Showing posts with label Phishing. Show all posts
Showing posts with label Phishing. Show all posts

Monday, June 17, 2019

Newly Identified Phishing Malware, Allantibots, Can Fool Even The Most Eagle-eyed User.

Apple IDs are a popular target for hackers because they can enable theft of financial data and other personally identifiable information (PII). These are often obtained through phishing campaigns intended to trick users into entering their personal data. In June 2019, Wapack Labs identified one such campaign that is leveraging a large infrastructure and a phishing kit dubbed ‘Allantibots’. Allantibots is a sophisticated phishing package and is characterized by its ability to spoof the Apple URL. This results in a phishing URL that looks completely legitimate, even to a cautious user. To read the article go here: https://redskyalliance.org/finished-analysis/allantibots

To read the full article and find an archive of related cyber reporting, follow this link to  Allantibots Article 

Be sure to check out our cyber portal for other related articles Red Sky Alliance.org

Thursday, January 4, 2018

2018 Cyber Security Threat and Vulnerability Predictions

This report encapsulates our predictions regarding the most significant cyber threats and vulnerabilities for 2018.
  • Phishing: Will likely become more popular among novice and criminal hackers.
  • Account Targeting: Account credentials are increasingly more available.
  • Democratization of Cyber Weapons: 2017 saw the most high-profile ransomware attack to-date with the Wannacry worm.
  • Tor Network: 2018 is the year of fighting and winning against the abuse of the Tor network.
  • Macro Malware: The popularity of malicious macros for malware delivery continued strong in 2017.
  • Geopolitical Tensions: Iran and North Korea tensions continue.
  • Blockchain-related Cybercrime: With the establishment of Bitcoin futures and general interest to blockchain technologies, exploitation in this field grows too...READ MORE
Wapack Labs has cataloged and reported on cyber threats and vulnerabilities in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Wednesday, November 15, 2017

Malicious URLs Used in Phishing Attempt

On 07 November, 2017 Wapack Labs observed, using Cyber Threat Analysis Center (CTAC), various emails in the URL of two phishing domains. The two phishing domains had different URLs but utilized the same web page interface. One domain is a compromised domain with an anti-virus detection ratio of 10/64 that has been leveraged since 12 June 2017. It is not flagged as suspicious as by Google Chrome browser. The second domain has an anti-virus detection ratio of 11/65 and has been leveraged since 02 October 2017. This domain was flagged as suspicious by Google Chrome browser. Both domains are still active. The phishing attempt appears to be a simple credential stealing scheme. The phishing page is disguised as Microsoft One Drive, attempting to get users to enter their passwords. Wapack Labs is providing this warning report as situational awareness...READ MORE

Wapack Labs has cataloged and reported on malicious URLs and phishing attempts in the past. An archive of related reporting can be found in the Red Sky Alliance portal.


Monday, September 25, 2017

Aeronautical Phishing Campaign Targets Transportation

TLP AMBER ANNOUNCEMENT:

Several email accounts were identified as part of an apparently unsuccessful phishing attack on several transportation related organizations. These email addresses were targeted in a phishing campaign, but the intended victims did not receive the phishing message due to a rate limit on the attacker’s email account. While the phishing message body was not observed, the subject line of the message was “Court Notice,” indicating the lure to be legal themed. The unsuccessful phishing attack took place on 15 January 2017. Monitoring of the keylogger data is ongoing, however, Wapack Labs has no further information at this time...READ MORE

Wapack Labs has cataloged and reported phishing attacks and credential theft in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

This TLP AMBER report is available only to Red Sky Alliance members.

Friday, August 11, 2017

Microsoft Office Hoax Phishing Site

On 27 July 2017, Wapack Labs, using our Cyber Threat Analysis Center (CTAC), discovered a phishing site disguised as a Microsoft Office Sign-in page. The phishing site is designed to trick users into entering their Microsoft related email and passwords. When a user enters their credentials into the malicious site, they are then redirected to the real Microsoft Sign-in page. The differences in the webpages can be seen in...READ MORE

Wapack Labs has cataloged and reported extensively on phishing in the past. An archive of related reporting can be found in the Red Sky Alliance portal.



Thursday, July 20, 2017

Financially Motivated APT-style Actors Target Retail & Hospitality

A new wave of financially motivated, APT-style group, of cyber threat actors are targeting large restaurant chains with phishing emails containing malicious attachments. As early as April 2017, a new wave of the group's activity has been targeting the retail and hospitality sectors. The APT-style group has been active since 2015 and is known for their use of the Carbanak malware. The most recent campaigns leverage two new RTF droppers to deliver a variant of a known backdoor. Early campaigns were known for targeting financial institutions and banks; in 2015, targeting European banks through a banking application called the Internet Front End Banking System (iFOBS). This report describes TTPs leveraged in the recent campaigns...READ MORE

Wapack Labs has cataloged and reported extensively on APTs, cyber threat actors, phishing, malware, financial institutions, and Carbanak in the past. An archive of related reporting can be found in the Red Sky Alliance portal.



Tuesday, April 11, 2017

FTC Subpoena-Themed Reconnaissance Campaign

Wapack Lab's analysts, using the Cyber Threat Analysis Center (CTAC), discovered a reconnaissance campaign that we assess with moderate confidence was conducted in preparation for a more malicious campaign. The logs contained email addresses, filenames, and IP addresses. It is believed these logs are from a phishing campaign that leveraged “FTC subpoena” (Federal Trade Commission) lures to entice targets to click a link in the email...READ MORE

Wapack Labs has cataloged and reported extensively on reconnaissance campaigns in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Thursday, March 30, 2017

"Hacking” – lead411.com Anyone?

During recent analysis, Wapack analysts discovered a sales lead email from app.lead411.com. Lead411 is a sales lead generation tool that mines open sources for opportunities. Hackers have been known to apply such tools for a lesser known use-case: pre-attack reconnaissance. In this case, a bad actor signed up for a lead411 account and is using it to identify potential victims for future targeting and topics or issues that can be used to lend legitimacy to a phishing email or possible CEO fraud.

Wapack Labs has cataloged and reported extensively on reconnaissance in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Friday, March 10, 2017

Nigerian Passport Fraud

A known Nigerian keylogger and threat actor was observed was observed on 27 February 2017 sending a phishing email with a United States, Citizenship and Immigration Services (USCIS) and U.S. Embassy lure. The phishing email referenced recent immigration executive orders by President Trump. The email attempted to lure the target into sending the threat actor a copy of his passport presumably to be used as part of the threat actor’s fraudulent activities. Fraudulent use of any legitimate passport can result in financial fraud, terrorist activity, and a whole host of other illegal activities.

Wapack Labs has cataloged and extensively reported on keylogger operations in the past. An archive of related reporting can be found in the Red Sky Alliance Portal.

Friday, March 3, 2017

The Amateur from Algeria

On March, 1, 2017 Wapack Labs Researcher observed a hacker providing malicious tools on various Arabic, Russian, and English hack-forums. He was observed selling gift cards for Bitcoin (BTC), promoting phishing scams, and posting website defacements. The hacker has the necessary skills to create basic exploits. The fact that his malicious software is free, may speak to its quality - or people’s trust in a novice...READ MORE

Wapack Labs has extensively reported on carders in the past. An archive of related reporting can be found in the Red Sky Alliance Portal.

TLP: AMBER
ACTOR TYPE: (II)
SERIAL: TR-042-2017
COUNTRIES: DZ
INDUSTRIES: Financial
REPORT DATE: 20170301

Friday, January 20, 2017

Algerian Phishing Attempt


A Red Sky Alliance member is reporting a suspected phishing email to Wapack Labs. Subsequent analysis reveals the campaign was initiated by an Algerian threat actor associated with a known hacking team. This Algerian threat actor compromised a French auto dealership on 19 July 2016 and sent phishing emails to a social group in New England U.S.A from a compromised domain belonging to a pizza shop in South Carolina. This information is offered as a caution; presented for your situational awareness.
  • Algerian threat actor associated with known hacking team.
  • Previously targeted French organizations for religious/national reasons. Target set and motivations, for the attacks, may have evolved.
  • The hacking team's twitter went dormant on 17 Sep 2015 with the message “#Team_Closed Goodbye and Expect Us in 2016”. On 19 December 2016 the group created a new Facebook page and appears active again...READ MORE
Publication Date: 12 January 2017
Handling Requirements: Traffic light protocol (TLP) GREEN
Attribution/Threat Actors: Laakel En Person/Moujahidin Team
Actor Type: Adversary capabilities have been assessed as Tier II
Potential Targets: Worldwide phishing
Past Reporting: N/A


The full report may be viewed in the Red Sky Alliance as DOC-4608. 
Contact Wapack Labs for more information.

Tuesday, December 27, 2016

Google AdWords Phishing Campaign

Wapack Labs has discovered a new phishing campaign. While generally simplistic, it contains some elements of high sophistication. It is also fairly expensive to operate, which suggests it is a precursor to a more sophisticated and potentially harmful campaign. Wapack Labs conducted a brief tactical analysis and is providing this report for your situational awareness.
  • Search for “Facebook” in Google Chrome produced a link to a fake anti-virus malware. 
  • Facebook was notified of this activity.
  • A much more serious malware campaign targeting major social, retail, and online companies may be in the works...READ MORE
Publication Date: 19 December 2016
Handling Requirements: Traffic light protocol (TLP) GREEN
Attribution/Threat Actors: Google AD campaign phishing/unknown author
Actor Type:  Adversary capabilities have been assessed as Tier II
Industries Targeted: Financial, business and retail sectors
Past Reporting: Red Sky Alliance: DOC-2901
Companies Cited In This Report: Facebook, EBay, and Home Deport

The full report may be viewed in the Red Sky Alliance as DOC-4557.  
Contact Wapack Labs for more information.

Monday, September 19, 2016

African Phishing Attacks and Money Transfer Woes

www.pcmag.com
Current intelligence from Africa revealed that many clients of CBAO Bank, a well-known West African banking group and the newly created Ivorian-Moroccan bank, Banque Atlantique, have been the targets of recent phishing attacks.  Customers are receiving targeted spoofed e-mails from false bank advisors informing them that, for security measures, they must update their banking information either by filling out a dynamic .pdf and sending it to designated e-mail address, or to connect via a given spoofed link from which online account information is then harvested.  These tactics have been used in Western Europe and the U.S. but might be re-employed due to recent success in Africa.  Additionally, money transfer provider’s trustworthiness is appearing to become an issue in Senegal, which has affected many local residents.  Both these issues are being tracked.  This information is being supplied for your situational awareness. 

Publication date:                           17 September 2016

Handling requirements:                 Traffic light protocol (TLP) GREEN

Attribution/Threat Actors:             African phishing and money transfer providers

Actor Type:                                    Tier II     

Potential Targets:                           International

Past Reporting:                               DOC-3811

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.