Showing posts with label PoS. Show all posts
Showing posts with label PoS. Show all posts

Monday, August 14, 2017

DiamondFox in the Wild

TLP AMBER ANNOUNCEMENT: 

DiamondFox is a credential stealing multi purpose botnet that is available on the black market as MaaS (Malware as a Service). Also known as Gorynych, DiamondFox is still actively leveraged in the wild with its recent version Crystal available in online marketplaces. This dangerous malware can steal information from PoS (Point of Sale) systems with campaigns targeting multi-state healthcare providers, dental clinics, manufacturers, and technology companies. To get a picture of the current state of DiamondFox botnets, Wapack Labs has collected recent samples and extracted the command and control (C2) information from their configuration files. This report provides technical details on DiamondFox, the Russian botnet infrastructure, and details regarding the domains...READ MORE

Wapack Labs has cataloged and reported extensively on malware and botnets in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

This TLP AMBER report is available only to Red Sky Alliance members.

Monday, March 27, 2017

Major Underground Carder Utilizes Point of Sale (PoS) Malware

Wapack Labs is researching a major underground carder who solicits on various carding/hacking forums. This actor advertises thousands of stolen credit cards from countless international banks. Actor's activity can be seen on several online shops, as well as many other connection points. The actor is also carding numerous retail stores in international venues with Point of Sale (PoS) malware, or skimmers. Wapack Labs is researching the actor's Tactics, Techniques and Procedures (TTPs).

Wapack Labs has cataloged and reported extensively on carding forums in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Monday, March 6, 2017

Hacking Community Re-directs Novice Forums

Wapack Labs Analysts are providing an update regarding an underground carding, malware, and skimming community run by hackers. One of the members is known for his involvement in PoS (Point of Sales) breaches of several retail chains. Our analysts recently observed this community advertising in novice carder forums, which they had not done before. Their websites all re-direct buyers to a different carding shop which are copies of domains. Some individuals in the underground carding community consider these sites to be compromised by law enforcement. Pushing their capabilities to a wider, even if less experienced audience, may trigger a rise in PoS attacks.

Wapack Labs has cataloged and extensively reported on underground communities in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Get Alerts as the Wapack Cyber Technical Reports are Posted. Become a Subscriber, Click here and Get 14 days for 99 cents!

TLP: AMBER
ACTOR TYPE: (III)
SERIAL: TR-043-2017
COUNTRIES: UA, RU
INDUSTRIES: All
REPORT DATE: 20170302