CryptoLocker Deep-Dive: Tracking security threats on the Bitcoin public ledger presented at Shmoocon2019 2019

by Olivia Kseib,

Summary : WhiteRabbit is an open source security research tool built on top of BlockSci, a blockchain analysis and exploration framework. In this presentation we will show how to leverage Bitcoin addresses associated to known ransomware campaigns and track payments made to these addresses. Our goal is to provide a tool that can act as another intelligence collection system for SOC analysts, threat hunters, malware researchers, and other defenders by leveraging Bitcoin public ledger data. This intelligence collection system allows analysts to track the activity of known ransomwares and assess the impact of these campaigns by directly looking into the amount of payments received. Furthermore, as cryptocurrencies continue gaining traction in public markets and criminal networks, we will demonstrate why Bitcoin wallet and other cryptocurrency addresses should be added as indicators of compromise (IOCs) to the “Pyramid of Pain.”