Showing posts with label APT. Show all posts
Showing posts with label APT. Show all posts

Thursday, January 18, 2018

Vietnamese APT Actors Involved in Watering-Hole Attacks

Beginning in February of 2017 a group of Vietnamese APT actors carried out a large campaign leveraging watering-hole attacks. The campaign is intended to conduct surveillance on entities within Southeast Asia and China. As part of the watering-hole attacks, the group leveraged a JavaScript reconnaissance framework to collect information on their targets. This report looks at the malicious JavaScript framework leveraged by the attackers, provides information on attribution, and looks at the infrastructure behind the campaign...READ MORE 

Wapack Labs has cataloged and reported on APT activity and watering-hole attacks in the past. An archive of related reporting can be found in the Red Sky Alliance portal. 

Wednesday, October 18, 2017

Iranian Cyber Campaign Evolutions – The Next Wave: Greenbug and Ismdoor

Greenbug is an Advanced Persistent Threat (APT) cyber-espionage group with suspected Iranian ties. In August 2017, a Greenbug tool dubbed Ismdoor resurfaced in the wild. The malware possesses many reconnaissance capabilities, and in August of 2016 was deployed to harvest account credentials prior to an attack against Saudi Arabian infrastructure. Wapack Labs assesses with moderate confidence that the presence of Ismdoor is an indicator that Greenbug may be performing reconnaissance for a future campaign. While the Greenbug group is not directly affecting the membership, the targeting of Middle Eastern gas and energy companies affects multiple supply chains with repercussions for U.S. and Allied interests in the region. Wapack Labs’ analysts have also detected an evolution in Iranian cyber campaigns indicating likely adoption of cyber espionage and cyber hacktivism models similar to those employed by the Chinese APT groups, whereby different groups are utilized in different campaigns and multiple teams conduct separate phases of a cyber campaign. The Iranian originated campaigns, similar to the Chinese APT model, are also conducted in waves. The resurgence of Greenbug and Ismdoor indicate another Iranian based cyber campaign cycle is being initiated in the Middle East...READ MORE

Wapack Labs has cataloged and reported on APT groups and campaigns in the past. An archive of related reporting can be found in the Red Sky Alliance portal. 

Friday, August 11, 2017

Shadowbrokers and the Scylla Hacking Store

The ShadowBrokers (SB) have recently started a new Tor based market called Scylla Hacking Store. SB is selling several APT stolen exploits (US, Russian and Chinese exploits), crimewave exploit kits, and other crimewave hacking tools: bots, hash cracking, and Microsoft Office exploits. Analysts believe, with medium confidence, the recent Petya activity may be related to SB sales of all the payload source code for the FuzzBunch framework, which included, EternalBlue...READ MORE

Wapack Labs has cataloged and reported extensively on the ShadowBrokers in the past. An archive of related reporting can be found in the Red Sky Alliance portal.


Thursday, July 20, 2017

Financially Motivated APT-style Actors Target Retail & Hospitality

A new wave of financially motivated, APT-style group, of cyber threat actors are targeting large restaurant chains with phishing emails containing malicious attachments. As early as April 2017, a new wave of the group's activity has been targeting the retail and hospitality sectors. The APT-style group has been active since 2015 and is known for their use of the Carbanak malware. The most recent campaigns leverage two new RTF droppers to deliver a variant of a known backdoor. Early campaigns were known for targeting financial institutions and banks; in 2015, targeting European banks through a banking application called the Internet Front End Banking System (iFOBS). This report describes TTPs leveraged in the recent campaigns...READ MORE

Wapack Labs has cataloged and reported extensively on APTs, cyber threat actors, phishing, malware, financial institutions, and Carbanak in the past. An archive of related reporting can be found in the Red Sky Alliance portal.



Tuesday, July 18, 2017

NotPetya: Ransomware Or Russian Wiper?

Creators of the NotPetya (also known as Petya, PetrWrap, Petya.A, Win32/Diskcoder.Petya.C, EternalPetya, Nyetya, and exPetr) continue to present NotPetya as “simple ransomware.” The developers have moved received bitcoins, sent payments to Pastebin and DeepPaste associated wallets, contacted the public, and apparently were able to decrypt one short NotPetya encrypted file. At the same time, NotPetya creators did not use the original Petya ransomware source code, and likely left no remedy for most users to recover their encrypted data, despite showing them the ransom note. These observations, together with targeting and comparative TTP data for XData and BlackEnergy3 Killdisk, allow Wapack analysts to attribute NotPetya as likely belonging to Russian APT. The Petya/NotPetya operation is likely another Russian APT targeted disruption of Ukrainian IT infrastructure and possibly an intelligence operation - yet masked as a ransomware case. At the same time, it is probable that Petya and NotPetya actors may have a master key to decrypt user files; in case the targeted disk was not destroyed and system information is available...READ MORE

Wapack Labs has cataloged and reported extensively on Petya/NotPetya, ransomware, BlackEnergy, Russian APT, wiper malware, and Ukrainian attacks in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Wednesday, April 26, 2017

Assessing the Multiple Personalities of an APT Actor

Wapack Labs assesses with medium confidence that an identified Advanced Persistent Threat (APT) "group" is actually a lone, nefarious actor using numerous personas. The "group's" forum was rumored to be operated by a foreign military unit and used as a place to re-sell data no longer needed to conduct operations. During the months of March and April 2017, Wapack Analysts observed the lone actor's activities across multiple underground forums and were able to tie said activities to aliases used by other group members...READ MORE

Wapack Labs has cataloged and reported extensively on APT's in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Thursday, November 10, 2016

@AnPoland and the Bradley Foundation

On 29 October 2016, Anonymous Poland (@AnPoland) claimed to have hacked and downloaded e-files from the Bradley Foundation (BF).  A letter was posted by numerous Anonymous groups which presented a letter explaining a donation of $150 million USD made by the Rothschild Assets Management Company, through the BF, to the Hillary Clinton Campaign.  BF, a traditional conservative foundation, is currently claiming that the posted letter is a fake.  This information is being provided for your situational awareness.

  • Anonymous Poland (@AnPoland) was created during 2016 Summer Olympics to hack the World Anti-doping Administration.
  • Wapack Labs assesses with moderate confidence that AnPoland is Russian APT.
  • Anonymous Poland was the first to report the hack of the Bradley Foundation, placing moderate confidence they are responsible.

Publication date:                           4 November 2016
Handling requirements:               Traffic light protocol (TLP) GREEN
Attribution/Threat Actors:          Anonymous Poland [suspected Russian APT]

Actor Type:                                    Adversary capabilities have been assessed as Tier IV*

Potential Targets:                          Bradley Foundation (other U.S. politically tied foundations)

Past Reporting:                             DOC-4287, DOC-4211

*States with the ability to successfully execute full spectrum (cyber capabilities in combination with all of their military and intelligence capabilities) operations to achieve a specific outcome in political, military, economic, etc. domains and apply at scale.

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.


Tuesday, August 23, 2016

APT Sinkhole Connection Notification

http://www.itbusinessedge.com
Wapack Labs released a report today that identified 17 connections to Advanced Persistent Threat (APT) sinkholes by six corporate networks.  While not a perfect indicator, connections to these sinkholes are indicative of potential compromise by an APT actor.  Wapack Labs recommends that each of the 17 machines be examined by security personnel.

What’s a sinkhole? When a computer is compromised by malware, it often connects to a computer outside of the victim network for instructions.  Wapack Labs purchased these command and control (C2) nodes specifically to identify computers reaching out of their native environment.  As a result, any computer connecting to the Wapack Labs sinkhole should be considered likely compromised, and examined immediately for compromise, data loss, exfiltration or theft.

APT sinkholes indicate potential State Sponsored Espionage attacks against them.

Companies in the following industries are mentioned in this report:
  • Fortune 100 Chemical
  • Internet Service Provider
  • SMB Virtual Server Hosting 
  • SMB Onsite managed IT
  • Medium sized Defense Industrial Base company
  • SMB IT Consulting
Publication Date: 22 August 2016

Handling requirements: Traffic light protocol (TLP) RED - Recipients may not share TLP: RED information with any parties outside of the specific exchange, meeting or conversation in which it is originally disclosed.

Attribution/Threat Actors: Various/Multiple

Actor type:  Adversary capabilities have been assessed as Tier IV and Tier V (Criminal, State Sponsored, Advanced Persistent Threat)

Previous reporting: Multiple

Targeted industries:  Chemical, Defense/Industrial Controls, Internet/Hosting


Victim information will be provided separately to Wapack Labs security partners.

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.