generators, as an outgrowth of this model, have been found to be readily available on the web. This has further fueled the proliferation of ransomware attacks by enabling individuals without programming skills to participate in the ransomware economy. Although the nuisance of ransomware generators has been mentioned by a few security reports, our community lacks an understanding of the characteristics of these Android ransomware generators. In this paper, we take the first step towards systematically studying Android ransomware generators. We analyze the RaaS business model from multiple perspectives including their behaviors, practices, generated apps, and ecosystem. We observe that deceptive tactics exist in some so-called ransomware generator apps, such as malware masquerading and developer spoofing. For the generated ransomware, we reveal their common locking mechanisms and a variety of unlocking mechanisms. We also provide an overview of the ecosystem by revealing the participating entities, propagation channels, and workflow. Our findings contribute to advancing our understanding of Android ransomware generators and their associated risks, and inform the development of effective countermeasures and strategies to combat ransomware threats.

    Keywords
    Ransomware Ransomware generator Ransomware as a Service Android malware
    Published
    2024-10-15
    Appears in
    SpringerLink
    http://dx.doi.org/10.1007/978-3-031-64954-7_22
    Copyright © 2023–2025 ICST
    EBSCOProQuestDBLPDOAJPortico
    EAI Logo

    About EAI

    • Who We Are
    • Leadership
    • Research Areas
    • Partners
    • Media Center

    Community

    • Membership
    • Conference
    • Recognition
    • Sponsor Us

    Publish with EAI

    • Publishing
    • Journals
    • Proceedings
    • Books
    • EUDL