Showing posts with label Indetectables. Show all posts
Showing posts with label Indetectables. Show all posts

Tuesday, January 10, 2017

Spanish Underground Promotion: Malware Cloaking Tool


Wapack Labs has identified a malware concealing tool that is being promoted by a persona on the Spanish Forum, indectables.net. This report is being provided for your situational awareness.
  • Indetectables.net is a very active underground Spanish forum
  • The malware cloaking tool is for Windows 7-10
  • Undetected malware can have serious ramification to network stability...READ MORE


Publication Date:u30 December 2016
Handling Requirements: Traffic light protocol (TLP) GREEN
Attribution/Threat Actors: Spanish underground forum persona
Actor Type: Adversary capabilities have been assessed as Tier II
Potential Targets: Numerous sectors
Past Reporting: Red Sky Alliance: DOC-4323, 4420, 4469

The full report may be viewed in the Red Sky Alliance as DOC-4573. 
Contact Wapack Labs for more information.

Tuesday, November 1, 2016

Indetectables RAT Receives Help from Several White Hat Hackers


In late September 2016, a Spanish speaking hacker released an updated version of a popular white hat developed Remote Access Tool (RAT) named “Indetectables RAT” on the Spanish language hacker forum Indetectables.net. This tool is posted to dozens of international hacker groups who have targeted US and international institutions and has a low anti-virus detection payload (13/56) for samples submitted to Virus Total. The hacker also received the advice of several well-known international white hat hackers whom he/she credits in the latest builder version (v.0.9.2).

Publication date:                        24 October 2016
Handling requirements:            Traffic light protocol (TLP) AMBER
Attribution/Threat Actors:       Indectables hacker
Actor Type:                                 Adversary capabilities have been assessed as Tier III*

Potential Targets:                       US/International institutions

Past Reporting:                           N/A

Indicators:                                   https://www.threatrecon.co/search?keyword= Indetectables_RAT

*Practitioners who focus on the discovery and use of unknown malicious code, are adept at installing user and kernel mode root kits10, frequently use data mining tools, target corporate executives and key users (government and industry) for the purpose of stealing personal and corporate data with the expressed purpose of selling the information to other criminal elements. 

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs


Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.

Thursday, October 13, 2016

South American Based Indetectables Member Shares RAT

Current Wapack Labs research revealed a Spanish language forum, Indetectables.net Forum, which highlights a member selling a popular remote access tool (RAT).  This information is being supplied for your situational awareness and protection. 







Publication date:                    26 September 2016

Handling requirements:          Traffic light protocol (TLP) AMBER

Attribution/Threat Actors:      Indetectables member

Actor Type:                             Adversary capabilities have been assessed as Tier III*


Potential Targets:                   USA / Brazil / South America

Past Reporting:                       Red Sky Alliance: DOC-2236, DOC-3379, DOC-3699

*Practitioners who focus on the discovery and use of unknown malicious code, are adept at installing user and kernel mode root kits10, frequently use data mining tools, target corporate executives and key users (government and industry) for the purpose of stealing personal and corporate data with the expressed purpose of selling the information to other criminal elements. 

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.