{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,7]],"date-time":"2026-03-07T18:00:20Z","timestamp":1772906420457,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":49,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,8,29]],"date-time":"2023-08-29T00:00:00Z","timestamp":1693267200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/100010661","name":"Horizon 2020 Framework Programme","doi-asserted-by":"publisher","award":["825355"],"award-info":[{"award-number":["825355"]}],"id":[{"id":"10.13039\/100010661","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100019180","name":"HORIZON EUROPE European Research Council","doi-asserted-by":"publisher","award":["804476"],"award-info":[{"award-number":["804476"]}],"id":[{"id":"10.13039\/100019180","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,8,29]]},"DOI":"10.1145\/3600160.3605047","type":"proceedings-article","created":{"date-parts":[[2023,8,9]],"date-time":"2023-08-09T22:54:41Z","timestamp":1691621681000},"page":"1-12","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Malware Finances and Operations: a Data-Driven Study of the Value Chain for Infections and Compromised Access"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3071-9027","authenticated-orcid":false,"given":"Juha","family":"Nurmi","sequence":"first","affiliation":[{"name":"Tampere University, Finland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9321-5235","authenticated-orcid":false,"given":"Mikko","family":"Niemel\u00e4","sequence":"additional","affiliation":[{"name":"Cyber Intelligence House, Portugal"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9160-0463","authenticated-orcid":false,"given":"Billy Bob","family":"Brumley","sequence":"additional","affiliation":[{"name":"Tampere University, Finland"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,8,29]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Lawrence Abrams. 2022. Raccoon Stealer malware suspends operations due to war in Ukraine. https:\/\/www.bleepingcomputer.com\/news\/security\/raccoon-stealer-malware-suspends-operations-due-to-war-in-ukraine\/"},{"key":"e_1_3_2_1_2_1","unstructured":"Ariel Ainhoren. 2019. Massive \u2019Collection #1\u2019 Data Dump: What\u2019s In It and How Did it Happen?https:\/\/intsights.com\/blog\/massive-collection-1-data-dump-whats-in-it-and-how-did-it-happen"},{"key":"e_1_3_2_1_3_1","volume-title":"21st Annual Workshop on the Economics of Information Security, WEIS 2021","author":"Akyazi Ugur","year":"2021","unstructured":"Ugur Akyazi, Michel van Eeten, and Carlos\u00a0Hernandez Ga\u00f1\u00e1n. 2021. Measuring Cybercrime as a Service (CaaS) Offerings in a Cybercrime Forum. In 21st Annual Workshop on the Economics of Information Security, WEIS 2021, Virtual Event, 28-29 June, 2021. http:\/\/resolver.tudelft.nl\/uuid:01cb117a-339c-42e9-9691-8456a12e3947"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/319709.319710"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/eCrime54498.2021.9738751"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/eCrime47957.2019.9037582"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-008-0084-2"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.2139\/ssrn.3226758"},{"key":"e_1_3_2_1_9_1","unstructured":"Alexandru Caciuloiu Pawinee Parnitudom Mikko Niemel\u00e4 Joshua James Juha Nurmi and Praphaphorn Tamarpirat. 2020. Darknet cybercrime threats to Southeast Asia. https:\/\/www.unodc.org\/documents\/southeastasiaandpacific\/\/Publications\/2021\/Darknet_Cybercrime_Threats_to_Southeast_Asia_report.pdf"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417892"},{"key":"e_1_3_2_1_11_1","volume-title":"32nd USENIX Security Symposium. USENIX Association. https:\/\/atc.usenix.org\/system\/files\/sec23fall-prepub-383-campobasso.pdf","author":"Campobasso Michele","year":"2023","unstructured":"Michele Campobasso and Luca Allodi. 2023. Know Your Cybercriminal: Evaluating Attacker Preferences by Measuring Profile Sales on an Active, Leading Criminal Market for User Impersonation at Scale. In 32nd USENIX Security Symposium. USENIX Association. https:\/\/atc.usenix.org\/system\/files\/sec23fall-prepub-383-campobasso.pdf"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/2488388.2488408"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1287624.1287628"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2005.20"},{"key":"e_1_3_2_1_15_1","unstructured":"Ben Cohen. 2020. Predator the Thief. https:\/\/www.cyberark.com\/resources\/threat-research-blog\/predator-the-thief"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.17863\/CAM.53769"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.drugpo.2015.01.008"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1080\/15564886.2016.1173158"},{"key":"e_1_3_2_1_19_1","volume-title":"Painless Steal: The Malware of Choice for Initial Access Brokers. https:\/\/www.cybersixgill.com\/blog\/painlessstealinitialaccessbrokers\/","author":"Lerner Dov","year":"2022","unstructured":"Dov Lerner. 2022. Painless Steal: The Malware of Choice for Initial Access Brokers. https:\/\/www.cybersixgill.com\/blog\/painlessstealinitialaccessbrokers\/"},{"key":"e_1_3_2_1_20_1","unstructured":"Brad Duncan. 2022. Windows MetaStealer Malware. https:\/\/isc.sans.edu\/diary\/Windows+MetaStealer+Malware\/28522"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1361-3723(19)30018-1"},{"key":"e_1_3_2_1_22_1","unstructured":"Esullivan. 2020. TAU-TIN - Kpot InfoStealer. https:\/\/community.carbonblack.com\/t5\/Threat-Advisories-Documents\/TAU-TIN-Kpot-InfoStealer\/ta-p\/88517"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4419-0140-8_9"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1093\/comjnl"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3199674"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427273"},{"key":"e_1_3_2_1_27_1","volume-title":"Pastebin: Running the site where hackers publicise their attacks. https:\/\/www.bbc.com\/news\/technology-17524822","author":"Kelion Leo","year":"2012","unstructured":"Leo Kelion. 2012. Pastebin: Running the site where hackers publicise their attacks. https:\/\/www.bbc.com\/news\/technology-17524822"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.5555\/1855768.1855790"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/csci49370.2019.00016"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-83"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/2068816.2068824"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.drugalcdep.2017.05.018"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/2987443.2987475"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2013.09.006"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_10"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3178876.3186178"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW55150.2022.00016"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW51379.2020.00071"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.23919\/CYCON.2019.8756845"},{"key":"e_1_3_2_1_40_1","unstructured":"Bruce Schneier. 2021. Adding a Russian Keyboard to Protect against Ransomware. https:\/\/www.schneier.com\/blog\/archives\/2021\/05\/adding-a-russian-keyboard-to-protect-against-ransomware.html"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-83r1"},{"key":"e_1_3_2_1_42_1","volume-title":"The Underground Economy of Spam: A Botmaster\u2019s Perspective of Coordinating Large-Scale Spam Campaigns. In 4th USENIX Workshop on Large-Scale Exploits and Emergent Threats, LEET \u201911","author":"Stone-Gross Brett","year":"2011","unstructured":"Brett Stone-Gross, Thorsten Holz, Gianluca Stringhini, and Giovanni Vigna. 2011. The Underground Economy of Spam: A Botmaster\u2019s Perspective of Coordinating Large-Scale Spam Campaigns. In 4th USENIX Workshop on Large-Scale Exploits and Emergent Threats, LEET \u201911, Boston, MA, USA, March 29, 2011, Christopher Kruegel (Ed.). USENIX Association. https:\/\/www.usenix.org\/conference\/leet11\/underground-economy-spam-botmasters-perspective-coordinating-large-scale-spam"},{"key":"e_1_3_2_1_43_1","volume-title":"14th Annual Workshop on the Economics of Information Security, WEIS 2015","author":"Thomas Kurt","year":"2015","unstructured":"Kurt Thomas, Danny\u00a0Yuxing Huang, David\u00a0Y. Wang, Elie Bursztein, Chris Grier, Tom Holt, Christopher Kruegel, Damon McCoy, Stefan Savage, and Giovanni Vigna. 2015. Framing Dependencies Introduced by Underground Commoditization. In 14th Annual Workshop on the Economics of Information Security, WEIS 2015, Delft, The Netherlands, 22-23 June, 2015. http:\/\/www.econinfosec.org\/archive\/weis2015\/papers\/WEIS_2015_thomas.pdf"},{"key":"e_1_3_2_1_44_1","unstructured":"Bill Toulas. 2022. New Meta information stealer distributed in malspam campaign. (2022). https:\/\/www.bleepingcomputer.com\/news\/security\/new-meta-information-stealer-distributed-in-malspam-campaign\/"},{"key":"e_1_3_2_1_45_1","volume-title":"Open data literature review. Barkeley School of Law","author":"Tran Emmie","year":"2015","unstructured":"Emmie Tran and Ginny Scholtes. 2015. Open data literature review. Barkeley School of Law, University of California (2015). https:\/\/www.law.berkeley.edu\/wp-content\/uploads\/2015\/04\/Final_OpenDataLitReview_2015-04-14_1.1.pdf"},{"key":"e_1_3_2_1_46_1","volume-title":"An In-depth Analysis of the AZORult Infostealer Malware Capabilities. Master\u2019s thesis","author":"van Rijn J.","unstructured":"H.\u00a0W.\u00a0J. van Rijn. 2021. An In-depth Analysis of the AZORult Infostealer Malware Capabilities. Master\u2019s thesis. Eindhoven University of Technology. https:\/\/research.tue.nl\/en\/studentTheses\/an-in-depth-analysis-of-the-azorult-infostealer-malware-capabilit"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/3419394.3423636"},{"key":"e_1_3_2_1_48_1","volume-title":"Market analysis: Assessing your business opportunities","author":"Winston William","unstructured":"William Winston, Robert\u00a0E Stevens, Philip\u00a0K Sherwood, and John\u00a0Paul Dunn. 2013. Market analysis: Assessing your business opportunities. Routledge. https:\/\/archive.org\/details\/marketanalysisas0000stev"},{"key":"e_1_3_2_1_49_1","volume-title":"Cybersecurity Research Datasets: Taxonomy and Empirical Analysis. In 11th USENIX Workshop on Cyber Security Experimentation and Test, CSET 2018","author":"Zheng Muwei","year":"2018","unstructured":"Muwei Zheng, Hannah Robbins, Zimo Chai, Prakash Thapa, and Tyler Moore. 2018. Cybersecurity Research Datasets: Taxonomy and Empirical Analysis. In 11th USENIX Workshop on Cyber Security Experimentation and Test, CSET 2018, Baltimore, MD, USA, August 13, 2018, Christian\u00a0S. Collberg and Peter A.\u00a0H. Peterson (Eds.). USENIX Association. https:\/\/www.usenix.org\/conference\/cset18\/presentation\/zheng"}],"event":{"name":"ARES 2023: The 18th International Conference on Availability, Reliability and Security","location":"Benevento Italy","acronym":"ARES 2023"},"container-title":["Proceedings of the 18th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3600160.3605047","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3600160.3605047","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T17:49:16Z","timestamp":1750182556000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3600160.3605047"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,8,29]]},"references-count":49,"alternative-id":["10.1145\/3600160.3605047","10.1145\/3600160"],"URL":"https:\/\/doi.org\/10.1145\/3600160.3605047","relation":{},"subject":[],"published":{"date-parts":[[2023,8,29]]},"assertion":[{"value":"2023-08-29","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}