How to Circumvent and Beat the Ransomware in Android Operating System—A Case Study of Locker.CB!tr

Author:

Drabent Kornel1,Janowski Robert1ORCID,Mongay Batalla Jordi2ORCID

Affiliation:

1. Faculty of Informatics, Warsaw School of Computer Science, Lewartowskiego 17, 00-169 Warsaw, Poland

2. Institute of Telecommunications, Warsaw University of Technology, Nowowiejska 15/19, 00-665 Warsaw, Poland

Abstract

Ransomware is one of the most extended cyberattacks. It consists of encrypting a user’s files or locking the smartphone in order to blackmail a victim. The attacking software is ordered on the infected device from the attacker’s remote server, known as command and control. In this work, we propose a method to recover from a Locker.CB!tr ransomware attack after it has infected and hit a smartphone. The novelty of our approach lies on exploiting the communication between the ransomware on the infected device and the attacker’s command and control server as a point to reverse disruptive actions like screen locking or file encryption. For this purpose, we carried out both a dynamic and a static analysis of decompiled Locker.CB!tr ransomware source code to understand its operation principles and exploited communication patterns from the IP layer to the application layer to fully impersonate the command and control server. This way, we gained full control over the Locker.CB!tr ransomware instance. From that moment, we were able to command the Locker.CB!tr ransomware instance on the infected device to unlock the smartphone or decrypt the files. The contributions of this work are a novel method to recover the mobile phone after ransomware attack based on the analysis of the ransomware communication with the C&C server; and a mechanism for impersonating the ransomware C&C server and thus gaining full control over the ransomware instance.

Funder

National Centre of Research and Development

Publisher

MDPI AG

Reference45 articles.

1. Ransomware: Evolution, mitigation and prevention;Richardson;Int. Manag. Rev.,2017

2. The Ransomware-as-a-Service economy within the darknet;Meland;Comput. Secur.,2020

3. Information security breaches due to ransomware attacks—A systematic literature review;Reshmi;Int. J. Inf. Manag. Data Insights,2021

4. Ransomware: Recent advances, analysis, challenges and future research directions;Beaman;Comput. Secur.,2021

5. Taheri, L., Kadir, A.F.A., and Lashkari, A.H. (2019, January 1–3). Extensible android malware detection and family classification using network-flows and API-calls. Proceedings of the International Carnahan Conference on Security Technology, Chennai, India.

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3