The financial impact of fraudulent e-commerce schemes has been increasing steadily. Several research reports demonstrate that some threat actors compromise legitimate websites and deploy malware for black-hat search engine optimization (SEO). This malware facilitates SEO poisoning, causing search engines to display deceptive lure pages as if hosted on the compromised sites, effectively redirecting users to fraudulent e-commerce platforms and increasing the risk of victimization. This study focuses on these threat actors and their tactics. To investigate relationships between malware families employed by these groups, we collected data on 2,852 command and control (C2) servers associated with 10 distinct malware families, alongside 697,816 fake e-commerce sites identified through these servers. We subsequently analyzed this data using Maltego, a widely recognized link analysis tool. Our results suggest the presence of four distinct groups each utilizing a single, unique malware family, and two groups operating multiple families. This analysis also provides valuable insights into the characteristics of these malware families.
SHIMAMURA et al. (Fri,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: