The Role of the Underground Market in Twitter Spam and Abuse
Total Page:16
File Type:pdf, Size:1020Kb
Trafficking Fraudulent Accounts: The Role of the Underground Market in Twitter Spam and Abuse Kurt Thomas† Damon McCoy‡ Chris Grier†∗ Alek Kolcz Vern Paxson†∗ †University of California, Berkeley ‡George Mason University ∗International Computer Science Institute Twitter {kthomas, grier, vern}@cs.berkeley.edu [email protected] [email protected] Abstract blacklists have lead to the emergence of an underground As web services such as Twitter, Facebook, Google, and market that specializes in selling fraudulent accounts in Yahoo now dominate the daily activities of Internet users, bulk. Account merchants operating in this space brazenly cyber criminals have adapted their monetization strate- advertise: a simple search query for “buy twitter ac- gies to engage users within these walled gardens. To fa- counts” yields a multitude of offers for fraudulent Twitter cilitate access to these sites, an underground market has credentials with prices ranging from $10–200 per thou- emerged where fraudulent accounts – automatically gen- sand. Once purchased, accounts serve as stepping stones erated credentials used to perpetrate scams, phishing, and to more profitable spam enterprises that degrade the qual- malware – are sold in bulk by the thousands. In order ity of web services, such as pharmaceutical spam [17] or to understand this shadowy economy, we investigate the fake anti-virus campaigns [25]. market for fraudulent Twitter accounts to monitor prices, In this paper we describe our investigation of the un- availability, and fraud perpetrated by 27 merchants over derground market profiting from Twitter credentials to the course of a 10-month period. We use our insights study how it operates, the impact the market has on Twit- to develop a classifier to retroactively detect several mil- ter spam levels, and exactly how merchants circumvent lion fraudulent accounts sold via this marketplace, 95% automated registration barriers.1 In total, we identified of which we disable with Twitter’s help. During active and monitored 27 account merchants that advertise via months, the 27 merchants we monitor appeared respon- web storefronts, blackhat forums, and freelance labor sible for registering 10–20% of all accounts later flagged sites. With the express permission of Twitter, we con- for spam by Twitter, generating $127–459K for their ef- ducted a longitudinal study of these merchants and pur- forts. chased a total of 121,027 fraudulent Twitter accounts on a bi-weekly basis over ten months from June, 2012 – 1 Introduction April, 2013. Throughout this process, we tracked ac- As web services such as Twitter, Facebook, Google, count prices, availability, and fraud in the marketplace. and Yahoo now dominate the daily activities of Inter- Our findings show that merchants thoroughly understand net users [1], cyber criminals have adapted their mon- Twitter’s existing defenses against automated registra- etization strategies to engage users within these walled tion, and as a result can generate thousands of accounts gardens. This has lead to a proliferation of fraudulent with little disruption in availability or instability in pric- accounts – automatically generated credentials used to ing. disseminate scams, phishing, and malware. Recent stud- In order to fulfill orders for fraudulent Twitter ac- ies from 2011 estimate at least 3% of active Twitter ac- counts, we find that merchants rely on CAPTCHA solving counts are fraudulent [29]. Facebook estimates its own services; fraudulent email credentials from Hotmail, Ya- fraudulent account population at 1.5% of its active user hoo, and mail.ru; and tens of thousands of hosts located base [13], and the problem extends to major web services around the globe to provide a diverse pool of IP addresses beyond just social networks [14]. 1Our study is limited to Twitter, as we were unable to acquire per- The complexities required to circumvent registration mission to conduct our research from other companies we saw being barriers such as CAPTCHAs, email confirmation, and IP abused. 1 to evade blacklisting and throttling. In turn, merchants 2 Background stockpile accounts months in advance of their sale, where “pre-aged” accounts have become a selling point in the Fraudulent accounts are just a single facet of the underground market. We identify which registration bar- menagerie of digital criminal goods and services for sale riers effectively increase the price of accounts and sum- in the underground market. We provide an overview marize our observations into a set of recommendations of previous investigations into the digital blackmarket, for how web services can improve existing automation outline the role that account abuse plays in this space, barriers to increase the cost of fraudulent credentials. and summarize existing strategies for detecting spam and abuse. Finally, in order to carry out our investigation of Finally, to estimate the overall impact the underground the market for fraudulent Twitter accounts, we adhere to market has on Twitter spam we leveraged our under- a strict set of legal and ethical guidelines set down by our standing of how merchants abuse the registration process institutions and by Twitter, documented here. in order to develop a classifier that retroactively detects fraudulent accounts. We applied our classifier to all ac- 2.1 Underground Market counts registered on Twitter in the last year and iden- tify several million suspected fraudulent accounts gener- At the center of the for-profit spam and malware ecosys- ated and sold via the underground market. During active tem is an underground market that connects Inter- months, the 27 merchants we monitor appeared respon- net miscreants with parties selling a range of special- sible for registering 10–20% of all accounts later flagged ized products and services including spam hosting [2, by Twitter as spam. For their efforts, the merchants 11], CAPTCHA solving services [19], pay-per-install generated an estimated total revenue between $127,000– hosts [4], and exploit kits [9]. Even simple services such $459,000 from the sale of accounts. as garnering favorable reviews or writing web page con- tent are for sale [21, 31]. Revenue generated by miscre- With Twitter’s cooperation, we disable 95% of all ants participating in this market varies widely based on fraudulent accounts registered by the merchants we business strategy, with spam affiliate programs generat- track, including those previously sold but not yet sus- ing $12–$92 million [17] and fake anti-virus scammers pended for spamming. Throughout the suspension pro- $5-116 million [25] over the course of their operations. cess, we simultaneously monitor the underground market for any fallout. While we do not observe an apprecia- Specialization within this ecosystem is the norm. ble increase in pricing or delay in merchants delivering Organized criminal communities include carders that new accounts, we find 90% of all purchased accounts im- siphon credit card wealth [7]; email spam affiliate pro- mediately after our action are suspended on arrival. We grams [16]; and browser exploit developers and traffic are now actively working with Twitter to integrate our generators [9]. The appearance of account merchants defense into their real-time detection framework to help is yet another specialization where sellers enable other prevent abusive signups. miscreants to penetrate walled garden services, while at the same time abstracting away the complexities of In summary, we frame our contributions as follows: CAPTCHA solving, acquiring unique emails, and dodg- • We perform a 10 month longitudinal study of 27 ing IP blacklisting. These accounts can then be used for a merchants profiting from the sale of Twitter ac- multitude of activities, outlined below, that directly gen- counts. erate a profit for miscreants. • We develop a classifier based on registration signals 2.2 Impact of Fraudulent Accounts that detects several million fraudulent accounts that merchants sold to generate $127,000–$459,000 in Miscreants leverage fraudulent social networking ac- revenue. counts to expose legitimate users to scams, phishing, and malware [8, 10]. Spam monetization relies on both grey- • We investigate the impact that the underground mar- market and legitimate affiliate URL programs, ad syn- ket has on Twitter spam levels and find 10–20% dication services, and ad-based URL shortening [29]. all spam accounts originate from the merchants we Apart from for-profit activities, miscreants have also study. leveraged fraudulent accounts to launch attacks from • We investigate the failures of existing automated within Twitter for the express purposes of censoring po- registration barriers and provide a set of recommen- litical speech [28]. All of these examples serve to illus- dations to increase the cost of generating fraudulent trate the deleterious effect that fraudulent accounts have accounts. on social networks and user safety. 2 2.3 Spam Detection Strategies world.com, and freelance labor pages including Fiverr and Freelancer [20, 21]. In total, we identify a disparate The pervasive nuisance of spam in social networks has group of 27 merchants. Of these, 10 operate their own lead to a multitude of detection strategies. These in- websites and allow purchases via automated forms, 5 so- clude analyzing social graph properties of sybil ac- licit via blackhat forums, and 12 advertise via freelance counts [6, 33, 34], characterizing the arrival rate and dis- sites that take a cut from sales. Advertisements for Twit- tribution of posts [8], analyzing statistical properties of ter accounts range in offerings from credentials for ac- account profiles [3, 26], detecting spam URLs posted by counts with no profile or picture, to “pre-aged” accounts2 accounts [27], and identifying common spam redirect that are months old with unique biographies and profile paths [15]. While effective, all of these approaches rely data. Merchants even offer 48 hours of support, during on at-abuse time metrics that target strong signals such which miscreants can request replacements for accounts as sending a spam URL or forming hundreds of rela- that are dysfunctional. We provide a detailed breakdown tionships in a short period.