{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,22]],"date-time":"2026-05-22T09:08:42Z","timestamp":1779440922501,"version":"3.53.1"},"reference-count":39,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2026,5,22]],"date-time":"2026-05-22T00:00:00Z","timestamp":1779408000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"JSPS (Japan Society for the Promotion of Science)\/MEXT (Ministry of Education, Culture, Sports, Science and Technology) KAKENHI","award":["24K14956"],"award-info":[{"award-number":["24K14956"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Digital Threats"],"published-print":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>The financial impact of fraudulent e-commerce schemes has been increasing steadily. Several research reports demonstrate that some threat actors compromise legitimate web sites and deploy malware for black-hat Search Engine Optimization (SEO). This malware facilitates SEO poisoning, causing search engines to display deceptive lure pages as if hosted on the compromised sites, effectively redirecting users to fraudulent e-commerce platforms and increasing the risk of victimization. This study focuses on these threat actors and their tactics. To investigate relationships between malware families employed by these groups, we collected data on 2,852 command and control (C2) servers associated with 10 distinct malware families, alongside 697,816 fake e-commerce sites identified through these servers. We subsequently analyzed these data using Maltego, a widely recognized link analysis tool. Our results suggest the presence of four distinct groups each utilizing a single, unique malware family, and two groups operating multiple families. This analysis also provides valuable insights into the characteristics of these malware families.<\/jats:p>","DOI":"10.1145\/3805707","type":"journal-article","created":{"date-parts":[[2026,3,27]],"date-time":"2026-03-27T14:22:35Z","timestamp":1774621355000},"page":"1-21","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Malware-Facilitated E-Commerce Fraud: A Link Analysis of Black-Hat SEO-Based E-Commerce Fraud Actor Groups Targeting Japan"],"prefix":"10.1145","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-8447-3648","authenticated-orcid":false,"given":"Makoto","family":"Shimamura","sequence":"first","affiliation":[{"name":"Trend Micro Incorporated, Tokyo, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-1258-185X","authenticated-orcid":false,"given":"Shingo","family":"Matsugaya","sequence":"additional","affiliation":[{"name":"Trend Micro Incorporated, Tokyo, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-0599-6576","authenticated-orcid":false,"given":"Keisuke","family":"Sakai","sequence":"additional","affiliation":[{"name":"Kanagawa Prefectural Police Headquarters, Yokohama, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-1077-5271","authenticated-orcid":false,"given":"Kosuke","family":"Takeshige","sequence":"additional","affiliation":[{"name":"Chiba Prefectural Police Headquarters, Chiba, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5596-282X","authenticated-orcid":false,"given":"Masaki","family":"Hashimoto","sequence":"additional","affiliation":[{"name":"Faculty of Engineering and Design, Kagawa University, Takamatsu, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,5,22]]},"reference":[{"key":"e_1_3_1_2_2","unstructured":"[n.\u2009d.]. Email Address Regular Expression That 99.99% Works. emailregex.com. Retrieved March 2026 from https:\/\/emailregex.com\/index.html"},{"key":"e_1_3_1_3_2","unstructured":"Samanvitha Basole and Mark Stamp. 2021. Cluster analysis of malware family relationships. arXiv:2103.05761. Retrieved from https:\/\/arxiv.org\/abs\/2103.05761"},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2016.02.009"},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420969"},{"key":"e_1_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1145\/3664649"},{"issue":"1","key":"e_1_3_1_7_2","first-page":"1","article-title":"An analysis of the nature of groups engaged in cyber crime","volume":"8","author":"Broadhurst Roderic","year":"2014","unstructured":"Roderic Broadhurst, Peter Grabosky, Mamoun Alazab, Brigitte Bouhours, and Steve Chon. 2014. An analysis of the nature of groups engaged in cyber crime. International Journal of Cyber Criminology 8, 1 (2014), 1\u201320.","journal-title":"International Journal of Cyber Criminology"},{"key":"e_1_3_1_8_2","unstructured":"Larry Cashdollar. 2020. WordPress Malware Setting Up SEO Shops. Retrieved March 2026 from https:\/\/www.akamai.com\/blog\/security\/wordpress-malware-setting-up-seo-shops"},{"key":"e_1_3_1_9_2","unstructured":"CloudFlare. [n.d.]. Email Address Obfuscation\u2014Cloudflare Web Application Firewall (WAF) docs\u2014developers.cloudflare.com. Retrieved March 2026 from https:\/\/developers.cloudflare.com\/waf\/tools\/scrape-shield\/email-address-obfuscation\/"},{"key":"e_1_3_1_10_2","unstructured":"The computer security group (CSEC) in the Information Processing Society of Japan (IPSJ). [n.\u2009d.]. Checklist for Ethical Considerations in Cybersecurity Research. Retrieved March 2026 from https:\/\/www.iwsec.org\/csec\/ethics\/checklist.html"},{"key":"e_1_3_1_11_2","unstructured":"Google. 2015. Fix the Japanese Keyword Hack. Retrieved April 2024 from https:\/\/web.dev\/articles\/fix-the-japanese-keyword-hack"},{"key":"e_1_3_1_12_2","volume-title":"Network and Distributed System Security (NDSS) Symposium 2025","author":"Hasegawa Mizuho","year":"2025","unstructured":"Mizuho Hasegawa, Akihide Saino, Akira Fujita, Kazuki Takada, Rui Tanabe, Carlos H. Ga\u00f1a\u0144, Michel van Eeten, and Katsunari Yoshioka. 2025. Do you sell this? Utilizing product searches to find SEO-driven fake shopping sites. In Network and Distributed System Security (NDSS) Symposium 2025."},{"key":"e_1_3_1_13_2","unstructured":"Zuzana Hromcov\u00e1 and Anton Cherepanov. 2021. Anatomy of native IIS malware. Retrieved from https:\/\/web-assets.esetstatic.com\/wls\/2021\/08\/eset_anatomy_native_iis_malware.pdf"},{"key":"e_1_3_1_14_2","unstructured":"Japan Cybercrime Control Center. 2024. Statistics of malicious shopping sites in 2023 (in Japanese). Retrieved March 2026 from https:\/\/www.jc3.or.jp\/threats\/topics\/article-555.html"},{"key":"e_1_3_1_15_2","first-page":"78","volume-title":"Computational Science (ICCS \u201924)","author":"Jing Rongqi","year":"2024","unstructured":"Rongqi Jing, Zhengwei Jiang, Qiuyun Wang, Shuwei Wang, Hao Li, and Xiao Chen. 2024. From fine-grained to refined: APT malware knowledge graph construction and attribution analysis driven by multi-stage graph computation. In Computational Science (ICCS \u201924). Springer Nature Switzerland, Cham, 78\u201393."},{"key":"e_1_3_1_16_2","doi-asserted-by":"crossref","unstructured":"Olha Jure\u010dkov\u00e1 Martin Jure\u010dek and Mark Stamp. 2024. Online clustering of known and emerging malware families. arXiv:2405.03298. Retrieved from https:\/\/arxiv.org\/abs\/2405.03298","DOI":"10.1007\/978-3-031-83157-7_2"},{"key":"e_1_3_1_17_2","first-page":"161","volume-title":"31st USENIX Security Symposium (USENIX Security \u201922)","author":"Kasturi Ranjita Pai","year":"2022","unstructured":"Ranjita Pai Kasturi, Jonathan Fuller, Yiting Sun, Omar Chabklo, Andres Rodriguez, Jeman Park, and Brendan Saltaformaggio. 2022. Mistrust plugins you must: A large-scale study of malicious plugins in WordPress marketplaces. In 31st USENIX Security Symposium (USENIX Security \u201922). USENIX Association, Boston, MA, 161\u2013178. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/kasturi"},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.3390\/s21196522"},{"issue":"9","key":"e_1_3_1_19_2","first-page":"1523","article-title":"Understanding attacks with fake shopping websites (in Japanese)","volume":"62","author":"Kodera Hirokazu","year":"2021","unstructured":"Hirokazu Kodera, Takashi Koide, Daiki Chiba, Kazufumi Aoki, and Mitsuaki Akiyama. 2021. Understanding attacks with fake shopping websites (in Japanese). IPSJ Journal 62, 9 (Sep. 2021), 1523\u20131535.","journal-title":"IPSJ Journal"},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1145\/3627106.3627184"},{"key":"e_1_3_1_21_2","unstructured":"LAC Co. Ltd. 2022. LAC SECURITY INSIGHT Vol. 2 2022 Automn (in Japanese). Retrieved March 2026 from https:\/\/www.lac.co.jp\/lacwatch\/pdf\/20221214_lsi_vol2.pdf"},{"key":"e_1_3_1_22_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.techsoc.2024.102470"},{"key":"e_1_3_1_23_2","unstructured":"Javier S. Lirola. 2018. GitHub\u2014jslirola\/cloudflare-email-decoder: Program to decode email protection from files\/servers managed with Cloudflare\u2014github.com. Retrieved March 2026 from https:\/\/github.com\/jslirola\/cloudflare-email-decoder\/tree\/master"},{"key":"e_1_3_1_24_2","unstructured":"Maltego. [n.\u2009d.]. Homepage\u2014maltego.com. Retrieved March 2026 from https:\/\/www.maltego.com\/"},{"key":"e_1_3_1_25_2","unstructured":"Art Martori. 2020. How to Find and Fix the Japanese Keyword Hack. Retrieved March 2026 from https:\/\/blog.sucuri.net\/2020\/04\/japanese-keyword-hack.html"},{"key":"e_1_3_1_26_2","unstructured":"Matthias Marx. 2024. BogusBazzar: A criminal network of webshop fraudsters. Retrieved March 2026 from https:\/\/www.srlabs.de\/blog-post\/bogusbazaar"},{"key":"e_1_3_1_27_2","unstructured":"Matomo. [n.\u2009d.]. Matomo\u2014The Google Analytics alternative that protects your data\u2014matomo.org. Retrieved March 2026 from https:\/\/matomo.org\/"},{"key":"e_1_3_1_28_2","doi-asserted-by":"crossref","first-page":"107","DOI":"10.1007\/978-3-031-86149-9_11","volume-title":"Advances in Internet, Data and Web Technologies","author":"Michishita Daigo","year":"2025","unstructured":"Daigo Michishita, Satoru Kobayashi, and Toshihiro Yamauchi. 2025. Investigation towards detecting landing websites for fake Japanese shopping websites. In Advances in Internet, Data and Web Technologies, Leonard Barolli (Ed.), Springer Nature Switzerland, Cham, 107\u2013119."},{"key":"e_1_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.26599\/BDMA.2023.9020023"},{"key":"e_1_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-97620-9_1"},{"key":"e_1_3_1_31_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2013.09.006"},{"key":"e_1_3_1_32_2","unstructured":"Stefan Pejcic. [n.\u2009d.]. GitHub\u2014stefanpejcic\/wordpress-malware. Retrieved March 2026 from https:\/\/github.com\/stefanpejcic\/wordpress-malware\/"},{"key":"e_1_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/3587471"},{"key":"e_1_3_1_34_2","unstructured":"Trend Micro Research. 2023. Grouping actors that operate fake E-commerce sites targeting Japanese (in Japanese). Retrieved March 2026 from https:\/\/www.trendmicro.com\/ja_jp\/research\/22\/j\/seo-poisoning.html"},{"key":"e_1_3_1_35_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.11.001"},{"key":"e_1_3_1_36_2","unstructured":"VirusTotal. [n.\u2009d.]. GitHub\u2014VirusTotal\/yara: The Pattern Matching Swiss Knife. Retrieved March 2026 from https:\/\/github.com\/VirusTotal\/yara"},{"key":"e_1_3_1_37_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3063840"},{"key":"e_1_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1145\/3610228"},{"key":"e_1_3_1_39_2","first-page":"3703","volume-title":"30th USENIX Security Symposium (USENIX Security \u201921)","author":"Yang Ronghai","year":"2021","unstructured":"Ronghai Yang, Xianbo Wang, Cheng Chi, Dawei Wang, Jiawei He, Siming Pang, and Wing Cheong Lau. 2021. Scalable detection of promotional website defacements in black hat SEO campaigns. In 30th USENIX Security Symposium (USENIX Security \u201921). USENIX Association, 3703\u20133720. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/yang-ronghai"},{"key":"e_1_3_1_40_2","doi-asserted-by":"publisher","DOI":"10.1145\/3474379"}],"container-title":["Digital Threats: Research and Practice"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3805707","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,22]],"date-time":"2026-05-22T08:55:56Z","timestamp":1779440156000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3805707"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,22]]},"references-count":39,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2026,6,30]]}},"alternative-id":["10.1145\/3805707"],"URL":"https:\/\/doi.org\/10.1145\/3805707","relation":{},"ISSN":["2692-1626","2576-5337"],"issn-type":[{"value":"2692-1626","type":"print"},{"value":"2576-5337","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,22]]},"assertion":[{"value":"2025-09-21","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-03-06","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-05-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}