How Do Exploit Kits Generate Malware Profits?

569 views
•
July 12, 2018
by
RSAC Cybersecurity
YouTube video player
How Do Exploit Kits Generate Malware Profits?

TL;DR

Exploit kits generate potential returns by delivering revenue-producing payloads such as ransomware, banking trojans, and cryptocurrency miners to victims. As exploit-kit activity declines, attackers increasingly adopt credential phishing, brute-force attacks, Office exploits, malicious macros, abused OLE objects, and software supply-chain attacks, choosing techniques according to their profitability.

Transcript

Um, hi. Uh, so my name is Daniel Frank. My co-presenters are Lior Ben Porat and, uh, Christopher Ellison. We all worked together, uh, in RSA before. Now we're all security researchers in, uh, different company. So our talk is, uh, about exploit kits and malware ROI. So, um, we're going to explain from the beginning until the end how exactly an expl... Read More

Key Insights

  • Exploit kits are flexible delivery mechanisms that allow their operators to choose and deploy different payloads against victims, including ransomware, banking trojans, and cryptocurrency miners. Their economic value comes from connecting successful exploitation with malware designed to produce revenue for attackers.
  • Exploit-kit analysis includes both technical and market dimensions, covering kit families, market share, geographic distribution, operating methods, payload selection, campaign costs, potential revenue, and return on investment. This combined view shows how attackers evaluate malicious technology as a business investment.
  • Exploit-kit activity has declined significantly in the wild according to observations by the presenters and other security vendors. The decline does not mean financially motivated attacks are disappearing, because attackers can redirect their efforts toward techniques that they consider more profitable.
  • Credential phishing and brute-force attacks are increasingly popular alternatives to exploit kits within the monitored cybercrime ecosystem. These methods represent part of a wider shift in attacker behavior as criminals pursue other ways to compromise victims and maintain revenue.
  • Office-based attacks use exploits, macros, and abused OLE objects as alternative infection techniques. Their presence among current trends shows that attackers can move beyond traditional exploit kits while continuing to seek practical methods for delivering malicious code.
  • Software supply-chain attacks can distribute malware through trusted applications. In the presented case, attackers poisoned a famous PDF editor application by redirecting its installer to attacker-controlled infrastructure, which then downloaded a malicious cryptocurrency-mining file.
  • The poisoned PDF editor campaign generated $54,000 in less than a month. This figure provides a concrete example of how coin-mining malware delivered through compromised software infrastructure can produce substantial revenue for the operators within a relatively short period.
  • GandCrab operates through a ransomware-as-a-service model supported by partner recruitment, marketing on the deep dark web, and dedicated infrastructure. Its business structure allows threat actors and participating partners to profit from ransomware campaigns rather than relying on a single operator.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How do exploit kits generate revenue for attackers?

Exploit kits generate potential revenue by compromising victims and delivering payloads designed to make money. The operator can select ransomware, a banking trojan, or a cryptocurrency miner and deploy it with the exploit kit. The resulting return depends on the delivered malware and campaign economics, including the costs of running the operation and the revenue produced by successful infections.

Q: What types of malware can exploit kits deliver?

Exploit kits can deliver several kinds of financially motivated malware, including ransomware, banking trojans, and cryptocurrency miners. Their flexibility allows an author or operator to choose the desired payload and deploy it together with the kit. The presentation uses examples of each category to connect the infection process with the profit and potential return available to attackers.

Q: Why are attackers moving away from exploit kits?

Researchers observed a major decline in exploit kits appearing in the wild, a trend also reported by other security vendors. Attackers are not giving up financially motivated activity. Instead, they are shifting toward techniques that may be more profitable, including credential phishing, brute-force attacks, Office exploits, macros, abused OLE objects, and software supply-chain attacks.

Q: What attack techniques are replacing exploit kits?

The main observed alternatives include credential phishing, brute-force attacks, Office exploits, malicious macros, abuse of OLE objects, and software supply-chain attacks. These techniques reflect a shift in the cybercrime ecosystem rather than an end to malicious activity. Attackers continue pursuing revenue by adopting other infection and delivery methods when exploit kits become less dominant.

Q: How did the poisoned PDF editor distribute coin-mining malware?

Attackers poisoned a famous PDF editor application and redirected its software installer so that it communicated with infrastructure controlled by them. That infrastructure delivered a malicious file containing coin-mining malware. The case demonstrates how a software supply-chain attack can turn a legitimate application and its installation process into a channel for distributing revenue-producing malware.

Q: How profitable was the PDF editor coin-mining campaign?

The poisoned PDF editor campaign generated $54,000 in less than a month. The revenue came from a coin-mining malware operation delivered through compromised software distribution. The example is presented as a glimpse into the money such campaigns can generate and illustrates why attackers may consider software supply-chain techniques an attractive alternative to exploit kits.

Q: What is the GandCrab ransomware-as-a-service model?

GandCrab is presented as a ransomware-as-a-service case study in which threat actors recruit partners, market the offering on the deep dark web, and provide infrastructure supporting ransomware operations. The model is designed to make participation enticing to prospective partners. Both the main threat actors and their partners can profit from campaigns conducted through this service structure.

Q: How can organizations better recognize and mitigate these attacks?

The presentation emphasizes increased awareness and recognition of exploit kits, ransomware, cryptocurrency miners, and related attack methods so potential victims can identify and avoid them. It also promises mitigation steps for exploit kits and their payloads. Understanding the complete attack process, changing market trends, payload behavior, and alternative vectors supports more effective recognition and defensive planning.

Summary & Key Takeaways

  • Exploit kits provide attackers with a flexible mechanism for selecting and delivering malicious payloads. The presentation covers their operation from initial deployment through infection, along with market trends, geographic distribution, prominent families, and payload examples involving cryptocurrency miners, banking trojans, and ransomware. It connects these technical processes to potential attacker returns.

  • The exploit-kit landscape has experienced a major decline in observed activity, but attackers have not abandoned financially motivated cybercrime. Researchers report a shift toward credential phishing, brute-force attacks, Office exploits, malicious macros, abused OLE objects, and software supply-chain attacks. These alternatives can provide attackers with other routes for distributing profitable malware.

  • Two cases illustrate the economics of modern malware operations. A poisoned PDF editor installer was redirected to attacker-controlled infrastructure and downloaded coin-mining malware, producing $54,000 in less than a month. GandCrab demonstrates ransomware as a service, including partner recruitment, marketing on the deep dark web, supporting infrastructure, and shared profitability.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚