Showing posts with label Fraud. Show all posts
Showing posts with label Fraud. Show all posts

Friday, December 22, 2017

Hackers Compromised Russian Bank And Used SWIFT for Withdrawal

On 15 December 2017, a Russian bank lost somewhere between $100,000 and $1 million US dollars after hackers sent SWIFT wire transfers abroad to Europe, Asia, and America. The bank was compromised (medium confidence) by a hacker group who sent malicious attachments to a number of different banks a few weeks prior. SWIFT was not compromised, but was used as a tool to siphon money from the compromised bank. The bank is going through ownership reorganization. Prior to this incident, it was receiving financial regulator warnings regarding its cyber security posture...READ MORE

Wapack Labs has cataloged and reported on attacks targeting banks and SWIFT in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Wednesday, December 6, 2017

BINs Sold at Hacker Shop

TLP AMBER ANNOUNCEMENT:
 
A new hacker/carder shop was discovered by Wapack Labs. The shop sells credit card data, hacking tools and compromised dating accounts. It accepts Bitcoins, and Perfect Money, which are automatically exchanged to Bitcoins via an exchange service. The shop has advertised via direct e-mails to hackers since October 2017 and an advertisement was detected on a hacker forum in November 2017. This hacker/carder shop is currently a medium threat and has thousands of items listed for sale. Financial organizations whose BINs match those of the compromised credit cards for sale, should take notice...READ MORE

Wapack Labs has cataloged and reported on hacker and carder shops in the past. An archive of related reporting can be found in the Red Sky Alliance portal. 


 This TLP AMBER report is available only to Red Sky Alliance members. 

Underground Market Selling Stolen Credit Cards

Wapack Labs recently identified a new private underground market. The market is targeting Amazon buyer gift cards and is also selling cloned credit and debit cards. The market only accepts Bitcoin as payment for these stolen goods and ships worldwide. It offers unique discreet shipping methods of cloned credit cards at different price points: $15 to mail the card in a birthday card, $25 to stuff the card inside a teddy bear, $50 to hide the card inside a calculator, and $100 to hide the card in non-working smartphone. They also offer a service that involves sending the product to abandoned houses or to a neighbor’s house. These physical delivery methods show diverse stolen credit card smuggling innovations. Each cloned card has a $4,000 - $7,000 balance with the correct PIN and a daily $500.00 cash withdrawal limit or $3,000.00 on line spending limit...READ MORE

Wapack Labs has cataloged and reported on underground markets and credit card theft in the past. An archive of related reporting can be found in the Red Sky Alliance portal. 

Monday, November 27, 2017

Google Images Technical Support Scams

In two separate instances, Wapack Labs has reported technical support scams. Upon examining these scams, Wapack Labs observed other products being targeted by scammers. Performing a Google Image search for “<technology product> technical support” yields images with phone numbers for technical support. Upon performing basic OSINT collection against these phone numbers, it is apparent these phone numbers are involved in scams. Scammer tactics routinely offer a Remote Desktop Support to troubleshoot the devices. Some of these scams charge monthly fees for remote support services, but do not actually fix technical problems, and others are solely for dropping malware during the Remote Desktop session. The malware dropped during the Remote Desktop sessions will often include free or cracked version of keyloggers and other novice data/credential exfiltration tools...READ MORE

Wapack Labs has cataloged and reported on technical support scams in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Tuesday, November 21, 2017

New Carding Shop with Extensive History

TLP AMBER ANNOUNCEMENT:     

Wapack Labs recently observed a new carding forum. The forum was registered by a Russian proxy registrant and is hosted on a Russian IP address. It was later transferred to several Russian hosts before ending on a Cloudflare IP. The forum began operation on 11 January 2017 and, since, has offered a high volume of credit cards for sale. It is likely the current credit card inventory is a continuation and re-branding of other illegal forums or possesses a large hacking team, as its history is greater than that of the website registration. The owner of the forum has been operating since 23 September 2016 on another forum. Wapack Labs believes this actor likely began this extensive illegal credit card sales history as a verified vendor on another forum previous to the current forum...READ MORE

Wapack Labs has cataloged and reported on carding forums in the past. An archive of related reporting can be found in the Red Sky Alliance portal. 


This TLP AMBER report is available only to Red Sky Alliance members. 


Friday, November 17, 2017

New Underground Market

Wapack Labs recently observed a new underground market that trades a variety of illegal goods including credit cards, fullz, exploits, botnet builders/installs, and other cyber crime related goods. The forum’s structure and listings resemble another well-known market and may be owned by the same individuals. One seller in the market is selling GozNym 2.0 botnet installs. This seller is selling this botnet on other Tor-based black markets and is operating under same alias. The fraud sections of the market are extremely active. Despite being heavily dominated by drugs and other illegal non-cyber sales, these cyber fraud-based sellers appear highly rated. Wapack Labs has discovered that most high-rated sellers primarily deal with stolen discount gift cards obtained through carding, or with stolen electronic goods, such as like-new Apple and Samsung products. Additionally, this level of fraud sellers are often observed making bulk sales of bank accounts and credit cards...READ MORE

Wapack Labs has cataloged and reported on underground Tor markets in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Friday, November 3, 2017

New Carding Shop

Wapack Labs observed a threat actor advertising a new carding shop on a hacking/carding forum. This threat actor first advertised the carding services on 21 July, 2017 and has been an active member on the forum, frequently advertising updates to their carding website. Currently the shop has over 500,000 stolen credit cards for sale from over 100+ banks. The shop updates its database with fresh cards on a bi-weekly basis. To access the shop, users must create a free account and enter a username, password, Jabber, and ICQ number (users can enter fake credentials). Once the account is created, users can freely browse the website. Web sections include news, cards, rules, orders, billing, checker, and support. The cards section identifies stolen credit cards. Credit cards are sorted by database, bank name, type, card issuer, country, state, city, city, or BIN. Full card information is provided before purchasing a card. Prices of the cards ranged from $1 to $40 USD. The checker section allows users to enter credit card information to see if the card is still valid. The shop charges 30 cents per check and has a refund policy of 5 minutes after purchase, if the card is invalid...READ MORE

Wapack Labs has cataloged and reported on carding shops and fraud in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
  
WWW.WAPACKLABS.COM

Friday, October 27, 2017

Dark Web Site Selling ATM Malware

Wapack Labs observed ATM malware being sold on a dark web site. The malware targets all models of Wincore Nixdorf ATMs. The website explains that the Wincore 200xe ATMs are the easiest cash machines to exploit. The malware currently costs $1500.00 in Bitcoin for the first month (beginning 15 October 2017). After the first month, the ‘registration’ fee will be doubled. $1500.00 buys the buyer one credit, which is valid for a one time use on one ATM. To execute the attack users must log-in to their account on the website and receive a code (for one credit). The malware will then show the attacker the amount of cash in each money cassette that resides inside the ATM. The malware will then bypass the normal ATM system processes and the ATM will dispense all the bills in a desired cassette. The website also provides video links on their Tor site, demonstrating the method to fraudulently withdraw money, along with a free 10-page step-by-step Word document which explains how to use the malware. This guide describes in detail the tools required, software instructions, and details referencing different types of ATMs. This includes how the ATMs operate and how to find the interior USB ports...READ MORE

Wapack Labs has cataloged and reported on ATM malware in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
  
WWW.WAPACKLABS.COM

Monday, September 25, 2017

New Tor Forum Recruiting Members

On 21 September 2017, Wapack labs observed a new tor based forum. The discovery was made while monitoring another space where members post and review dark web markets. The forum is recently new and has three main discussion sections within the forum: Drugs, Fraud, and General. With the forum recently opening for registration, the number of members is likely to grow. If members from other forums have migrated to the new forum, it has potential to become a reliable replacement market on the dark web. Wapack Labs will monitor the new forum and report on any activities affecting Red Sky Alliance members...READ MORE 

Wapack Labs has cataloged and reported extensively on Tor forums and markets in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Friday, June 9, 2017

IBNS Malicious Infrastructure Targets Financial Institutions

In the last days of May, Wapack Labs identified a large email delivery infrastructure targeting multiple industries including finance and transportation. Wapack Labs dubbed this network “IBNS”. The infrastructure consists of a single name server and over 17k typo-squatted domains. The size of this recently discovered IBNS network is unprecedented. Wapack Labs believes that IBNS is a malicious provider that uses web automation and reseller services to facilitate their criminal activities. The actors sell through channels, using resellers instead of selling direct, creating a level of separation between themselves and the users. Tactics Techniques and Procedures (TTPs) associated with the activity suggest attribution to a known Nigerian fraud group. 

+++++++++++++++++++++++++++++

I hear every day about the stupid users clicking through, and the CISO that talks about the problem being in the human. Honestly? I get kinda mad when I hear it. Why? These guys are using automated psychology to overwhelm, confuse and take advantage of unsuspecting users.

It means to me that the CISO who said it has never seen well crafted emails meant to slip past the goalie.  Or perhaps they don't understand the idea that users only have so much will power, or that my own out-of-band email account (an AOL account that I've had for probably 20 years) receives far more spam than it does legitimate email.

Bad guys are smart. They know that users have only a limited amount of will power, and after seeing hundreds of spam per day, the idea that some of them are going to be opened —out of sheer exhaustion and confusion, is 100%.

Overwhelm, confuse, create fatigue, repeat, add additional sources of confusion, repeat again.

ONE typosquat dump that we identified had over 17,000 domains that look a heck of a lot like credit card and payment company domains. CapitalOne? Capital1? CapitalONE? Capital-one? My typo squats are terrible but you get the idea. Imagine dozens of variations created programmatically and then used to overwhelm.

Folks, it's not about stupid users. It's about information security folks not understanding the strategy of fatigue and confusion and then how to protect those (your) lambs as they're being lead (by Nigerian scammers, Lazarus actors, or APT) to slaughter.  It's like the door to door salesman that keeps throwing features, prices, and deals at you until you sign just together the guy out of your house.  There's psychology involved.

…and you only need one to slip past the goalie to be infected, and many times, you'll have absolutely no idea that you've been p0wned.

Wapack Labs has been running this thing that we call the Cyber Threat Analysis Center. We scour primary sources to identify intended victims before they become victims. The graphic above is a sample of a report that we provide on a weekly basis to one of our folks. We give them normalized blacklists in periodic chunks of that they can drop into their defenses —either their intrusion prevention systems, SEIM, or whatever they have.  They can wait for us to give it to them or they can pull it programmatically via API on whatever frequency that they desire.

Want to know more? Drop us a note through the website, or at jmckee@wapacklabs.com.

OK folks.. it's our first nice day in a while up here in NH and that lawn (hay field?) isn't going to mow itself.

Oh, before I forget, if you're local, I hope to see some of you at our Granite State Security cookout Monday afternoon… nothing heavy, just burgers and beer but it's supposed to be nice. Let's have some fun! Here's the link to the meet up… I've invited the local Open Source community and security folks.

Have a great weekend!
Jeff




Friday, March 10, 2017

Nigerian Passport Fraud

A known Nigerian keylogger and threat actor was observed was observed on 27 February 2017 sending a phishing email with a United States, Citizenship and Immigration Services (USCIS) and U.S. Embassy lure. The phishing email referenced recent immigration executive orders by President Trump. The email attempted to lure the target into sending the threat actor a copy of his passport presumably to be used as part of the threat actor’s fraudulent activities. Fraudulent use of any legitimate passport can result in financial fraud, terrorist activity, and a whole host of other illegal activities.

Wapack Labs has cataloged and extensively reported on keylogger operations in the past. An archive of related reporting can be found in the Red Sky Alliance Portal.

Thursday, September 29, 2016

Credit Card Fraud & EMV Security Chip

Mobile banking fraud in Europe has increased by a factor of 20; a trend that could follow in the U.S.  Credit card fraud has hit critical mass in the U.S., causing a push in technology in new mobile apps, which could create a virtual playground for criminals.  A recent surge in the volume of U.S. credit card fraud has forced industries to adopt the European EuroPay, MasterCard and Visa (EMV) card system.  The resistance to the EMV conversion will result in higher merchant costs and ATM manufacturer resistance, which has prompted a growth in mobile banking apps.

Publication date:                        26 September 2016

Handling requirements:              Traffic light protocol (TLP) GREEN

Attribution/Threat Actors:          Unknown at this time

Actor Type:                                 Adversary capabilities have been assessed as Tier III*

Potential Targets:                        USA

Past Reporting:                            Red Sky Alliance: DOC-3952, DOC-4265

*Practitioners who focus on the discovery and use of unknown malicious code, are adept at installing user and kernel mode root kits10, frequently use data mining tools, target corporate executives and key users (government and industry) for the purpose of stealing personal and corporate data with the expressed purpose of selling the information to other criminal elements. 

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.

Wednesday, July 3, 2013

The Secret Lives of Computers

The Secret Lives of Computers:

The things you find in a digital forensic investigation




It is often asked “Why would I ever conduct a forensic investigation on a computer?!” Well if you are concerned about what people are doing on a computer (or cell phone), what is going on it, coming from it, or happening to it then it benefits you to conduct an investigation. A digital forensic investigation sounds like a big complicated procedure, but an initial examination can have a relatively quick turn around and give you plenty of information. In some cases involving white collar crime, a single investigation (with an affidavit) can be brought to civil court to produce injunctive relief or even settlements.

So let's begin to answer the mysteries of a computer investigation and see if it is something that would benefit you, your company, or legal situation. In a preliminary forensic investigation many questions can be answered if you are concerned about something specific, but typically we like to try and shed light on the following:

File Activity

No, unfortunately I can't show you files jumping around or being active, but I can show you creation, deletion, and modification. In most cases this file activity drives the rest of the investigation. When we plot out file activity on a timeline it begins to tell a tale of what was going on with the computer at the time. For instance if we see large file creation on a certain date, then that usually indicates things like installing programs or copying files from one place to another. If we see a lot of file deletion, then that could mean that someone is trying to “burn” or “shred” the evidence. If you couple large creation and deletion together then that could point to someone copying files from one place (let’s say your company’s network server) to the local system, copying off the computer (maybe to a thumb drive) and then wiping them clean. Or so they think.

USB Drives

USB devices are becoming more ubiquitous and increasing to incredibly large capacities. The amount of data that used to be contained in several servers is now placed onto one 2TB external hard drive. While their capacity is very large, their physical size gets smaller and smaller. Are you aware of all the things that your employees are carrying on a thumb drive? Very few companies implement a policy to control the flow of information to external devices. In my experience, a majority of my investigations have included someone plugging a thumb drive into their computer days, if not hours before they leave the company. Are you sure they only took their personal photos and music, or did they just clean out all of your client records and proprietary information?

Internet History

Internet history can sometimes be the most telling of all the information in a computer. How often do you go to work, log into your computer, and then go directly to Gmail and log into your personal email? Few companies restrict this type of personal access (although they may frown upon it). Today many applications and services are becoming “cloud ready”. This means that information is no longer stored on your local systems. Instead this information travels out over the Internet and is stored on some other company’s servers. Is it secure in travel? Is it safe when sitting on those servers? Many services like Dropbox also offer huge amounts of storage space for people to upload information to. An employee could easily upload information from their system, to Dropbox, and then access it from anywhere else in the world.
If you aren’t concerned about movement of data through the Internet, maybe you are concerned about what your employees are doing on their computers as far as spending too much time on Facebook or playing games. Plenty of HR people lose sleep over what is being done and said over things like Facebook or Instant Messaging. In many cases a computer investigation can collect and parse this type of information and even give you remnants of the pages that the person looked at. For investigations pertaining to harassment, chat logs can be collected and produced for legal counsel (in many cases even if they had been deleted).

Wait, there’s more…


These are just a few of the things that a standard preliminary investigation could offer you. If you have a concern about what is happening on your work or personal computers, then please give Wapack Labs a call to find out how we can help. Whether you are in HR, legal, IT, or own your own business, there are several ways that we could help put your mind at ease or solidify a legal action. Our certified and experienced digital forensic examiners can assist with almost any type of digital investigation. We specialize in helping even those that have never heard of digital forensics or are wary of technology in general. Don’t worry, we speak English too and won’t get overly technical! Wapack Labs is located in Manchester, NH and services all of New England. Call us at 603-606-1246, email me at dkirmes@wapacklabs.com, or stop by our lab at 250 Commercial St. Suite 2013.

Thursday, May 2, 2013


Your Company Is Walking Out the Door

Today just about every company in America has their vital proprietary information on computers. Everything from email, client lists, pricing models, to trade secrets is stored on company computers. In many cases those computers leave the office daily, or sometimes never show up onsite if the employee works from home. Even if your company utilizes the most rigid security rules and not a single computer leaves the facility, emails are still sent back and forth from smart phones. A lot of the time attachments can be saved directly from emails to the smart phones and then transferred on from there without the company’s IT department ever being aware.

This situation becomes even more precarious when you include companies that allow people to bring their own device (BYOD). In these situations company data often resides on the personal laptop or in a “cloud” solution where the data are available from any device connected to the internet. What happens when the employee leaves? Can you guarantee that nothing was stolen, deleted maliciously, or taken to a competing shop? Without conducting a proper digital forensic investigation by certified examiners you may never know what was taken. Even if your internal IT department does their due diligence in trying to determine a theft, without the proper forensic handling of the evidence, it may not be admissible in court.

Attorney Sid Leach from the law firm Snell & Wilmer wrote an excellent paper (“What Every Lawyer Needs to Know about Computer Forensic Evidence”) pertaining to the valuable information that digital forensic investigations reveal. Whether it pertains to fraudulent activities, non-compete contracts, harassment, or intellectual property theft, Mr. Leach explains that “A forensic examination of a departing employee’s laptop or computer workstation can provide a goldmine of information concerning what the ex-employee was doing”.

In my own experiences I have seen companies both large and small with employees leaving abruptly or on bad terms causing suspicions as to their activities. It is always in the company’s best interest to at least have a forensic examiner create a forensically sound bit-by-bit copy of the device before it is used by another employee. In these situations, even if your company doesn’t proceed with an immediate investigation, at least you have a court admissible copy to work from if anything were to arise in the future. Wapack Labs is a digital forensic firm based in Manchester, NH with certified and experienced digital forensic examiners to handle any investigation or discovery need. Contact us today to see how we can help you!