Showing posts with label Nigeria. Show all posts
Showing posts with label Nigeria. Show all posts

Friday, January 12, 2018

Nigerian Hacker Leveraging Predator Pain Keylogger

TLP AMBER ANNOUNCEMENT: 

Wapack Labs identified a Nigerian hacker who was responsible for a large 2017 Predator Pain keylogger collection. This actor is actively targeting company sales departments in the Asia-Pacific region with malicious spam e-mails. Once he has established persistence on a target, he monitors internal network activity, records E-mail correspondence, and impersonates company personnel by sending contractors fake invoices...READ MORE 

Wapack Labs has cataloged and reported on Nigerian threat actors in the past. An archive of related reporting can be found in the Red Sky Alliance portal.    
 
 WWW.WAPACKLABS.COM 

This TLP AMBER report is available only to Red Sky Alliance members.

Friday, June 9, 2017

IBNS Malicious Infrastructure Targets Financial Institutions

In the last days of May, Wapack Labs identified a large email delivery infrastructure targeting multiple industries including finance and transportation. Wapack Labs dubbed this network “IBNS”. The infrastructure consists of a single name server and over 17k typo-squatted domains. The size of this recently discovered IBNS network is unprecedented. Wapack Labs believes that IBNS is a malicious provider that uses web automation and reseller services to facilitate their criminal activities. The actors sell through channels, using resellers instead of selling direct, creating a level of separation between themselves and the users. Tactics Techniques and Procedures (TTPs) associated with the activity suggest attribution to a known Nigerian fraud group. 

+++++++++++++++++++++++++++++

I hear every day about the stupid users clicking through, and the CISO that talks about the problem being in the human. Honestly? I get kinda mad when I hear it. Why? These guys are using automated psychology to overwhelm, confuse and take advantage of unsuspecting users.

It means to me that the CISO who said it has never seen well crafted emails meant to slip past the goalie.  Or perhaps they don't understand the idea that users only have so much will power, or that my own out-of-band email account (an AOL account that I've had for probably 20 years) receives far more spam than it does legitimate email.

Bad guys are smart. They know that users have only a limited amount of will power, and after seeing hundreds of spam per day, the idea that some of them are going to be opened —out of sheer exhaustion and confusion, is 100%.

Overwhelm, confuse, create fatigue, repeat, add additional sources of confusion, repeat again.

ONE typosquat dump that we identified had over 17,000 domains that look a heck of a lot like credit card and payment company domains. CapitalOne? Capital1? CapitalONE? Capital-one? My typo squats are terrible but you get the idea. Imagine dozens of variations created programmatically and then used to overwhelm.

Folks, it's not about stupid users. It's about information security folks not understanding the strategy of fatigue and confusion and then how to protect those (your) lambs as they're being lead (by Nigerian scammers, Lazarus actors, or APT) to slaughter.  It's like the door to door salesman that keeps throwing features, prices, and deals at you until you sign just together the guy out of your house.  There's psychology involved.

…and you only need one to slip past the goalie to be infected, and many times, you'll have absolutely no idea that you've been p0wned.

Wapack Labs has been running this thing that we call the Cyber Threat Analysis Center. We scour primary sources to identify intended victims before they become victims. The graphic above is a sample of a report that we provide on a weekly basis to one of our folks. We give them normalized blacklists in periodic chunks of that they can drop into their defenses —either their intrusion prevention systems, SEIM, or whatever they have.  They can wait for us to give it to them or they can pull it programmatically via API on whatever frequency that they desire.

Want to know more? Drop us a note through the website, or at jmckee@wapacklabs.com.

OK folks.. it's our first nice day in a while up here in NH and that lawn (hay field?) isn't going to mow itself.

Oh, before I forget, if you're local, I hope to see some of you at our Granite State Security cookout Monday afternoon… nothing heavy, just burgers and beer but it's supposed to be nice. Let's have some fun! Here's the link to the meet up… I've invited the local Open Source community and security folks.

Have a great weekend!
Jeff




Friday, March 10, 2017

Nigerian Passport Fraud

A known Nigerian keylogger and threat actor was observed was observed on 27 February 2017 sending a phishing email with a United States, Citizenship and Immigration Services (USCIS) and U.S. Embassy lure. The phishing email referenced recent immigration executive orders by President Trump. The email attempted to lure the target into sending the threat actor a copy of his passport presumably to be used as part of the threat actor’s fraudulent activities. Fraudulent use of any legitimate passport can result in financial fraud, terrorist activity, and a whole host of other illegal activities.

Wapack Labs has cataloged and extensively reported on keylogger operations in the past. An archive of related reporting can be found in the Red Sky Alliance Portal.

Thursday, January 12, 2017

Threat Actor with Diverse Malware Toolset

Analysis of Wapack Labs CyberWatch® data have led to the identification of a sophisticated threat actor with a diverse malware toolset. This report is being provided for your situational awareness.
  • Leverages a wide variety of malware
  • Targeting remains unknown at this time
  • Collected data indicates the threat actor is capable of reverse engineering malicious tools...READ MORE


Publication Date: 30 December 2016
Handling Requirements: Traffic light protocol (TLP) GREEN
Attribution/Threat Actors: Oldstealer
Actor Type: Adversary capabilities have been assessed as Tier III
Potential Targets: Numerous sectors
Past Reporting: N/A


The full report may be viewed in the Red Sky Alliance as DOC-4574. 
Contact Wapack Labs for more information.

Tuesday, December 6, 2016

Nigeria & Cyber Security: Two Steps Forward, One Step Back


Nigeria has long been a haven for highly talented and successful hackers, scammers, and their many spin off groups. Having developed this negative cyber reputation, Nigeria has in recent years enacted cyber laws to combat these groups and help protect their businesses and reputation. These laws were recently used for unfortunate political purposes, yet demonstrate a positive direction toward improved cyber security efforts.
  • Nigeria has a historical negative reputation for cyber hackers and scammers.
  • New cyber security legislation has been enacted to curb cybercrime.
  • Nigeria has recently arrested a popular blogger under the cyber laws, which was viewed as a political more than law enforcement measure.

While our Wapack Labs African Desk sees Nigeria making real progress in cyber security, we still see a country facing an increasing domestic and international threat in all domains of cyber security. When considerations of terrorism and the ongoing Boko Haram activities are brought into the equation, the pursuit of bloggers seems quite petty at best, and at worst, negligently misguided. While Nigeria continues to make very real steps forward in cyber security, it also tends to take a few steps backwards along the way.  This information is being supplied for your situational awareness.

Publication Date: 3 December 2016
Handling Requirements: Traffic light protocol (TLP) GREEN
Attribution/Threat Actors: Hackers & Scammers
Actor Type: Adversary capabilities have been assessed as Tier III
Potential Targets: Worldwide targets using Nigerian networks; connections to terrorism
Past Reporting: DOC-4283, DOC-4002, DOC-4486

The full report is available on our Executive Readboard.

Wednesday, November 9, 2016

Cyber in Nigeria: Local Hub of Crime with Deep Roots


Nigeria continues to be known globally as the lead in Internet scams.  The Nigerian government has stepped up efforts to combat these crimes and recently arrested “Mike” who headed the infamous cyber hacking group using 419 scams.   Mike is alleged to be a major operator within a global network of cybercriminals that included money laundering in the U.S., Europe and China.   This information is being supplied for your situational awareness.
  • Nigerian 419 scams have evolved into a wider range of cybercrime and terrorist support.
  • Worldwide militant extremists often take every advantage in the unstable cyber environment.
  • A recent Nigerian arrest shines a spotlight on their old problem, yet shows positive international solutions.

Publication date:                   5 November 2016
Handling requirements:       Traffic light protocol (TLP) GREEN
Attribution/Threat Actors:   419 type Nigerian hacker group (collusion w/Boko Haram)
Actor Type:                            Adversary capabilities have been assessed as Tier III*
Potential Targets:                  Worldwide unsuspecting victims
Past Reporting:                      DOC-3993, DOC-4283, DOC-3931
 
* Practitioners who focus on the discovery and use of unknown malicious code, are adept at installing user and kernel mode root kits10, frequently use data mining tools, target corporate executives and key users (government and industry) for the purpose of stealing personal and corporate data with the expressed purpose of selling the information to other criminal elements.

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.