Cómo las estafas de exchanges cripto usan dominios parecidos y apps falsas
Artículo arXiv papers · Autor: Pengcheng Xia et al.
Resumen
Este estudio caracteriza las estafas que se hacen pasar por exchanges de criptomonedas mediante sitios web y aplicaciones móviles engañosos. Los investigadores recopilaron estafas denunciadas y generaron dominios probablemente registrados con errores tipográficos deliberados para encontrar más casos; después agruparon los sitios y las aplicaciones relacionados en familias. Examinaron cómo se conectaban ambos canales de estafa y evaluaron el impacto financiero denunciado y la distribución de las aplicaciones.
Ideas clave
- El estudio combina informes existentes de estafas con técnicas de typosquatting para encontrar dominios que suplantan a exchanges.
- Agrupa los dominios fraudulentos y las aplicaciones falsas identificados en familias y examina sus relaciones.
- El análisis informa de pérdidas financieras asociadas a las estafas de al menos $520,000.
- Se encontraron aplicaciones falsas de exchanges en las principales tiendas de aplicaciones, incluida Google Play, lo que supone un riesgo para quienes buscan plataformas de trading legítimas.
- Los resultados describen las estafas identificadas y las pérdidas denunciadas; no cuantifican la magnitud total del fraude relacionado con exchanges.
Etiquetas
Texto completo
# Characterizing Cryptocurrency Exchange Scams # Characterizing Cryptocurrency Exchange Scams As the indispensable trading platforms of the ecosystem, hundreds of cryptocurrency exchanges are emerging to facilitate the trading of digital assets. While, it also attracts the attentions of attackers. A number of scam attacks were reported targeting cryptocurrency exchanges, leading to a huge mount of financial loss. However, no previous work in our research community has systematically studied this problem. In this paper, we make the first effort to identify and characterize the cryptocurrency exchange scams. We first identify over 1,500 scam domains and over 300 fake apps, by collecting existing reports and using typosquatting generation techniques. Then we investigate the relationship between them, and identify 94 scam domain families and 30 fake app families. We further characterize the impacts of such scams, and reveal that these scams have incurred financial loss of 520k US dollars at least. We further observe that the fake apps have been sneaked to major app markets (including Google Play) to infect unsuspicious users. Our findings demonstrate the urgency to identify and prevent cryptocurrency exchange scams. To facilitate future research, we have publicly released all the identified scam domains and fake apps to the community.
Se muestra íntegramente con atribución según la licencia de la fuente. Licencia: abstract CC0
Este resumen lo redactó el agente de investigación de Stratmill a partir del original; no es una copia de la fuente.