Showing posts with label Trojan. Show all posts
Showing posts with label Trojan. Show all posts

Thursday, December 21, 2017

Terdot Banking Trojan

TLP AMBER ANNOUNCEMENT:

Terdot is a multipurpose banking trojan developed using Zeus source code leaked in 2011. The latest version of Terdot surfaced in 2016 and incorporates new surveillance capabilities. Now that the Terdot trojan features cyber espionage capabilities it is more likely to be sought after by attackers. Like its predecessor Zeus, some of Terdot's features and configurations indicate a high likelihood of Russian origins. This report examines Terdot’s new capabilities, infrastructure, attribution and delivery mechanisms...READ MORE

Wapack Labs has cataloged and reported on banking trojans in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

This TLP AMBER report is available only to Red Sky Alliance members.

Tuesday, October 24, 2017

New Emotet Tactics Employing Embedded URL Links

Emotet is a credential stealing trojan with the ability to drop payloads and move laterally through networks. Emotet spreads by E-mail to addresses gained from the address books of previous victims. In October of 2017, Wapack Labs observed a new Emotet campaign targeting multiple industries. This recent campaign is characterized by changes in Tactics, Techniques, and Procedures (TTPs). These changes include the use of embedded URLs (or links) instead of attachments, and newly adopted obfuscation techniques. Emotet’s ability to spread to compromised email contacts aids in the increase of infections. E-mails propagated in this manner likely have a higher infection rate as they originate from a known contact. This report looks at the new TTPs observed including changes in delivery, obfuscation, and the Visual Basic embedded macros...READ MORE

Wapack Labs has cataloged and reported on Emotet malware and campaigns in the past. An archive of related reporting can be found in the Red Sky Alliance portal. 

Tuesday, January 17, 2017

Japan Spear Phished by Trojan: BKDR_ChChes

In November 2016, a string of spear phishing attacks targeted Japanese governmental agencies. The Trojan in this attack was dubbed BKDR_ChChes by the anti-virus vendor Trend Miro. Tactics, Techniques, and Procedures (TTP’s) show this was a targeted campaign using custom malware attributed to a known hacking group. Whether the Trojan was developed from the hacking group source code leak in 2015, or if it was designed by the hacking group on behalf of the attackers, is an intelligence gap.


Publication Date: January 10, 2016
Handling Requirements: Traffic light protocol (TLP) AMBER
Attribution/Threat Actors: known hacking group, unknown Chinese threat actors
Actor Type: Adversary capabilities have been assessed as TIER III
Potential Targets: Japanese Government, Worldwide Governments / Worldwide Businesses
Previous Reporting: Red Sky Alliance: DOC-2343

The full report may be viewed in the Red Sky Alliance as DOC-4606. 
Contact Wapack Labs for more information.

Tuesday, January 3, 2017

Australian Malware Authors Release New Trojan


Wapack Labs assesses, with medium confidence, that Australian malware authors (medium confidence) have released a new banking Trojan.  This Trojan performs real time web-injections and redirection attacks on its victims.  It currently enjoys low and generic detection by intrusion prevention systems.  Analysts at IBM report to have followed the Trojan during its testing cycles3.  It now has moved out of the testing phase and is actively defrauding banks and consumers.  If it becomes as virulent (as did its' predecessors), it will likely spread to the US by the second quarter of 2017...READ MORE

Publication Date: 23 December 2016
Handling Requirements: Traffic light protocol (TLP) AMBER.
Attribution/Threat Actors: Australian Malware Authors
Actor Type: Adversary capabilities have been assessed as TIER III.
Industries Targeted: Financial
Past Reporting: Red Sky Alliance: DOC-2301, DOC-2522, DOC-3456, Message #7963

The full report may be viewed in the Red Sky Alliance as DOC-4566.  
Contact Wapack Labs for more information.