Showing posts with label credit card. Show all posts
Showing posts with label credit card. Show all posts

Thursday, February 1, 2018

Hacker Shop Selling Exfiltrated Data

TLP AMBER ANNOUNCEMENT:

Wapack labs identified a hacker shop that sells batches of files exfiltrated from computers that belong to companies and corporations from various industries, such as a local law enforcement agency, financial institutions, mining companies, and logistic organizations. The shop's victims are located in several countries, though most are in the United States (US). It sells financial data sources, to include full credit card payment authorization forms. The shop has also exposed online banking check operations without obfuscation...READ MORE

Wapack Labs has cataloged and reported on hacker shops in the past. An archive of related reporting can be found in the Red Sky Alliance portal.  

 WWW.WAPACKLABS.COM

This TLP AMBER report is available only to Red Sky Alliance members.

Wednesday, December 6, 2017

Underground Market Selling Stolen Credit Cards

Wapack Labs recently identified a new private underground market. The market is targeting Amazon buyer gift cards and is also selling cloned credit and debit cards. The market only accepts Bitcoin as payment for these stolen goods and ships worldwide. It offers unique discreet shipping methods of cloned credit cards at different price points: $15 to mail the card in a birthday card, $25 to stuff the card inside a teddy bear, $50 to hide the card inside a calculator, and $100 to hide the card in non-working smartphone. They also offer a service that involves sending the product to abandoned houses or to a neighbor’s house. These physical delivery methods show diverse stolen credit card smuggling innovations. Each cloned card has a $4,000 - $7,000 balance with the correct PIN and a daily $500.00 cash withdrawal limit or $3,000.00 on line spending limit...READ MORE

Wapack Labs has cataloged and reported on underground markets and credit card theft in the past. An archive of related reporting can be found in the Red Sky Alliance portal. 

Monday, September 25, 2017

TOR "Skimmer Shop"


On 20 September 2017, Wapack Labs observed a Tor site selling a variety of credit card skimming devices. The owners of the Tor site claim to produce and modify all the products in their own workshops, which are purported to be located in the U.S. and Europe. The website states the business began in early 2015 and now consists of eleven (11) technically trained employees. The skimmer shop sells a variety of skimmers based on the shopper’s interests. The website presents various skimmer sections: ATM, gas pump, GSM (Global System for Mobile communication) receivers, POS, RFID, readers, and other skimmer accessories. Prices range from $800.00 USD to $1800.00 USD, depending on the skimmer wanted. Wapack Labs will continue to monitor this dark net skimmer shop in attempt to identify and monitor the threat actors and their activities...READ MORE

Wapack Labs has cataloged and reported extensively on Tor network shops in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Tuesday, February 21, 2017

New Carding Shop Owner

Wapack Labs reports that an underground forum member, who is a new carding shop owner/operator, has been selling debit and credit cards on hacker/carder forums - boasting a 90% validity rate. The actor created a thread for card dumps and has a large base of various credit cards for sale; some belonging to a Red Sky Alliance member. He is still actively posting credit card dumps and providing a link to a web shop where the cards can be purchased. Lately, he has been selling large amounts of cards from numerous banks in the United States...READ MORE

Wapack Labs has extensively reported on card dumping in the past. An archive of related reporting can be found in the Red Sky Alliance Portal. 

The following organizations were cited in this report: Red Sky Alliance member

TLP: AMBER
ACTOR TYPE: (III)
SERIAL: IA-003-2017
COUNTRIES: RU
INDUSTRIES: Financial
REPORT DATE: 20170217

Tuesday, February 7, 2017

Vast Quantities of Credit Cards Being Sold in the Underground

Wapack Labs has monitored an underground forum member, who provides a web page link, where he sells debit and credit cards. The actor created a thread for card dumps and has a large base of various credit cards for sale; some belonging to a Red Sky Alliance member. He is still actively posting credit card dumps and providing a link to a web shop where the cards can be purchased. Lately, he has been selling large amounts of cards from numerous banks in the United States.

Wapack Labs has extensively reported on card dumping in the past. An archive of related reporting can be found in the Red Sky Alliance Portal. 

The following organizations were cited in this report: Red Sky Alliance member

TLP: AMBER
ACTOR TYPE: (II)
SERIAL: TR-027-2017
COUNTRIES: US
INDUSTRIES: Financial
REPORT DATE: 20170203

Wednesday, November 16, 2016

Russian Hacker Monetizes Traffic

A Russian hacker has been operating in the Russian underground for over 10 years; carrying out activities that range from stealing and distributing credit card data to hacking pharmacy-related websites in order to monetize their traffic. Known actor was observed working with another Russian speaking hacker, which possibly connects actor to the gang that operated several botnets.

Thursday, September 29, 2016

Credit Card Fraud & EMV Security Chip

Mobile banking fraud in Europe has increased by a factor of 20; a trend that could follow in the U.S.  Credit card fraud has hit critical mass in the U.S., causing a push in technology in new mobile apps, which could create a virtual playground for criminals.  A recent surge in the volume of U.S. credit card fraud has forced industries to adopt the European EuroPay, MasterCard and Visa (EMV) card system.  The resistance to the EMV conversion will result in higher merchant costs and ATM manufacturer resistance, which has prompted a growth in mobile banking apps.

Publication date:                        26 September 2016

Handling requirements:              Traffic light protocol (TLP) GREEN

Attribution/Threat Actors:          Unknown at this time

Actor Type:                                 Adversary capabilities have been assessed as Tier III*

Potential Targets:                        USA

Past Reporting:                            Red Sky Alliance: DOC-3952, DOC-4265

*Practitioners who focus on the discovery and use of unknown malicious code, are adept at installing user and kernel mode root kits10, frequently use data mining tools, target corporate executives and key users (government and industry) for the purpose of stealing personal and corporate data with the expressed purpose of selling the information to other criminal elements. 

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.

Monday, September 19, 2016

'AFRICard' - Banking Consumer Fraud & Hacking

www.idt.com
Wapack Labs’ African subject matter expert (SME), presented research findings on African consumer fraud with the use of the popular ‘Africard,’ credit and debit cards.  The Nigerian owned United Bank of Africa (UBA) is being civilly sued in West Africa for allegedly using hacked consumer identifying information from a past cyber-attack on subsidiary,  International Bank of Burkina.  The use of the illegally obtained information “may” be centered around local networks of resellers, who are supported by financial services, to reach consumers, or with UBA banking agents.  It is alleged that this information is being used to prey on common inter-country African family transfer of West African Franc money via the ‘Africard’ credit/debit cards in Western European countries.  Many of these former French colonies could affect fraud in Western Europe and possible ties to the U.S. banking market.  Wapack Labs will continue to monitor.  This information is being supplied for your situational awareness. 

Publication date:                           16 September 2016

Handling requirements:                 Traffic light protocol (TLP) GREEN

Attribution/Threat Actors:             United Bank of Africa,  Bank of Burkina - Nigeria

Actor Type:                                    Tier II

Potential Targets:                           West Africa / Financial Services

Past Reporting:                               DOC-3116, DOC-3709

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.