Showing posts with label RAT. Show all posts
Showing posts with label RAT. Show all posts

Friday, March 9, 2018

REMCOS Remote Administration Tool

REMCOS is a new, publicly available Remote Administration Tool (RAT) that has become popular with hackers. Since January 2018, over 14 hundred samples were submitted to Virus Total, indicating the RAT is growing in popularity. Recent changes to Tactics, Techniques, and Procedures (TTP) include embedding payloads in MP3 and JPEG files; resulting in little to no Antivirus (AV) detections and significantly increasing the likelihood for infections. The malware in this report downloads payloads embedded in other files with little or no current detections, which may indicate the possibility of a high infection rate...READ MORE

Wapack Labs has cataloged and reported on Remote Administration Tools in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Friday, July 14, 2017

Petya/NotPetya and Really Not Petya - Loki Bot Credential Stealing Malware


In late June 2017, Wapack Labs identified a malicious email targeting Ukrainian Financial Institutions (FI) to deliver a credential stealing malware called Loki Bot. This incident happened at the same time as the Petya/NotPetya Ransomware outbreak, which also targeted Ukrainian banking infrastructure. Possibly due to the confusion generated during the initial Petya/NotPetya outbreak, Loki Bot samples and C2s were reported as being Petya/NotPetya ransomware. Further confusion resulted when Anti-virus (AV) detections began identifying Loki Bot as Petya/NotPetya. Loki Bot is sold in underground Tor marketplaces and can steal passwords from browsers, File Transfer Protocol (FTP) applications, email accounts, and crypto-coin wallets. This report discusses the misattribution of Loki Bot, along with technical details of analyzed Loki Bot samples

Get the full report here. 
Wapack Labs has cataloged and reported extensively on Loki Bot, and Loki RAT, in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Monday, February 27, 2017

The Economical RAT: Luminosity.Link


The Luminosity.Link Remote Administration Tool (RAT) has been observed by a number of companies over the past year being spread through phishing emails. The Luminosity.Link RAT is sold openly online and contains numerous features that make it popular among cyber criminals. Luminosity.Link is designed using the .NET framework for use on Windows Operating systems. 

The Key Findings of our analysis revealed:
  • Recent samples leverage the AutoIt scripting tool
  • Luminosity.Link uses the SundownEK (Exploit Kit) for delivery
  • Luminosity.Link samples contain encrypted configurations
Luminosity.Link is an economical RAT for cyber criminals. Coupling it with Exploit Kits targeting Windows systems further increases infection success rates. We assess with high confidence that the development and use of the Luminosity.Link RAT will continue...READ MORE

Wapack Labs has extensively reported on Remote Access Tools (RAT) in the past. An archive of related reporting can be found in the Red Sky Alliance Portal. 

TLP: AMBER
ACTOR TYPE: (I&II)
SERIAL: FR17-002 
COUNTRIES: Worldwide 
INDUSTRIES: Any, DIB 
REPORT DATE: 20170221

Tuesday, November 1, 2016

Indetectables RAT Receives Help from Several White Hat Hackers


In late September 2016, a Spanish speaking hacker released an updated version of a popular white hat developed Remote Access Tool (RAT) named “Indetectables RAT” on the Spanish language hacker forum Indetectables.net. This tool is posted to dozens of international hacker groups who have targeted US and international institutions and has a low anti-virus detection payload (13/56) for samples submitted to Virus Total. The hacker also received the advice of several well-known international white hat hackers whom he/she credits in the latest builder version (v.0.9.2).

Publication date:                        24 October 2016
Handling requirements:            Traffic light protocol (TLP) AMBER
Attribution/Threat Actors:       Indectables hacker
Actor Type:                                 Adversary capabilities have been assessed as Tier III*

Potential Targets:                       US/International institutions

Past Reporting:                           N/A

Indicators:                                   https://www.threatrecon.co/search?keyword= Indetectables_RAT

*Practitioners who focus on the discovery and use of unknown malicious code, are adept at installing user and kernel mode root kits10, frequently use data mining tools, target corporate executives and key users (government and industry) for the purpose of stealing personal and corporate data with the expressed purpose of selling the information to other criminal elements. 

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs


Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.

Tuesday, October 25, 2016

Argentinian Programmer Providing RATs, DDoS & Defacer Keyloggers


Spanish language forum research by Wapack Labs has uncovered an Argentinian programmer who provides numerous malicious tools in many forums.  These tools include numerous forms of Remote Access Tools (RATs), Distributed Denial of Service (DDoS), and defacer keyloggers which can be used in numerous ways - for illegitimate purposes.  This actor appears to be a skilled programmer possibly living in Argentina, as is indicated in the actor's related blog profile.  Its unsure what the motives are since the malicious tools are offered for free.  Actor has been providing malicious tools for the past five years.  This information is being supplied for your situational awareness. 

Publication date:                            20 October 2016

Handling requirements:                  Traffic light protocol (TLP) GREEN

Attribution/Threat Actor:               Argentina

Actor Type:                                    Adversary capabilities have been assessed as Tier II*

Potential Targets:                           Worldwide – Spanish/Hispanic consumers

Past Reporting:                               Red Sky Alliance: DOC-4323

* Practitioners with a greater depth of experience, with the ability to develop their own tools (from publicly known vulnerabilities).

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world. 

Thursday, October 13, 2016

South American Based Indetectables Member Shares RAT

Current Wapack Labs research revealed a Spanish language forum, Indetectables.net Forum, which highlights a member selling a popular remote access tool (RAT).  This information is being supplied for your situational awareness and protection. 







Publication date:                    26 September 2016

Handling requirements:          Traffic light protocol (TLP) AMBER

Attribution/Threat Actors:      Indetectables member

Actor Type:                             Adversary capabilities have been assessed as Tier III*


Potential Targets:                   USA / Brazil / South America

Past Reporting:                       Red Sky Alliance: DOC-2236, DOC-3379, DOC-3699

*Practitioners who focus on the discovery and use of unknown malicious code, are adept at installing user and kernel mode root kits10, frequently use data mining tools, target corporate executives and key users (government and industry) for the purpose of stealing personal and corporate data with the expressed purpose of selling the information to other criminal elements. 

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.