Showing posts with label cyber intelligence. Show all posts
Showing posts with label cyber intelligence. Show all posts

Tuesday, May 7, 2019

Remote Desktop Protocol (RDP) a Deep Dive Webinar


Save the Date: Friday Noon EST, May 10th 
Click Here to Register

Wapack Labs is excited to invite you to our 2nd Cyber Intelligence on-line Briefings (CIB). This webinar is a deep dive into Remote Desktop Protocol (RDP). Jesse Burke, Advanced Cyber Analyst, will share research on RDP Wrap, Backdoors, Inception, and MiTM. Join our webinar on Friday noon for the webinar and the reports.

Thursday, September 13, 2018

CHANNEL 001:CYBER BRIEF: The Missing Link in the Supply Chain Webinar

Introducing a NEW Wapack Labs Monthly Cyber Brief Webinar Series - called 'Channel 001'. We will host a webinar every month on prevailing cyber topics. These webinars are open to everyone and are free to attend. First up, we have a Supply Chain webinar - 'The Missing Link in the Supply Chain'.

September 19th, 10:00 AM EDT REGISTER NOW


In recent years, the global supply chain has become the new "playground for hackers". With chain inherently having numerous links (from suppliers to manufacturers to distributors), the number of potentially exploitable relationships makes it an attractive target. This presentation includes the 'how' and the 'why' of supply chain attacks and describes several notable malware campaigns affecting supply chain in multiple industries.

Viewers will:
• Understand the basic nature of cyber supply chains
• Gain insight into cyber supply chain vulnerabilities
• Learn how to begin protecting our cyber supply chains 


Your presenter Chris Hall, Co-Owner and Principal Engineer at Wapack Labs, has been in the intelligence community for over 18 years in various capacities including SIGINT, network defense, reverse-engineering, and fusion. In 2012, Chris moved from the government to the private sector to help form the Red Sky alliance and then co-found Wapack Labs in 2013. As a partner at Wapack Labs, Chris's main responsibility is to oversee the production, sourcing, and collection of intelligence.

Please join us for this webinar and many more to come. September 19th, 10:00 AM EDT.

REGISTER NOW


Contact Wapack Labs for more information:
603-606-1246, or info@wapacklabs.com 


WWW.WAPACKLABS.COM 

Friday, March 23, 2018

China Government Hacker Resurgent

In 2015, China and the United States pledged a bilateral Cyber Agreement that they would refrain from conducting cyber operations to steal intellectual property from one another. In 2016, a major drop in such intrusions was noted. By 2017, however, several new cases of cyber intrusion against defense contractors and other commercial entities were identified, which raises the question of whether the Chinese have in fact been constrained by the 2015 agreement. Wapack Labs reviewed the major cyber operations cases of 2017, that appeared to have Chinese origins, to assess the current trends in government-sponsored operations and answer the question: is China currently abiding by this agreement? Has being a signatory to the agreement constrained Chinese government behavior in any meaningful way?...READ MORE

Wapack Labs has cataloged and reported on Chinese state-sponsored cyber operations in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
  
WWW.WAPACKLABS.COM

Saturday, October 1, 2016

Cyberwatch update

To all who've been using Cyberwatch(R) and provided feedback, thank you!  It's very much appreciated. As a result of some of these feedback,  Cyberwatch API version 1.1 was released last night, and its packed with improvements that you've requested:
  1. 25-35% faster with database clustering improvements
  2. For our automated alerting mechanism, we've built in dynamic notification API keys, which don’t require authenticating! Click through, see everything we know from that 
  3. API key removal from the url on the front end wrapper
  4. Security Updates & bug improvements 
To all who've not yet heard of Cyberwatch, last week we went public with a new application program interface (API), that allows users to run queries against our backend raw intelligence collections.  We knew two things... 

First, many (all?) companies need intelligence --not just information received when they buy that million dollar security tool, but a real understanding of what's going on outside of their border router that will likely affect them. 

Second, many of those companies would prefer to slog through the myriad of google groups, open source lists, and take on the dark web themselves and waste an enormous amount of time chasing things that just don't mean much to the questions they should be asking themselves. 

For example... a RISK focused security pro will always want to know if there's a RISK of something breaching. And if they do, what's the likelihood of loss?

An INTELLIGENCE focused security pro will want to look over the horizon for risks that'll might mean something soon, or they'll want to know that tactical information --what IP blocks should we be monitoring now? Blocking now? Remediating?

At the same time,  our customer base is largely 100,000 computers or bigger... which while good for us, represents a small number of companies who need help... and who may be partnered with or in the supply chain to these larger companies. 

I've talked with dozens of smaller companies. They simply can not, and like will never, spend the money on an intelligence shop.

So what if Wapack Labs could help them? What if we could allow users to query our backend data for say, 30 queries per day (for free), so that these smaller companies could see exactly what they're exposure looks like --and what if Wapack Labs could refer them to a security professional (under NDA of course) to help that smaller company get well? 

Well, that's exactly what we did.
  • Wapack Labs passively collects key logger 'dump' locations at about 1300 locations around the world; 
  • We collect on very specific sinkholes;
  • We collect some specific open source --but not all... we don't want circular reporting;
  • And we collect about a dozen other specific items that can help tell a company when they might have problems. 
And we make that all searchable to anyone who wants to search against it. 

As well, we started (this week) performing automated victim notifications. Our first batch, roughly 5000 of them, went out on Wednesday, with a no-cost, one time link to our databases to show the companies what we found, and why we think they may have been victimized. That email contains a link to our new Partner Exchange Program, and allows the victim to request a referral to one of our trusted, NDA'd,  partners who can assist in the cleanup if needed. 

The Cyberwatch API is available at api.wapacklabs.com.

Need more? We've built an ugly demo front end (we'll make it look nicer soon, I promise) on the API... cyberwatch.wapacklabs.com. Use it to monitor a portfolio of companies. If you're watching your supply chain, or a group of investment companies, you can set up five companies in our Cyberwatch front end, or you can use the API to bring the data into your own environment. Either way... you should be able to pull our data into a usable front end of your choosing or use ours.

So, to those who've provided feedback? We're listening.
To those who've not yet tried it? Try it! 

We're heading into Christmas shopping season. And although much of the work we'd done in the past is APT and Espionage related, we've taken on a second flavor in our analysis --money. So if you're a retailer, financial institution, or a supplier to one of these, as we head into the Christmas shopping season you should be watching our API at least daily, knocking down the threats we identify. 

Give it a try. There's absolutely no reason you shouldn't... it's free and we might know something about you that you don't already know.

Until next time,
Have a great weekend!
Jeff

(CyberWatch(R) is a registered Trademark of Wapack Labs Corporation.)


Monday, September 12, 2016

Wapack Labs Announces Cyberwatch® API for Proactive Cyber Threat Intelligence.

Orlando, FL, September 12, 2016:  Wapack Labs, a cyber threat intelligence company, announced their new Cyberwatch® Application Program Interface (API) today at the Information Security Certification Consortium (ISC2) Congress in Orlando, FL. Companies will now be able to search Wapack Labs’ cyber intelligence collections directly through this bold, new application. That means users can identify and address security threats faster—including before they’re realized.


Wapack Labs recovers information stolen by hackers from keylogger information, sinkholes, the dark web, malicious emails, and more. “With Cyberwatch® API, we’re opening our collections to those not normally privy to high-end cyber threat intelligence,” says Jeff Stutzman, CEO of Wapack Labs. Everything from usernames and passwords to financial transactions and credit card information can indicate previously unknown network breaches. Users can simply enter a company domain into Wapack Labs Cyberwatch® API (api.wapacklabs.com) and find out if it has been compromised. 



What makes Wapack Labs Cyberwatch® API of even greater value, however, is that it enables companies to be proactive. “Because of the sheer volume of our backend collections—which also includes data derived from malicious actors’ activities, and not just the information they steal—results from your search can help you identify if you’re being targeted.” Stutzman explains.  This is revolutionary for an industry where, today, offerings are almost always post-hoc; that is, they are built after a company has already been broken into. Antivirus, sharing intrusion prevention rules, and indicators of compromise all rely on expert analysis after someone has been hacked, and damage is already done. For another company to successfully capitalize on these types of security offerings, they must obtain and incorporate this information into their security tools before the threat evolves.



The Cyberwatch® API enables companies to connect their security tools directly to Wapack Labs’ intelligence backend, giving them direct access to clean, parsed data without requiring additional analysis, thereby prioritizing work for CISOs and their cyber security operations center (SOC) teams. 



These are not credential dumps or aggregated data,” says Stutzman. “This is information stolen by nefarious actors or malware from roughly 15,000 companies and organizations all over the world. If a company or individual finds themselves in a query of our data, if they haven’t been hacked yet, they may be soon, and can get a head-start on precautions.” 



Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC, and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber. Wapack Labs’ engineers, researchers, and analysts design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information, using deep analysis techniques and visualization. Information derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.



For questions or comments regarding this report, please contact the lab directly by at 603-606-1246, or Chuck Nettleship at cnettleship@wapacklabs.com.