The emergence and commoditization of cyber-criminal activities calls for new empirical methods, measures, and technologies to quantify and understand offender operations across all forms of cyber-crime: from malware engineering and attack delivery, to running underground operations trading illegal goods such as drugs and illegal pornography, to spreading disinformation and planning (cyber-)terrorism operations. Without appropriate scientific measures of cyber-offender and attacker operations, capabilities, and resources, it remains impossible to derive sound policies, strategies and technologies that appropriately address realistic and evidence-based attacker and offender models. WACCO calls for all contributions aiming at providing methods, measures, metrics, and technologies or tools to quantitatively or qualitatively evaluate cyber-offenders and attackers from technical and non-technical angles. The workshop invites contributions from, but not limited to, the fields of computer science and computer security, criminology, psychology, law, and economics addressing this issue.
WACCO welcomes (full and short) paper submissions, for publication in the EuroSP IEEE proceedings and presentation at WACCO, and Research talks, for presentation at WACCO (no proceedings). All submissions will go through the same review process, and receive feedback from the PC.
Call for Papers
WACCO welcomes (full and short) paper submissions, for publication in the EuroSP IEEE proceedings and presentation at WACCO, and Research talks, for presentation at WACCO (no proceedings). All submissions will go through the same review process, and receive feedback from the PC.
Topics of interest include, but are not limited to:
- Empirical studies on attacker operations and communities
- Novel methods to perform attacker measurements at scale across several communities
- Cooperation and trust as a source of attackers’ effectiveness
- Attackers’ skill set
- Attackers’ operational security
- Measuring the spread of false information campaigns on social media
- Quantitative and qualitative methods to measure, track, and counter cybercrime
- Cybercrime measurement and networks
- Cybercrime policy
- Economics of cybercrime
- Profiling of cybercriminals
- Security metric design and evaluation
- Security patch measurement
- Statistical exploration and prediction of security incidents
- Open Source INTelligence (OSINT) and digital footprints
The workshop is co-located with the 11th IEEE European Symposium on Security and Privacy (EuroS&P 2026).
Important Dates
All deadlines are Anywhere on Earth (AoE = UTC-12h).
| Paper submission due | March 22, 2026 [EXTENDED] | |
| Acceptance notice to authors | April 10, 2026 | |
| Publication-ready papers submitted | Apr 16, 2026 | |
| Workshop | July 6, 2026 |
Program
Below are the sessions for WACCO 2026.
Registration
9:30 – 9:45
Welcome
9:45 – 10:00
Keynote
10:00 – 11:00
Prof. Juan Tapiador, Computer Security Lab, UC3M
Vision over Visibility: From the Wild Years of Malware Sharing to Corporate Nomenclature Silos
Abstract. Cyber threat intelligence originated during the early years of malware sharing, an era that prioritized a global vision of the threat landscape. Early defenders focused on the grand strategy of collective defense, freely sharing samples and telemetry to ensure comprehensive visibility across the malware research ecosystem. As the market matured, commercial realities altered these priorities. This keynote explores how the commoditization of threat intelligence led vendors to prioritize proprietary visibility over a collective vision. We illustrate this shift using empirical data from historical malware sharing practices and the contemporary threat actor name fragmentation problem.
Bio. Juan Tapiador is a Professor in the Department of Computer Science at Universidad Carlos III de Madrid (UC3M), where he leads the Computer Security Lab. His research focuses on network and systems security, with an emphasis on malware, cyberattacks, and privacy. He has received several best paper awards at security conferences and recognitions from data protection agencies, including the Best Practical Paper Award at the 41st IEEE Symposium on Security and Privacy, the CNIL-Inria Privacy Protection Prize, and the AEPD Emilio Aced Prize for Privacy Research. Additionally, his research has been featured in prominent international media outlets, including Wired, The Times, Le Figaro, and El País.
Coffee Break
11:00 – 11:30
Session 1: Cybercrime Ecosystems, Markets, and Services
11:30 – 12:30
The Hacker’s Guide to Staying Out of Jail: Examining Prevention of Prosecution Content on the Dark Web
Emerson Suter and Matthew Edwards
Analyzing Supply and Demand Signals for Cybercrime Services in Technical-Support Scams
Raghavendra Cherupalli, Yi Ting Chua, Tyler Moore and Gary Warner
Topical Shifts in the Dark Web: A Longitudinal Analysis of Content in Cybercrime Forums and Marketplaces
Roy Ricaldi, Maximilian Schäfer, Philipp Zech, Luca Allodi, Raffaela Groner and Irdin Pekaric
Lunch Break
12:30 – 13:30
Session 2: Understanding Cybercriminal Communities and Behavior
13:30 – 15:00
From Cyber Threat to Political Action: The Identity and Motivations Presented by Anonymous Sudan for DDoS Attacks
Cassie Lowery, Matthew Edwards and Laura Smith
From Forum Threads to Cyber Threats: How Hackers Discuss Human Factors
Jan-Philip van Acken, Marre Slikker, Slinger Jansen and Katsiaryna Labunets
Towards Group-level Cybercriminal Profiling - Cultural Dimensions and Participation Roles in Dark Web Communities
Elizabeth Eardley, Simran Chandarana and Konstantinos Mersinas
An Assessment of Geopolitical Discussions in Cybercrime Forums
Isa-May Beauchamp, Estelle Ruellan and Masarah Paquet-Clouston
Coffee Break
15:00 – 15:30
Session 3: Malware Distribution and Criminal Tooling
15:30 – 16:30
Inside Crypter-as-a-Service: An Ecosystem Analysis of the exploit.in Underground Forum (Research Talk)
Maira de Freitas Pereira, Mathieu Jeannot, Romain Guittienne, Sebastien Larinier, Jean-Yves Marion, Pierre Marty and Manon Pamar
Large-Scale Analysis of Malware Distribution via Fake Game Cheats and Cracked Software on YouTube
Rei Yamagishi, Shota Fujii and Tatsuya Mori
Tor Through the Lens of OSINT: Studying the Presence of Exit Nodes in Blocklists
Adrian Jimenez-Gamo and Sergio Pastrana
Session 4: Cyber Threat Intelligence, Attribution, and Investigation
16:30 – 17:30
Work in Progress: An Analysis of ATT&CK TTP Adoption and Semantic Ambiguity
Manuel Suarez-Roman, Juan Caballero and Juan Tapiador
Graph-Based Modelling and Prediction of Adversary Behaviour from Honeypot Traces
David Guilherme, Miguel Faísco, Hans P. Reiser and Ibéria Medeiros
Connecting the Dots using Digital Fingerprints: Ontology-Grounded Action-Centric Knowledge Graphs for Scalable Cybercrime Case Linkage
Spriha Joshi, Anna Wilbik and Frank Thuijsman
Review Model
Open review reports
WACCO promotes an open and transparent review process. Reviews of accepted papers will be published together with the papers and archived in a public github repository associated with WACCO. A link to that repository must be included in all accepted submissions. The reasons why WACCO implements an open report model are the following:
- It documents why the paper was considered positively to contribute to the larger scientific domain it pertains to;
- It provides a critique useful to better delineate research limitations and scope, which can be of particular benefit to young researchers and students alike;
- It provides a structural incentive for reviewers to write constructive and clear reviews;
- It provides a structural incentive for authors to implement reviewer recommendations for the camera-ready version of their paper;
- It provides a critical viewpoint for future work and research follow-ups;
- It provides additional transparency to the quality of the adopted review process and its outcomes.
Submission
WACCO encourages submission of full papers and position papers from academia, industry, and government for appearance in the EuroSP IEEE proceedings. They should present interesting results for both theory and experimentation in the area of attacker and cyber-crime operations. We also particularly welcome independent reproduction of previous studies or experiments or negative results. We expect full papers to be of 10 pages in length (IEEE Format). Longer papers that document extensive experimentation are full in scope (which could be described in annex of the main body of the paper). Position papers of around 4 pages in length should present new open and interesting questions that the community should address or open questions that past research papers have not yet addressed. We expect position papers to be presented in panels or poster-platform sessions.
Additionally, WACCO welcomes submissions of Research Talks. Research Talk submissions will go through the same review process as full/short papers and will be evaluated on the same criteria of quality, but will not appear in the IEEE proceedings. We especially encourage the submission of multidisciplinary work looking for feedback from qualified experts in the domain. Research Talk submissions can be in any format, and of length commensurate to the contribution. Indicatively, Research Talks submissions are expected to be in the range of 7000-8000 words. To keep review loads acceptable, submissions of more than 10000 words may be desk rejected. Research Talk submissions should clearly state “Research Talk” in the title of the submission.
Anonymous submissions
Papers should be fully anonymized before review: author names or affiliations may not appear or be revealed in the text. Previous work of the authors should be referred to the third person. In the unusual case that an anonymous reference is not possible, the authors should blind the reference (e.g. “[x] Blinded citation to preserve submission anonymity”). Papers that are not properly anonymized may be desk rejected.
Submission of work that has been previously presented at conferences without proceedings, even if that work is associated with the names of the authors, or is published on online repositories such as ArXiv.org or SSRN, is allowed as long as the submission is fully anonymized. PC members that may recognize the work and its authors are asked to declare conflict on that paper and will not be assigned to it.
Publications
All papers will be published by IEEE CS and posted on the IEEE digital libraries. All authors of accepted papers are expected to present their paper at the workshop.
Ethical aspects and harm prevention
We expect authors to carefully consider and address ethical considerations, vulnerability disclosure, and other potential harms associated with carrying out their research, or potential negative consequences that could stem from publishing their work. Failure to adequately discuss such potential harms within the body of the submission may result in rejection of a submission, regardless of its quality and scientific value.
Open science
We encourage authors to release code, data, and other materials (such as survey instruments) needed to reproduce their work publicly under an open source license. We acknowledge that sometimes it is not possible to share these openly, such as when it involves malware samples, data from human subjects that must be protected, or proprietary data obtained under agreement that precludes publishing the data itself. In those cases, authors should provide a clear explanation of why the data cannot be released.
Submission site
Please submit your paper through EasyChair here.
Organization Committees
Program Co-chairs
| Luca Allodi | Eindhoven University of Technology | l.allodi@tue.nl |
| Alice Hutchings | University of Cambridge | alice.hutchings@cl.cam.ac.uk |
| Sergio Pastrana | University Carlos III of Madrid | spastran@inf.uc3m.es |
Publicity Chairs
Roy Ricaldi (Eindhoven University of Technology).
Program Committee
- Abhishta Abhishta, University of Twente
- Maria Bada, Queen Mary University of London
- Jorge Blasco, Universidad Politecnica de Madrid
- Yi Ting Chua, University of Tulsa
- Benoît Dupont, University of Montreal
- Matthew Edwards, University of Bristol
- Carlos Ganan, Delft
- Anita Lavorgna, University of Bologna
- Rutger Leukfeldt, NSCR
- Jonathan Lusthaus, Oxford University
- Tom Meurs, Politie
- Asier Moneva, NSCR
- Tyler Moore, The University of Tulsa
- Rebekah Overdorf, Ruhr University Bochum
- Yanna Papadodimitraki, University of Cambridge
- Masarah Paquet-Clouston, Université de Montréal
- Sasha Romanosky, Carnegie Mellon University/RAND
- Mohammad Hammas Saeed, George Washington University
- Will Scott, Protocol Labs
- Daniel R. Thomas, University of Strathclyde
- Jeroen van der Ham, University of Twente
- Rolf van Wegberg, TU Delft
- Marleen Weulen Kranenbarg, Vrije Universiteit Amsterdam
- Dmitry Zhdanov, Illinois State University
Registration
The workshop is co-located with the 11th IEEE European Symposium on Security and Privacy (EuroS&P 2026). To register please visit the registration page of the main event.