Press play, install malware: a study of rhythm game-based malware dropping


연구 분야: Safety



학회: International Journal of Information Security


초록

Malware remains a major cybersecurity threat, often evading traditional detection methods. This study builds on our previous research with Tetris to present a more efficient covert channel attack using a Trojanized version of the rhythm game “Guitar Hero”. This new method delivers and executes malicious payloads in under 2.5 min, significantly faster than our previous Tetris-based approach. The engaging and musical nature of the rhythm game makes it more appealing to users, increasing the likelihood of attracting potential victims compared to the more monotonous Tetris. The attack encodes payloads into game levels, compelling users to make specific moves that unknowingly assemble malware on their devices, thereby evading detection. This study is the second to introduce gamification in malware transmission and the first to “force” user actions to achieve the objectives of the attacker. We provide a detailed analysis of this attack and suggest countermeasures, highlighting the necessity of human-based dynamic malware analysis and enhanced user awareness. Our findings underscore the evolving nature of cyber threats and the urgent need for innovative defensive strategies to address such sophisticated covert channel attacks.


Author Profile
Efstratios Vasilellis

Department of Informatics Athens University of Economics Athens Greece

Greece
Author Profile
Grigoris Gkionis

Department of Informatics Athens University of Economics Athens Greece

Greece
Author Profile
Dimitris Gritzalis

Department of Informatics Athens University of Economics Athens Greece

Greece

📄 논문 정보

발행 연도 2024년
인용수 0
출판 국가 Greece
사이트 Springer
좋아요 수 0

연관 논문 목록 (562건)