CCF A区块链论文分享-NDSS 2026(2)-CtPhishCapture:揭露针对加密货币钱包的基于凭证窃取的网络钓鱼诈骗(附pdf)

Conference:Network and Distributed System Security Symposium (NDSS)

CCF level:CCF A

Year:2026

Title:

CtPhishCapture: Uncovering Credential-Theft-Based Phishing Scams Targeting Cryptocurrency Wallets

CtPhishCapture:揭露针对加密货币钱包的基于凭证窃取的网络钓鱼诈骗

Authors:****

Abstract:****

Due to the substantial financial incentives involved, credential-theft-based cryptocurrency wallet phishing (CtPhish) scams have emerged as one of the most prevalent malicious activities in the cryptocurrency ecosystem. In these attacks, victims are lured into visiting CtPhish websites or applications and deceived into disclosing their credentials, allowing attackers to steal their cryptocurrency assets. Although several phishing detection approaches exist, they are either inapplicable to CtPhish or suffer from significant limitations.

To bridge this gap, we propose CtPhishCapture, a large-scale detection system targeting CtPhish websites and applications. CtPhishCapture visits suspicious websites, employs large language model (LLM)-based detection methods to identify CtPhish websites, and attempts to download and analyze potential CtPhish applications for further detection. Over a six-month deployment, CtPhishCapture identifies 5,138 CtPhish websites and 10,612 CtPhish applications. Notably, only 17% of the websites and 21% of the applications were previously reported by the community, indicating that CtPhishCapture newly discovers 83% of the websites and 79% of the applications, making it the largest known detection system for CtPhish to date.

Leveraging the collected dataset, we conduct a comprehensive end-to-end measurement and analysis of the CtPhish ecosystem. Our analysis examines how attackers attract victims to CtPhish websites and apps, how they gain users' trust, and ultimately how they exfiltrate victims' cryptocurrency assets. Additionally, we provide in-depth measurements of the associated websites and applications, including their characteristics, evasion techniques, and estimated financial losses. Finally, we deploy CtPhishCapture in collaboration with a leading search engine provider. By integrating CtPhishCapture's detection results, the weekly user complaints about CtPhish are reduced by a factor of 5.8.

由于涉及巨额经济利益,基于凭证窃取的加密货币钱包网络钓鱼(CtPhish)诈骗已成为加密货币生态系统中最普遍的恶意活动之一。在这些攻击中,受害者被诱骗访问 CtPhish 网站或应用程序,并被骗泄露凭证,从而使攻击者能够窃取其加密货币资产。尽管存在多种网络钓鱼检测方法,但它们要么不适用于 CtPhish,要么存在重大局限性。

为了弥补这一不足,我们提出了 CtPhishCapture,一个针对 CtPhish 网站和应用程序的大规模检测系统。CtPhishCapture 会访问可疑网站,采用基于大型语言模型(LLM)的检测方法来识别 CtPhish 网站,并尝试下载和分析潜在的 CtPhish 应用程序以进行进一步检测。在为期六个月的部署中,CtPhishCapture 识别出了 5,138 个 CtPhish 网站和 10,612 个 CtPhish 应用程序。值得注意的是,此前社区仅报告过 17% 的网站和 21% 的应用程序,这意味着 CtPhishCapture 首次发现了 83% 的网站和 79% 的应用程序,使其成为迄今为止已知最大的 CtPhish 检测系统。

利用收集到的数据集,我们对 CtPhish 生态系统进行了全面的端到端测量和分析。我们的分析考察了攻击者如何吸引受害者访问 CtPhish 网站和应用程序,如何获取用户信任,以及最终如何窃取受害者的加密货币资产。此外,我们还对相关的网站和应用程序进行了深入测量,包括它们的特征、规避技术和预估的经济损失。最后,我们与一家领先的搜索引擎提供商合作部署了 CtPhishCapture。通过整合 CtPhishCapture 的检测结果,每周用户对 CtPhish 的投诉减少了 5.8 倍。

Pdf:

https://www.ndss-symposium.org/wp-content/uploads/2026-f2854-paper.pdf

相关推荐
虎头金猫2 天前
4K 视频总卡在公网带宽?用 N1 + OpenList 把网盘播放链路重新理顺
运维·服务器·网络·python·容器·beautifulsoup·pandas
wuyk5553 天前
《WiFi 嵌入式物联网开发全套实战》| 第 16 章 ESP32 AP+STA 双模共存原理与工程坑点
网络·stm32·物联网
QYRdata3 天前
年均增速24.2%!机器人数据湖未来六年增长动能强劲
网络·机器人·服务发现
CHENKONG_CK3 天前
破解制鞋打磨痛点:RFID赋能去毛刺工序自动化升级
网络·单片机·嵌入式硬件·网络协议·tcp/ip
chshang19923 天前
工业路由器是什么?浅谈5G工业网络中的IR602
网络·物联网·5g·智能路由器
萧瑟余晖3 天前
Netty 核心组件与 Reactor 模型详解
网络·架构
ITxiaobing20233 天前
IP 定位服务选型指南:从准确率到工程落地的技术考察
linux·服务器·网络
wuyk5553 天前
【Socket 进阶之路】第 9 章 Linux 网络服务量产稳定性优化|心跳保活、TIME_WAIT、SO_LINGER、内存池、断线重连、完整异常防护框架
linux·服务器·开发语言·网络·物联网
z落落3 天前
C#UDP+串口服务端+UDP 客户端(含 CRC16 校验)
网络·网络协议·udp
huaweichenai3 天前
spring boot操作PDF
java·spring boot·pdf