Showing posts with label Australia. Show all posts
Showing posts with label Australia. Show all posts

Wednesday, February 8, 2017

The Taxman Cometh: Selling W-2 Forms in the Darkweb


Wapack Labs has identified an actor in the Tor-based markets - we have labeled “Taxman”. Taxman is selling U.S. W-2 Forms from 2016 as well as taxpayer dates of birth. He also sells bank account information for at least one U.S. and one Australian bank, as well as Credit Reports. Taxman also sells botnets, along with installation and support for same. He is a verified vendor on several Darkweb Tor-based .onion domains and deals exclusively in Bitcoin. 

TLP: AMBER
ACTOR TYPE: (III)
SERIAL: TR-030-2017
COUNTRIES: US, Australia
INDUSTRIES: Financial
REPORT DATE: 20170207

Tuesday, January 3, 2017

Australian Malware Authors Release New Trojan


Wapack Labs assesses, with medium confidence, that Australian malware authors (medium confidence) have released a new banking Trojan.  This Trojan performs real time web-injections and redirection attacks on its victims.  It currently enjoys low and generic detection by intrusion prevention systems.  Analysts at IBM report to have followed the Trojan during its testing cycles3.  It now has moved out of the testing phase and is actively defrauding banks and consumers.  If it becomes as virulent (as did its' predecessors), it will likely spread to the US by the second quarter of 2017...READ MORE

Publication Date: 23 December 2016
Handling Requirements: Traffic light protocol (TLP) AMBER.
Attribution/Threat Actors: Australian Malware Authors
Actor Type: Adversary capabilities have been assessed as TIER III.
Industries Targeted: Financial
Past Reporting: Red Sky Alliance: DOC-2301, DOC-2522, DOC-3456, Message #7963

The full report may be viewed in the Red Sky Alliance as DOC-4566.  
Contact Wapack Labs for more information.