
Wapack Labs has cataloged and reported on attacks targeting banks and SWIFT in the past.
An archive of related reporting can be found in the Red Sky Alliance
portal.

TLP AMBER ANNOUNCEMENT:



In a 22 June 2017 report, twenty (20) ships near the Russian Black Sea coast indicated their GPS location to be inland at Gelendzhyk Airport. Similar GPS position malfunctioning was noticed in automobiles driving near the Kremlin in Moscow, Russia. These GPS anomalies indicate the likelihood that Russia is testing security measures by utilizing GPS spoofing to test their capability in the event of a military conflict; both on land and at sea...READ MORE
TLP AMBER ANNOUNCEMENT:
Creators of the NotPetya (also known as Petya, PetrWrap, Petya.A, Win32/Diskcoder.Petya.C, EternalPetya, Nyetya, and exPetr) continue to present NotPetya as “simple ransomware.” The developers have moved received bitcoins, sent payments to Pastebin and DeepPaste associated wallets, contacted the public, and apparently were able to decrypt one short NotPetya encrypted file. At the same time, NotPetya creators did not use the original Petya ransomware source code, and likely left no remedy for most users to recover their encrypted data, despite showing them the ransom note. These observations, together with targeting and comparative TTP data for XData and BlackEnergy3 Killdisk, allow Wapack analysts to attribute NotPetya as likely belonging to Russian APT. The Petya/NotPetya operation is likely another Russian APT targeted disruption of Ukrainian IT infrastructure and possibly an intelligence operation - yet masked as a ransomware case. At the same time, it is probable that Petya and NotPetya actors may have a master key to decrypt user files; in case the targeted disk was not destroyed and system information is available...READ MORE
Russian president, Vladimir Putin, recently met with Ethereum Cryptocurrency founder, Vitalik Buterin. Russia, in the past, has effectively banned Bitcoin use by its companies and is now likely switching to "use and control" emerging Blockchain technologies. Bitcoin is the original blockchain-based cryptocurrency and has become very popular in black markets, including online drug sales and cybercrime. Ether (token for Ethereum), is one of the alternatives growing fast in general popularity. Besides the currency function, Ethereum provides much more functionality: it is an open-source, public, blockchain-based distributed computing platform that features smart contact (scripting) functionality, which facilitates online contractual agreements. This makes Ethereum technologies of interest for major financial institutions and IT companies. Blockchain technologies are not bad per se, and many Western financial institutions are attracted to its use, but Russia's history of protecting black-hat hackers and controlling some online black markets make this development worrisome...READ MORE
Wapack Labs Analysts are researching a Tor-based darknet marketplace that sells stolen financial items; credit cards, gift cards, and occasionally provides free dumps that exposed Personally Identifiable Information (PII) of individuals. New accounts are available every week and the marketplace's administrators claim they are 100% verified - how-to manuals are provided with transactions. The marketplace is operating on a global basis, their stolen products are from the US, EU, Oceania, and Russia. Further research is being conducted to identity the source of the stolen credit cards...READ MORE
Yevgeniy Nikulin is a potent Russian hacker responsible for major breaches including Linkedin, Dropbox and Formspring, as well as less known funds theft from a Bitcoin hedge fund and from individuals. After his arrest in Prague, Russia filed its own extradition request to fight the one from the US. There are unconfirmed allegations that Nikulin may have some insights on the 2016 Presidential Elections related hacking. Nikulin is a high-skilled dangerous hacker. While the true nature of his connections to the Russian government is unproven, it is possible that it prompted the legal help that he is getting...READ MORE
Wapack Labs is tracking a reported ransomware attack on various countries affecting operations in the health and financial sectors. The malware has been titled: WCry, WannaCry or WanaCrypt0r ransomware. Open source reporting indicates that Russia, Ukraine, Taiwan, Spain, and the United Kingdom are being targeted. CCN-CERT (SP) has confirmed the malware propagates through the leaked Equation Group ETERNALBLUE SMB exploit. Microsoft Security Bulletin MS17-010 details mitigations for this exploit.
Wapack Labs is researching an established Russian hacker who provides DDoS services for hire. The hacker offers a wide variety of DDoS attacks which can be accomplished on any specified port - guarantees 100% anonymity and a 100% refund for a failed DDoS attack. The cost for services vary. Payments may be made in Webmoney, Qiwi, and Bitcoin. All communication is over ICQ, Jabber, or Telegram.
Russian media source, RBC, is claiming English-speaking pro-Trump groups, Facebook Secured Borders, and Twitter Tea Party News are operated by a Russian “Troll Factory.” Russian businessman, Yevgeniy Prigozhin, is known for financing a Russian troll factory which employs Internet “trolls” who post and comment for the purpose of swaying public opinion both domestically and internationally. Prigozhin has been implicated in many other public and questionable business ventures. Currently, positive Russian ownership of these pro-Trump focused troll factories remains uncertain.
Cryptocheck (Cc) is a dubious Russian based payment system discovered in recent collections. Cc heralds a safe and anonymous way to transfer money online. Cc combines electronic vouchers, traditional payment systems and cryptocurrency. This payment service is used in many Russian speaking forums; however, Cc has also been found in a number of English speaking forums. Cc promoted their service as a combination of all the best cyber payment systems that exist using cryptocurrency. Personal user data is not requested or used in Cc. Cc provides payments with unique check and code numbers. The check number can have 58^6 combinations and the code number consists of 58^9 possible combinations, offering anonymity.
Carding forum AlphaBay’s (AB) rules, posted on Twitter, have sparked debate in the underground that the forum is controlled by malicious actors in Russia. Rumors of AB being linked to Russian organized crime are not new, but rules prohibiting malware that targets Russian citizens or the sale of financial information on Russian citizens lends credence to such claims. Russian carding forums routinely include rules of this type to avoid drawing the attention of Russian authorities. AB’s adoption of such rules can only help them in their efforts to become the dominant underground marketplace for illicit goods and activities online.
The Autonomous Noncommercial Organization Professional Association of Designers of Data Processing Systems (ANO PO KSI) was sanctioned by the U.S. in response to Russian interference in the 2016 U.S. Presidential election. The company works with the Russian Defense Ministry, FSB, and other government organizations. They produce election ballot and census form scanners, and aero-surveillance cameras...READ MORE