Characteristic Analysis and Attack Group Identification of Phishing Sites Targeting Japan
摘要
In recent years, phishing incidents have surged domestically, reaching an all-time high in both number and monetary losses in 2023. However, it remains unclear which attack entities are responsible for the most significant phishing damages. This paper analyzes and classifies phishing sites targeting Japanese users. The analysis utilized data from 255,929 phishing sites collected between January 2023 and December 2023 from PhishHunter, a phishing observation system operated by Trend Micro as a part of activities in Japan Cybercrime Control Center (JC3). Our analysis revealed that 40.9% of the phishing sites targeted banking institutions, with a single attack group BP1 responsible for 80.3% of all observed domains. Through YARA rules based on HTML source characteristics, combined with IP addresses and WHOIS data, we successfully classified the sites into 213 groups. The most active group BP1 (205,615 domains) primarily targeted banking institutions, while another group CP31 (17,173 domains) focused on credit card companies, showing distinct patterns in their attack strategies. This study demonstrates the effectiveness of source-based classification in identifying and tracking major attack groups, providing crucial insights for prioritizing countermeasures against the most impactful threats.