Massimo La Morgia

dblp:223/6903 · DBLP profile ↗
← Back
16ranked-venue papers
9as first author
12since 2021 · last 2025
0000-0001-7132-078XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 2 first-author · 3 since 2021Systems, architecture and hardware · 3 · 2 first-author · 1 since 2021Security and privacy · 3 · 3 since 2021Software engineering, systems software and programming languages · 3 · 2 first-author · 2 since 2021Databases, data management, data science and information retrieval · 3 · 3 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2025 TGDataset: Collecting and Exploring the Largest Telegram Channels Dataset
abstract
Telegram is a widely adopted instant messaging platform. It has become worldwide popular because of its emphasis on privacy and its social network features such as channels-virtual rooms in which only the admins can post and broadcast messages to all the subscribers. Channels are used to deliver live updates (e.g., weather alerts) and content to a large audience (e.g., COVID-19 announcements) but unfortunately also to disseminate radical ideologies and coordinate attacks such as the Capitol Hill riot.
Massimo La Morgia, Alessandro Mei, Alberto Maria Mongardini
KDD (1)1
2025 The Conspiracy Money Machine: Uncovering Telegram's Conspiracy Channels and their Profit Model
Vincenzo Imperati, Massimo La Morgia, Alessandro Mei, Alberto Maria Mongardini, Francesco Sassi
USENIX Security Symposium2
2025 The Blockchain Warfare: Investigating the Ecosystem of Sniper Bots on Ethereum and BNB Smart Chain
abstract
In the world of cryptocurrencies, the public listing of a new token often generates significant hype. In many cases, the price of the token skyrockets in a few seconds, and timing is crucial to determine the success or failure of an investment opportunity. In this work, we present an in-depth analysis of sniper bots, automated tools designed to buy tokens as soon as they are listed on the market. We leverage GitHub open-source repositories of sniper bots to analyze their features and how they are implemented. Then, we build a dataset of Ethereum and BNB Smart Chain (BSC) liquidity pools to identify operations performed using sniper bots. Our findings reveal 352,413 sniping operations on Ethereum and 1,716,917 on BSC for a total turnaround of $155,630,184 and $137,548,859, respectively. We find that Ethereum operations have a higher success rate but require a larger investment. Finally, we analyze possible countermeasures and mechanisms used in token smart contracts that can reduce the negative impact of sniper bots.
Federico Cernera, Massimo La Morgia, Alessandro Mei, Alberto Maria Mongardini, Francesco Sassi
ACM Trans. Internet Techn.2
2025 Pretending to be a VIP! Characterization and Detection of Fake and Clone Channels on Telegram
abstract
Telegram is a widely used instant messaging app that has gained popularity due to its high level of privacy protection. Telegram has standout social network features like channels, which are virtual rooms where only administrators can post and broadcast messages to all subscribers. However, these same features have also led to the emergence of problematic activities and a significant number of fake accounts. To address these issues, Telegram has introduced verified and scam marks for channels, but only a small number of official channels are currently marked as verified, and only a few fakes as scams. In this research, we conduct a large-scale analysis of Telegram by collecting data from 120,979 different public channels and over 247 million messages. We identify and analyze two types of channels: Clones and fakes. Clones are channels that publish identical content from another channel in order to gain subscribers and promote services. Fakes, on the other hand, are channels that impersonate celebrities or well-known services by posting their own messages. To automatically detect fake channels, we propose a machine learning model that achieves an F1-score of 85.45%. By applying this model to our dataset, we find the main targets of fakes are political figures, well-known people such as actors or singers, and services.
Massimo La Morgia, Alessandro Mei, Alberto Maria Mongardini, Jie Wu 0001
ACM Trans. Web1
2024 DARD: Deceptive Approaches for Robust Defense Against IP Theft
abstract
With the rise of smart working and recent global events, the risk of cyberattacks is increasing steadily. Sometimes adversaries focus on stealing valuable data, such as intellectual property (IP): they exfiltrate a large volume of IP documents from a target company. They then identify those of their interest by leveraging automated methods. This work proposes the DARD (Deceptive Approaches for Robust Defense against IP theft) system, a framework designed to deceive adversaries who rely on automatic approaches to classify exfiltrated documents. Starting from an original repository of documents, DARD automatically generates a new deceptive repository that misleads popular automatic approaches, resulting in clusters of documents that are significantly different from the actual ones. By utilizing this approach, DARD aims to hinder the accurate clustering and the identification of the topic of documents by adversaries relying on automated techniques. The paper presents four deceptive operations (Basic Shuffle, Shuffle increment, Shuffle reduction, and Change topic) that DARD leverages to create a deceptive repository. We evaluate the efficacy of our approach by considering three different types of adversaries, each possessing varying levels of knowledge and expertise. Through extensive experiments, we show that the DARD system can deceive both automatic topic modeling and document clustering techniques, including widely-used commercial tools such as Amazon Comprehend. Hence, our solution provides a robust defense mechanism against Intellectual Property (IP) theft.
Alberto Maria Mongardini, Massimo La Morgia, Sushil Jajodia, Luigi V. Mancini, Alessandro Mei
IEEE Trans. Inf. Forensics Secur.2
2023 A Game of NFTs: Characterizing NFT Wash Trading in the Ethereum Blockchain
abstract
The Non-Fungible Token (NFT) market in the Ethereum blockchain experienced explosive growth in 2021, with a monthly trade volume reaching $6 billion in January 2022. However, concerns have emerged about possible wash trading, a form of market manipulation in which one party repeatedly trades an NFT to inflate its volume artificially. Our research examines the effects of wash trading on the NFT market in Ethereum from the beginning until January 2022, using multiple approaches. We find that wash trading affects 5.66% of all NFT collections, with a total artificial volume of $3,406,110,774. We look at two ways to profit from wash trading: Artificially increasing the price of the NFT and taking advantage of the token reward systems provided by some marketplaces. Our findings show that exploiting the token reward systems of NFTMs is much more profitable (mean gain of successful operations is $1.055M on LooksRare), more likely to succeed (more than 80% of operations), and less risky than reselling an NFT at a higher price using wash trading (50% of activities result in a loss). Our research highlights that wash trading is frequent in Ethereum and that NFTMs should implement protective mechanisms to stop such illicit behavior.
Massimo La Morgia, Alessandro Mei, Alberto Maria Mongardini, Eugenio Nerio Nemmi
ICDCS1
2023 It's a Trap! Detection and Analysis of Fake Channels on Telegram
abstract
Telegram is a widely used instant messaging app that has gained popularity due to its high level of privacy protection and social network features like channels, which are virtual rooms where only administrators can post and broadcast messages to all subscribers. However, these same features have also led to the emergence of problematic activities and a significant number of fake accounts. To address these issues, Telegram has introduced verified and scam marks for channels, but only a small number of official channels are currently marked as verified, and only a few fakes as scams.In this research, we conduct a large-scale analysis of Telegram by collecting data from 120,979 different public channels and over 247 million messages. We identify and analyze fake channels on Telegram. To automatically detect fake channels, we propose a machine learning model that achieves an accuracy of 85.49%. By applying this model to our dataset, we find the main targets of fakes are political figures, well-known people such as actors or singers, and services.
Massimo La Morgia, Alessandro Mei, Alberto Maria Mongardini, Jie Wu 0001
ICWS1
2023 Translated Texts Under the Lens: From Machine Translation Detection to Source Language Identification
Massimo La Morgia, Alessandro Mei, Eugenio Nerio Nemmi, Luca Sabatini, Francesco Sassi
IDA1
2023 Token Spammers, Rug Pulls, and Sniper Bots: An Analysis of the Ecosystem of Tokens in Ethereum and in the Binance Smart Chain (BNB)
Federico Cernera, Massimo La Morgia, Alessandro Mei, Francesco Sassi
USENIX Security Symposium2
2023 The Doge of Wall Street: Analysis and Detection of Pump and Dump Cryptocurrency Manipulations
abstract
Cryptocurrencies are increasingly popular. Even people who are not experts have started to invest in these assets, and nowadays, cryptocurrency exchanges process transactions for over 100 billion US dollars per month. Despite this, many cryptocurrencies have low liquidity and are highly prone to market manipulation. This paper performs an in-depth analysis of two market manipulations organized by communities over the Internet: The pump and dump and the crowd pump. The pump and dump scheme is a fraud as old as the stock market. Now, it has new vitality in the loosely regulated market of cryptocurrencies. Groups of highly coordinated people systematically arrange this scam, usually on Telegram and Discord. We monitored these groups for more than 3 years, detecting around 900 individual events. We report on three case studies related to pump and dump groups. We leverage our unique dataset of the verified pump and dumps to build a machine learning model able to detect a pump and dump in 25 seconds from the moment it starts, achieving the results of 94.5% of F1-score. Then, we move on to the crowd pump, a new phenomenon that hit the news in the first months of 2021, when a Reddit community inflated the price of the GameStop stocks (GME) by over 1,900% on Wall Street, the world’s largest stock exchange. Later, other Reddit communities replicated the operation on the cryptocurrency markets. The targets were DogeCoin (DOGE) and Ripple (XRP). We reconstruct how these operations developed and discuss differences and analogies with the standard pump and dump. We believe this study helps understand a widespread phenomenon affecting cryptocurrency markets. The detection algorithms we develop effectively detect these events in real-time and helps investors stay out of the market when these frauds are in action.
Massimo La Morgia, Alessandro Mei, Francesco Sassi, Julinda Stefa
ACM Trans. Internet Techn.1
2022 Nationality and Geolocation-Based Profiling in the Dark(Web)
abstract
In this paper we are concerned with geolocating the anonymous crowds of Dark Web forums. We do not focus on single users, but on the crowd as a whole. We work in two directions: The first idea is to exploit the time of all posts in the Dark Web forums to build profiles of the visiting crowds and to match the crowd profiles to that of users from known regions. Then, we develop a new dataset to detect the native language of the crowds to support and integrate this match. We assess the effectiveness of our methodology on the standard web and two Dark Web forums with users of known origin, and apply it to three controversial anonymous Dark Web forums. We believe that this work helps the community better understand the Dark Web from a sociological point of view and supports the investigation of authorities when the security of citizens is at stake.
Massimo La Morgia, Alessandro Mei, Eugenio Nerio Nemmi, Simone Raponi, Julinda Stefa
IEEE Trans. Serv. Comput.1
2021 The parallel lives of autonomous systems: ASN allocations vs. BGP
abstract
Autonomous Systems (ASes) exist in two dimensions on the Internet: the administrative and the operational one. Regional Internet Registries (RIRs) rule the former, while BGP the latter. In this work, we reconstruct the lives of the ASes on both dimensions, performing a joint analysis that covers 17 years of data. For the administrative dimension, we leverage delegation files published by RIRs to report the daily status of Internet resources they allocate. For the operational dimension, we characterize the temporal activity of ASNs in the Internet control plane using BGP data collected by the RouteViews and RIPE RIS projects. We present a methodology to extract insights about AS life cycles, including dealing with pitfalls affecting authoritative public datasets. We then perform a joint analysis to establish the relationship (or lack of) between these two dimensions for all allocated ASNs and all ASNs visible in BGP. We characterize the usual behaviors, specific differences between RIRs and historical resources, as well as measure the discrepancies between the two "parallel" lives. We find discrepancies and misalignment that reveal useful insights, and we highlight through examples the potential of this new lens to help pinpoint malicious BGP activity and various types of misconfigurations. This study illuminates a largely unexplored aspect of the Internet global routing system and provides methods and data to support broader studies that relate to security, policy, and network management.
Eugenio Nerio Nemmi, Francesco Sassi, Massimo La Morgia, Cecilia Testart, Alessandro Mei, Alberto Dainotti
Internet Measurement Conference3
2020 Pump and Dumps in the Bitcoin Era: Real Time Detection of Cryptocurrency Market Manipulations
abstract
In the last years, cryptocurrencies are increasingly popular. Even people who are not experts have started to invest in these securities and nowadays cryptocurrency exchanges process transactions for over 100 billion US dollars per month. However, many cryptocurrencies have low liquidity and therefore they are highly prone to market manipulation schemes.In this paper, we perform an in-depth analysis of pump and dump schemes organized by communities over the Internet. We observe how these communities are organized and how they carry out the fraud. Then, we report on two case studies related to pump and dump groups. Lastly, we introduce an approach to detect the fraud in real time that outperforms the current state of the art, so to help investors stay out of the market when a pump and dump scheme is in action.
Massimo La Morgia, Alessandro Mei, Francesco Sassi, Julinda Stefa
ICCCN1
2020 A Light in the Dark Web: Linking Dark Web Aliases to Real Internet Identities
abstract
Most users have several Internet names. On Face-book or LinkedIn, for example, people usually appear with the real one. On other standard websites, like forums, people often use aliases to protect their real identities with respect to the other users, with no real privacy against the web site and the authorities. Aliases in the Dark Web are different: users expect strong identity protection.In this paper, we show that using both "open" aliases (aliases used in the standard Web) and Dark Web aliases can be dangerous per se. Indeed, we develop tools to link Dark Web to open aliases. For the first time, we perform a massive scale experiment on real scenarios. First between two Dark Web forums, then between the Dark Web forums and the standard forums. Due to a large number of possible pairs, we first reduce the search space cutting down the number of potential matches to a small set of candidates, and then on the selection of the correct alias among these candidates. We show that our methodology has excellent precision, from 87% to 94%, and recall around 80%.
Ehsan Arabnezhad, Massimo La Morgia, Alessandro Mei, Eugenio Nerio Nemmi, Julinda Stefa
ICDCS2
2020 GDPR: When the Right to Access Personal Data Becomes a Threat
abstract
One year following the entry into force of the GDPR, all websites and data controllers have updated their procedures to store users' data. The GDPR does not only cover how and what data should be saved by the service providers, but it also guarantees an easy way to know what data are collected and the freedom to export them. In this paper, we carry out a comprehensive study on the right to access data provided by Article 15 of the GDPR. We examined more than 300 data controllers, requesting access to personal data to each of them. We found that almost each data controller has a slightly different procedure to fulfill the request and several ways to provide data back to the user, from a structured file like CSV to a screenshot of the monitor. We measure the time needed to complete the access data request and the completeness of the information provided. After this phase of data gathering, we analyze the authentication process followed by the data controllers to establish the identity of the requester. We find that 50.4% of the data controllers that handled the request have flaws in their procedures of identifying users or in their phase of sending the data, exposing users to new threats, even if these data controllers store data in compliance with the GDPR. Our surprising and undesired results show that, in its present deployment, the GDRP has actually decreased the privacy of users of web services.
Luca Bufalieri, Massimo La Morgia, Alessandro Mei, Julinda Stefa
ICWS2
2018 Time-Zone Geolocation of Crowds in the Dark Web
abstract
Dark Web platforms like the infamous Silk Road market, or other cyber-criminal or terrorism related forums, are only accessible by using anonymity mechanisms like Tor. In this paper we are concerned with geolocating the crowds accessing Dark Web forums. We do not focus on single users. We aim at uncovering the geographical distribution of groups of visitors into time-zones as a whole. Our approach, to the best of our knowledge, is the first of its kind applied to the Dark Web. The idea is to exploit the time of all posts in the Dark Web forums to build profiles of the visiting crowds. Then, to uncover the geographical origin of the Dark Web crowd by matching the crowd profile to that of users from known regions on regular web platforms. We assess the effectiveness of our methodology on standard web and two Dark Web platforms with users of known origin, and apply it to three controversial anonymous Dark Web forums. We believe that this work helps the community better understand the Dark Web from a sociological point of view and support the investigation of authorities when the security of citizens is at stake.
Massimo La Morgia, Alessandro Mei, Simone Raponi, Julinda Stefa
ICDCS1