Showing posts with label Asia. Show all posts
Showing posts with label Asia. Show all posts

Thursday, March 15, 2018

SWIFT: India City Union Bank Heist

TLP AMBER ANNOUNCEMENT:

On Saturday 17 February 2018, India’s City Union Bank disclosed that its systems were hacked. They discovered that three fraudulent remittances, totaling nearly $2 million, were sent to accounts in Dubai, Turkey, and China via the SWIFT financial platform. SWIFT, or the Society for Worldwide Interbank Financial Telecommunication, is the world’s largest electronic payment messaging system, facilitating the exchange of more than $6 trillion a day. The majority of international interbank messages use the SWIFT network. This network enables financial institutions worldwide to send and receive information about financial transactions in a secure, standardized and reliable format. SWIFT sends payment orders, which must be settled by correspondent accounts that the institutions maintain with each other. SWIFT bank heists in the past have been attributed, with medium confidence, to North Korean actors...READ MORE

Wapack Labs has cataloged and reported on cyber threats targeting SWIFT in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

This TLP AMBER report is available only to Red Sky Alliance members.

Monday, January 22, 2018

Asian Bitcoin Exchanges as Potential Hacker Targets

North Korea has been identified as conducting multiple thefts of Bitcoin cryptocurrency in 2017. These thefts have involved spearphishing attacks against at least two Bitcoin exchanges in South Korea that resulted in compromises of their systems and the loss of millions of dollars in Bitcoin. This appears to be part of a major North Korean campaign to acquire Bitcoin as a way to raise hard currency. This campaign was active through at least, December 2017. Given the North Korean interest in Bitcoin and the success of their hacker efforts to date, other cryptocurrency exchanges in the region may also be at risk. As a guide to further monitoring of this situation, a listing of exchanges in South Korea and Japan was compiled. The Japanese list consists of those recently certified by the Japanese government and one that is still awaiting certification...READ MORE

Wapack Labs has cataloged and reported on cryptocurrency related targeting in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Thursday, January 18, 2018

Vietnamese APT Actors Involved in Watering-Hole Attacks

Beginning in February of 2017 a group of Vietnamese APT actors carried out a large campaign leveraging watering-hole attacks. The campaign is intended to conduct surveillance on entities within Southeast Asia and China. As part of the watering-hole attacks, the group leveraged a JavaScript reconnaissance framework to collect information on their targets. This report looks at the malicious JavaScript framework leveraged by the attackers, provides information on attribution, and looks at the infrastructure behind the campaign...READ MORE 

Wapack Labs has cataloged and reported on APT activity and watering-hole attacks in the past. An archive of related reporting can be found in the Red Sky Alliance portal. 

Friday, January 12, 2018

Nigerian Hacker Leveraging Predator Pain Keylogger

TLP AMBER ANNOUNCEMENT: 

Wapack Labs identified a Nigerian hacker who was responsible for a large 2017 Predator Pain keylogger collection. This actor is actively targeting company sales departments in the Asia-Pacific region with malicious spam e-mails. Once he has established persistence on a target, he monitors internal network activity, records E-mail correspondence, and impersonates company personnel by sending contractors fake invoices...READ MORE 

Wapack Labs has cataloged and reported on Nigerian threat actors in the past. An archive of related reporting can be found in the Red Sky Alliance portal.    
 
 WWW.WAPACKLABS.COM 

This TLP AMBER report is available only to Red Sky Alliance members.

Wednesday, June 7, 2017

NK Lazarus Threat to the Financial Sector Remains High

Newly discovered Command & Control (C2) Internet Protocols (IPs) confirm the geolocation of North Korean threat actors, Lazarus Group; despite their deliberate attempts at misdirection. They are known for their custom-tailoring and reuse of code between malware families and campaigns. Since 2009, Lazarus Group has targeted Asian-based financial institutions, European and South American financial institutions, and media companies, such as Sony Pictures. Recent financial and trading sanctions, levied on North Korea, will increase the likelihood of attacks on financial sectors; similar to the documented attacks, leveraging the Society for Worldwide Interbank Financial Telecommunications (SWIFT), to compromise central banks...READ MORE

Wapack Labs has cataloged and reported extensively on financial compromise and the Lazarus Group in the past. An archive of related reporting can be found in the Red Sky Alliance portal.