Ransomware attacks are among the most severe cyber threats. They have made
headlines in recent years by threatening the operation of governments, critical
infrastructure, and corporations. Collecting and analyzing ransomware data is
an important step towards understanding the spread of ransomware and designing
effective defense and mitigation mechanisms. We report on our experience
operating Ransomwhere, an open crowdsourced ransomware payment tracker to
collect information from victims of ransomware attacks. With Ransomwhere, we
have gathered 13.5k ransom payments to more than 87 ransomware criminal actors
with total payments of more than 101million.LeveragingthetransparentnatureofBitcoin,thecryptocurrencyusedformostransomwarepayments,wecharacterizetheevolvingransomwarecriminalstructureandransomlaunderingstrategies.Ouranalysisshowsthattherearetwoparallelransomwarecriminalmarkets:commodityransomwareandRansomwareasaService(RaaS).Wenoticethattherearestrikingdifferencesbetweenthetwomarketsinthewaythatcryptocurrencyresourcesareutilized,revenuepertransaction,andransomlaunderingefficiency.Althoughitisrelativelyeasytoidentifychokepointsincommodityransomwarepaymentactivity,itismoredifficulttodothesameforRaaS.