Showing posts with label Japan. Show all posts
Showing posts with label Japan. Show all posts

Monday, January 22, 2018

Asian Bitcoin Exchanges as Potential Hacker Targets

North Korea has been identified as conducting multiple thefts of Bitcoin cryptocurrency in 2017. These thefts have involved spearphishing attacks against at least two Bitcoin exchanges in South Korea that resulted in compromises of their systems and the loss of millions of dollars in Bitcoin. This appears to be part of a major North Korean campaign to acquire Bitcoin as a way to raise hard currency. This campaign was active through at least, December 2017. Given the North Korean interest in Bitcoin and the success of their hacker efforts to date, other cryptocurrency exchanges in the region may also be at risk. As a guide to further monitoring of this situation, a listing of exchanges in South Korea and Japan was compiled. The Japanese list consists of those recently certified by the Japanese government and one that is still awaiting certification...READ MORE

Wapack Labs has cataloged and reported on cryptocurrency related targeting in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Tuesday, May 30, 2017

Cyber Espionage Targets Managed Service Providers (MSPs)

Wapack Labs Analysts assess with high confidence a growing cyber espionage campaign, with a Chinese nexus, that has been targeting Managed Service Providers (MSPs) in order to compromise multiple organizations. This campaign is responsible for intrusions in the United States, Europe, and Japan. Typical targets include construction, engineering, aerospace, telecom, and government institutions. The actors involved leverage a wide variety of tools and custom malware, allowing flexibility when it comes to the methods used for intrusion...READ MORE

Wapack Labs has cataloged and reported extensively on espionage campaigns in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Tuesday, January 17, 2017

Japan Spear Phished by Trojan: BKDR_ChChes

In November 2016, a string of spear phishing attacks targeted Japanese governmental agencies. The Trojan in this attack was dubbed BKDR_ChChes by the anti-virus vendor Trend Miro. Tactics, Techniques, and Procedures (TTP’s) show this was a targeted campaign using custom malware attributed to a known hacking group. Whether the Trojan was developed from the hacking group source code leak in 2015, or if it was designed by the hacking group on behalf of the attackers, is an intelligence gap.


Publication Date: January 10, 2016
Handling Requirements: Traffic light protocol (TLP) AMBER
Attribution/Threat Actors: known hacking group, unknown Chinese threat actors
Actor Type: Adversary capabilities have been assessed as TIER III
Potential Targets: Japanese Government, Worldwide Governments / Worldwide Businesses
Previous Reporting: Red Sky Alliance: DOC-2343

The full report may be viewed in the Red Sky Alliance as DOC-4606. 
Contact Wapack Labs for more information.