Showing posts with label Russia. Show all posts
Showing posts with label Russia. Show all posts

Friday, December 22, 2017

Hackers Compromised Russian Bank And Used SWIFT for Withdrawal

On 15 December 2017, a Russian bank lost somewhere between $100,000 and $1 million US dollars after hackers sent SWIFT wire transfers abroad to Europe, Asia, and America. The bank was compromised (medium confidence) by a hacker group who sent malicious attachments to a number of different banks a few weeks prior. SWIFT was not compromised, but was used as a tool to siphon money from the compromised bank. The bank is going through ownership reorganization. Prior to this incident, it was receiving financial regulator warnings regarding its cyber security posture...READ MORE

Wapack Labs has cataloged and reported on attacks targeting banks and SWIFT in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Thursday, December 21, 2017

Terdot Banking Trojan

TLP AMBER ANNOUNCEMENT:

Terdot is a multipurpose banking trojan developed using Zeus source code leaked in 2011. The latest version of Terdot surfaced in 2016 and incorporates new surveillance capabilities. Now that the Terdot trojan features cyber espionage capabilities it is more likely to be sought after by attackers. Like its predecessor Zeus, some of Terdot's features and configurations indicate a high likelihood of Russian origins. This report examines Terdot’s new capabilities, infrastructure, attribution and delivery mechanisms...READ MORE

Wapack Labs has cataloged and reported on banking trojans in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

This TLP AMBER report is available only to Red Sky Alliance members.

Dead Russian Social Media Accounts Hacked

Social media accounts originally belonging to the deceased were recently observed promoting pro-Putin messages in Russia. The Russian social network, VK (formerly Vkontakte), reported that accounts were hacked. Social media accounts whose owners are no longer living and other abandoned accounts with weak password security were used in this campaign. Because they were deceased or abandoned accounts, account owners could not react to possible security warnings. Social media networks have different processes for deactivating deceased users. Abandoned accounts may be especially vulnerable to brute force attacks and may later be used in malware or disinformation campaigns. This use of hacked accounts poses a risk of international-level account hijacking on a variety of social media networks...READ MORE

Wapack Labs has cataloged and reported on social media hijacking in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Friday, December 8, 2017

Russian Troll Handlers

TLP AMBER ANNOUNCEMENT:
 
Fake social media accounts controlled by a Russian APT group were focusing on spreading leaks aligned with the Russian agenda. At the same time, another group not only supported candidate Trump, but also spread divisive content from all political affiliations and even organized anti-Trump events in the US. Russian troll operations continued through 2017. It is likely that the group continues its operations in the US and that the associated accounts are dedicated to information warfare. Their cover identities, however, are being changed and the operations are being scaled down compared to the 2016 US presidential campaign...READ MORE 

Wapack Labs has cataloged and reported on Russian social media trolling in the past. An archive of related reporting can be found in the Red Sky Alliance portal. 

WWW.WAPACKLABS.COM 

This TLP AMBER report is available only to Red Sky Alliance members.

Tuesday, November 21, 2017

New Carding Shop with Extensive History

TLP AMBER ANNOUNCEMENT:     

Wapack Labs recently observed a new carding forum. The forum was registered by a Russian proxy registrant and is hosted on a Russian IP address. It was later transferred to several Russian hosts before ending on a Cloudflare IP. The forum began operation on 11 January 2017 and, since, has offered a high volume of credit cards for sale. It is likely the current credit card inventory is a continuation and re-branding of other illegal forums or possesses a large hacking team, as its history is greater than that of the website registration. The owner of the forum has been operating since 23 September 2016 on another forum. Wapack Labs believes this actor likely began this extensive illegal credit card sales history as a verified vendor on another forum previous to the current forum...READ MORE

Wapack Labs has cataloged and reported on carding forums in the past. An archive of related reporting can be found in the Red Sky Alliance portal. 


This TLP AMBER report is available only to Red Sky Alliance members. 


Friday, November 3, 2017

Russian ISP Doing Business with North Korea

On 01 Oct 2017, TransTeleCom, a Russian owned telecommunications company began routing North Korean Internet. TransTeleCom owns one of the largest fiber optic cable based networks in the world. It is a fully owned subsidiary of Russian Railways, a joint-stock company with 100 percent involvement under the Russian Ministry of Transport. North Korea’s external Internet connections were historically serviced by China Unicom, but will now be provided by both China Unicom and Russia’s TransTeleCom. IPv4 traffic route allocation is 60 percent through TransTeleCom and 40 percent through China Unicom. Unicom will continue providing 100 percent IPv6 routing for North Korea. The contract between TransTeleCom and North Korea was originally signed in 2009. The recent Russian telecommunications escalation seems to be in support of North Korea after U.S. Cyber Command Distributed-Denial-of-Service (DDoS) attacks. Having routes in both China and Russia limits North Korea’s dependence on any one country as they are currently facing intense geopolitical pressures. North Korea’s shift from being predominantly Chinese hosted, to Russian support, is primarily due to U.S. political pressure on China to sever ties with North Korea over the recent nuclear missile tests and China’s failure to protect North Korea from the recent U.S. DDoS attacks. TransTeleCom operates similarly to China Unicom, the current North Korean Internet Service Provider (ISP), which has fiber optics laid along China’s Sino-Korean Friendship Bridge. However, TransTelecom is believed to be delivering North Korea’s Internet over the Korea-Russia Friendship Bridge, the only crossable border between North Korea and Russia. Wapack Labs will continue to monitor malicious cyber activities out of North Korean netblocks....READ MORE

Wapack Labs has cataloged and reported on North Korean cyber activity in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Monday, September 18, 2017

Carding Forum Observation

On 15 September 2017, Wapack Labs observed a carding forum advertising services on numerous other carding forums. In addition to selling stolen credit cards (CCs), the forum's database contains thousands of CCs on a global scale. Meta-data and screenshots from several online videos point to the threat actor being from Russia. Wapack Labs will continue to monitor the forum in order to identify the Tactics, Techniques, and Procedures (TTPs) and the persona operating the carding forum.

Wapack Labs has cataloged and reported extensively on Russia and carding forums in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Friday, August 18, 2017

Russia May Have Tried Maritime GPS Spoofing

In a 22 June 2017 report, twenty (20) ships near the Russian Black Sea coast indicated their GPS location to be inland at Gelendzhyk Airport. Similar GPS position malfunctioning was noticed in automobiles driving near the Kremlin in Moscow, Russia. These GPS anomalies indicate the likelihood that Russia is testing security measures by utilizing GPS spoofing to test their capability in the event of a military conflict; both on land and at sea...READ MORE

Wapack Labs has cataloged and reported extensively on Russia and GPS spoofing in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Monday, August 14, 2017

DiamondFox in the Wild

TLP AMBER ANNOUNCEMENT: 

DiamondFox is a credential stealing multi purpose botnet that is available on the black market as MaaS (Malware as a Service). Also known as Gorynych, DiamondFox is still actively leveraged in the wild with its recent version Crystal available in online marketplaces. This dangerous malware can steal information from PoS (Point of Sale) systems with campaigns targeting multi-state healthcare providers, dental clinics, manufacturers, and technology companies. To get a picture of the current state of DiamondFox botnets, Wapack Labs has collected recent samples and extracted the command and control (C2) information from their configuration files. This report provides technical details on DiamondFox, the Russian botnet infrastructure, and details regarding the domains...READ MORE

Wapack Labs has cataloged and reported extensively on malware and botnets in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

This TLP AMBER report is available only to Red Sky Alliance members.

Friday, August 11, 2017

Shadowbrokers and the Scylla Hacking Store

The ShadowBrokers (SB) have recently started a new Tor based market called Scylla Hacking Store. SB is selling several APT stolen exploits (US, Russian and Chinese exploits), crimewave exploit kits, and other crimewave hacking tools: bots, hash cracking, and Microsoft Office exploits. Analysts believe, with medium confidence, the recent Petya activity may be related to SB sales of all the payload source code for the FuzzBunch framework, which included, EternalBlue...READ MORE

Wapack Labs has cataloged and reported extensively on the ShadowBrokers in the past. An archive of related reporting can be found in the Red Sky Alliance portal.


Tuesday, July 18, 2017

NotPetya: Ransomware Or Russian Wiper?

Creators of the NotPetya (also known as Petya, PetrWrap, Petya.A, Win32/Diskcoder.Petya.C, EternalPetya, Nyetya, and exPetr) continue to present NotPetya as “simple ransomware.” The developers have moved received bitcoins, sent payments to Pastebin and DeepPaste associated wallets, contacted the public, and apparently were able to decrypt one short NotPetya encrypted file. At the same time, NotPetya creators did not use the original Petya ransomware source code, and likely left no remedy for most users to recover their encrypted data, despite showing them the ransom note. These observations, together with targeting and comparative TTP data for XData and BlackEnergy3 Killdisk, allow Wapack analysts to attribute NotPetya as likely belonging to Russian APT. The Petya/NotPetya operation is likely another Russian APT targeted disruption of Ukrainian IT infrastructure and possibly an intelligence operation - yet masked as a ransomware case. At the same time, it is probable that Petya and NotPetya actors may have a master key to decrypt user files; in case the targeted disk was not destroyed and system information is available...READ MORE

Wapack Labs has cataloged and reported extensively on Petya/NotPetya, ransomware, BlackEnergy, Russian APT, wiper malware, and Ukrainian attacks in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Wednesday, June 7, 2017

Russia is Considering Ethereum's Blockchain Technology

Russian president, Vladimir Putin, recently met with Ethereum Cryptocurrency founder, Vitalik Buterin. Russia, in the past, has effectively banned Bitcoin use by its companies and is now likely switching to "use and control" emerging Blockchain technologies. Bitcoin is the original blockchain-based cryptocurrency and has become very popular in black markets, including online drug sales and cybercrime. Ether (token for Ethereum), is one of the alternatives growing fast in general popularity. Besides the currency function, Ethereum provides much more functionality: it is an open-source, public, blockchain-based distributed computing platform that features smart contact (scripting) functionality, which facilitates online contractual agreements. This makes Ethereum technologies of interest for major financial institutions and IT companies. Blockchain technologies are not bad per se, and many Western financial institutions are attracted to its use, but Russia's history of protecting black-hat hackers and controlling some online black markets make this development worrisome...READ MORE

Wapack Labs has cataloged and reported extensively on Russia, blockchains, and cryptocurrency in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Tuesday, June 6, 2017

Darknet Marketplace Exposes Financial Items on Global Scale

Wapack Labs Analysts are researching a Tor-based darknet marketplace that sells stolen financial items; credit cards, gift cards, and occasionally provides free dumps that exposed Personally Identifiable Information (PII) of individuals. New accounts are available every week and the marketplace's administrators claim they are 100% verified - how-to manuals are provided with transactions. The marketplace is operating on a global basis, their stolen products are from the US, EU, Oceania, and Russia. Further research is being conducted to identity the source of the stolen credit cards...READ MORE

Wapack Labs has cataloged and reported extensively on darknet marketplaces in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Thursday, May 25, 2017

The LinkedIn, Dropbox, and Formspring Hacker: Yevgeniy Nikulin

Yevgeniy Nikulin is a potent Russian hacker responsible for major breaches including Linkedin, Dropbox and Formspring, as well as less known funds theft from a Bitcoin hedge fund and from individuals. After his arrest in Prague, Russia filed its own extradition request to fight the one from the US. There are unconfirmed allegations that Nikulin may have some insights on the 2016 Presidential Elections related hacking. Nikulin is a high-skilled dangerous hacker. While the true nature of his connections to the Russian government is unproven, it is possible that it prompted the legal help that he is getting...READ MORE

Wapack Labs has cataloged and reported extensively on hackers in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Friday, May 12, 2017

Equation Group's Exploit is Operating Globally: #WannaCry Ransomware

Wapack Labs is tracking a reported ransomware attack on various countries affecting operations in the health and financial sectors. The malware has been titled: WCry, WannaCry or WanaCrypt0r ransomware. Open source reporting indicates that Russia, Ukraine, Taiwan, Spain, and the United Kingdom are being targeted. CCN-CERT (SP) has confirmed the malware propagates through the leaked Equation Group ETERNALBLUE SMB exploit. Microsoft Security Bulletin MS17-010 details mitigations for this exploit.

Wapack Labs has cataloged and reported extensively on ransomware in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Monday, April 10, 2017

Russian Hacker: DDoS Services for Hire

Wapack Labs is researching an established Russian hacker who provides DDoS services for hire. The hacker offers a wide variety of DDoS attacks which can be accomplished on any specified port - guarantees 100% anonymity and a 100% refund for a failed DDoS attack. The cost for services vary. Payments may be made in Webmoney, Qiwi, and Bitcoin. All communication is over ICQ, Jabber, or Telegram.

Wapack Labs has cataloged and reported extensively on DDoS hackers in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Tuesday, March 28, 2017

Russian Troll Factory Open for Business

Russian media source, RBC, is claiming English-speaking pro-Trump groups, Facebook Secured Borders, and Twitter Tea Party News are operated by a Russian “Troll Factory.” Russian businessman, Yevgeniy Prigozhin, is known for financing a Russian troll factory which employs Internet “trolls” who post and comment for the purpose of swaying public opinion both domestically and internationally. Prigozhin has been implicated in many other public and questionable business ventures. Currently, positive Russian ownership of these pro-Trump focused troll factories remains uncertain.

Wapack Labs has reported extensively on public sentiment in the past. An archive of related reporting can be found in the Red Sky Alliance Portal.

Monday, March 27, 2017

Transfer Money Anonymously with Russian Cryptocheck

Cryptocheck (Cc) is a dubious Russian based payment system discovered in recent collections. Cc heralds a safe and anonymous way to transfer money online. Cc combines electronic vouchers, traditional payment systems and cryptocurrency. This payment service is used in many Russian speaking forums; however, Cc has also been found in a number of English speaking forums. Cc promoted their service as a combination of all the best cyber payment systems that exist using cryptocurrency. Personal user data is not requested or used in Cc. Cc provides payments with unique check and code numbers. The check number can have 58^6 combinations and the code number consists of 58^9 possible combinations, offering anonymity.

Wapack Labs has cataloged and reported extensively on payment services in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Tuesday, March 14, 2017

AlphaBay: Avenue on the “new” Silk Road?

Carding forum AlphaBay’s (AB) rules, posted on Twitter, have sparked debate in the underground that the forum is controlled by malicious actors in Russia. Rumors of AB being linked to Russian organized crime are not new, but rules prohibiting malware that targets Russian citizens or the sale of financial information on Russian citizens lends credence to such claims. Russian carding forums routinely include rules of this type to avoid drawing the attention of Russian authorities. AB’s adoption of such rules can only help them in their efforts to become the dominant underground marketplace for illicit goods and activities online. 

Wapack Labs has cataloged and extensively reported on Russian cyber activity in the past. An archive of related reporting can be found in the Red Sky Alliance Portal.

WWW.WAPACKLABS.COM

Tuesday, March 7, 2017

Sanctioned ANO PO KSI: Surveillance and Ballot Reading


The Autonomous Noncommercial Organization Professional Association of Designers of Data Processing Systems (ANO PO KSI) was sanctioned by the U.S. in response to Russian interference in the 2016 U.S. Presidential election. The company works with the Russian Defense Ministry, FSB, and other government organizations. They produce election ballot and census form scanners, and aero-surveillance cameras...READ MORE

Wapack Labs has extensively reported on election interference in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

TLP: GREEN
ACTOR TYPE: (V)
SERIAL: TAR-17
COUNTRIES: RU, U.S.
INDUSTRIES: Military, Political
REPORT DATE: 20170306