Showing posts with label cyber security. Show all posts
Showing posts with label cyber security. Show all posts

Tuesday, May 7, 2019

Remote Desktop Protocol (RDP) a Deep Dive Webinar


Save the Date: Friday Noon EST, May 10th 
Click Here to Register

Wapack Labs is excited to invite you to our 2nd Cyber Intelligence on-line Briefings (CIB). This webinar is a deep dive into Remote Desktop Protocol (RDP). Jesse Burke, Advanced Cyber Analyst, will share research on RDP Wrap, Backdoors, Inception, and MiTM. Join our webinar on Friday noon for the webinar and the reports.

Tuesday, February 26, 2019

Chinese Cameras Get the Hook!

US officials allege Chinese technology manufacturers are producing equipment that allegedly permits China to spy on users. US universities are replacing telecom equipment made by Huawei and other Chinese companies to avoid losing federal funding under the NDAA.  

To read the full article and find an archive of related reporting, follow this link to READBOARD.

WWW.WAPACKLABS.COM

Tuesday, February 20, 2018

Huawei and ZTE Phones and Other Devices – Security Up for Sale

TLP AMBER ANNOUNCEMENT: 

Huawei, a long time Chinese telecommunications equipment competitor to the U.S. Cisco Systems, has earned a reputation for selling equipment that contains various cybersecurity, intellectual property, and quality control issues. Wapack Labs concurs with U.S. government agencies that Huawei and ZTE equipment are a cause for concern when considering supply chain equipment. Huawei and ZTE have higher than normal rates of cybersecurity issues due to a range of root causes. The United States, United Kingdom, Canada, Australia and South Korea began instituting measures to limit Huawei, and ZTE equipment from being used relative to government and military related communications as far back as 2003. The warnings were issued via reports to the U.S. Congress from the Intelligence Community, with ZTE officially banned for use by U.S. government agencies in 2013. They further started instituting that government contractors and vendors also comply with contracting restrictions against vendor and contractor utilization of Huawei and ZTE equipment for security reasons even before the national security issues were made openly public in 2011...READ MORE

Wapack Labs has cataloged and reported on Huawei and telecommunications in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM


This TLP AMBER report is available only to Red Sky Alliance members.

Friday, December 29, 2017

Implications of the EU General Data Protection Regulation

The European Union (EU) General Data Protection Regulation (GDPR) will go into force in May 2018. This is a comprehensive change to data protection regulations in the EU, but it will also require foreign companies that collect data on EU citizens to comply with its provisions. The GDPR establishes requirements in many areas that go beyond existing regulations or the security practices of U.S. companies. The greatest potential impact on U.S. companies and cybersecurity personnel is the schedule of penalties that can be imposed for data breaches or other failures to comply with the GDPR. Fines of up to $24 million or 4% of worldwide annual turnover for the year of the infraction can be levied against a company. This creates a possible opportunity for hackers that breach the data holdings of a major corporation. They can threaten to expose the breach, which would trigger huge fines unless the hackers are paid a substantial ransom to keep quiet...READ MORE
 
Wapack Labs has cataloged and reported on data protection regulations in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM 

Friday, December 8, 2017

China's Cyberspace Administration and Cyber Security Law

TLP AMBER ANNOUNCEMENT:
 
The Cyberspace Administration of China (CAC) was formed in 2014 as the principal Chinese government entity responsible for Chinese Internet content control. The current CAC Director, Xu Lin, is a close political ally to Chinese President Xi Jinping. The CAC likely directly reports to a committee chaired by President Xi and all official actions indicate that the regime is very serious about exerting significant control over the Chinese Internet. Most CAC enforcement activity has focused on Internet political control, in which "cyber security" involves censorship of any dissent. There is no indication that the CAC is enforcing controls over foreign corporations on data flow out of China, hardware requirements for acquisition and use inside China, or security inspections of foreign companies. As the designated agency to implement and enforce the cyber security law, the CAC has become the central entity in the Chinese Internet monitoring and censorship regime...READ MORE

Wapack Labs has cataloged and reported on Chinese Internet control in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
 
This TLP AMBER report is available only to Red Sky Alliance members.

Wednesday, June 28, 2017

Lurking Offshore: The Business Case Study for Working Together

Last week, the MPS-ISAO held a cybersecurity intelligence themed webinar, “Lurking Offshore: Active Cyber Threats Targeting Ports & Maritime”, with our partner, Wapack Labs. It’s a fascinating story about a financially motivated adversary using spear-phish to target Ports.I’m sure you are thinking, “Another scary cyber story… Why should I care?”By studying the data associated with this actor – how, when, why, and who, the case for Maritime and Port organizations working together to protect themselves from cyber adversaries is made. Cybersecurity silos need to be shattered - now.

Understanding the adversary.
Because Wapack has been tracking this adversary for some time, we have learned a lot by studying the intel.
First, this adversary is successful.  Our intel team sees an almost 100% success rate with a low detection rate (< 5%) through traditional security technology and vendor sourced data.  During the first six months of 2017, over 1,000 U.S. and European victims have been observed.
It’s a cost-effective, organized business operation. The malware being used only costs about $30 per month, and the adversary has developed a business model with specialized skills.  Also, there is high reuse between victims. So, if one Port is compromised, there is a good possibility that other Ports will be targeted using the same spear-phish email.
And, this adversary is persistent.  They improve odds of success by including supply chain partners in the scope of an attack.  In one instance where a Port was the intended victim, ten suppliers to this Port were targeted at the same time and with the same spear-phish email being used across all organizations.  The targeted suppliers were diverse too.  They included organizations who performed:   
  • Construction Consortium
  • Logistics Services
  • Oil & Gas Services
  • Consulting Services
  • Marine Transport
  • IT Services Provider
  • Multi-Modal Transport
  • Oil & Gas Engineering Services

Turning the tide.  
In 2015, The Obama administration issued two important pieces of Cybersecurity legislation.  A Presidential Executive Order (EO) was issued in February 2015 to promote private sector cybersecurity information sharing.  Section 2 of this EO states, “strongly encourage the development and formation of Information Sharing and Analysis Organizations (ISAOs).”  A few months later, the Cybersecurity Information Sharing Act of 2015 (CISA) was signed into law to “improve cybersecurity in the United States through enhanced sharing of information about cybersecurity threats.” CISA provides information sharing legal protections to organizations who participate in an ISAO.  

These two pieces of legislation led to the formation of the Maritime and Port Security ISAO, and its parent organization – the International Association of Certified ISAOs (IACI), to promote cyber resilience.   
If someone could tell you where the sharks were, wouldn’t you want to know?
The MPS-ISAO, headquartered at the Global Situational Awareness Center (GSAC) at NASA/Kennedy Space Center, is a non-profit private sector-led organization working in collaboration with government to advance Port and Maritime cyber resilience.  The core mission to enable and sustain a safe, secure and resilient Maritime and Port Critical Infrastructure through security situational intelligence, bi-directional information sharing, coordinated response, and best practice adoption supported by role-based education.
Port and Maritime organizations who subscribe to the MPS-ISAO’s cyber intelligence service have the advantage of early threat awareness provided via industry-specific, cross-sector, and global cyber intelligence along with countermeasure solutions.  They participate in a Maritime and Port community composed of stakeholders from across the industry sector who are interested in working together to achieve cyber resilience.  
Going back to the Lurking Offshore Case Study, we know that this adversary targets multiple victims within a Port’s supply chain using the same malicious email, and then reuses the email across another 8-10 Port victims.  When the email is shared into the MPS-ISAO Community, early threat awareness enables organizations to put protective measures in place.  
So, a single share can protect many.
And, the business case for working together was never stronger.
Wapack Labs’ engineers, researchers, and analysts design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information, using deep analysis techniques and visualization. Information derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.

Tuesday, January 17, 2017

IP Range Blocked in Guyana

A Guyana telecommunication company, GTT, has been implicated in a large-scale spamming campaign and various cyber security related incidents. This prompted the IP ranges of GTT to be blocked by several U.S. financial institutions and payment services. This may cause financial challenges to citizens and business in Guyana, but once the cyber security matters are rectified the IP range could be released. This information is being supplied for your situational awareness.
  • Guyana is an English-speaking South American/Caribbean country located to the east of Venezuela.
  • Guyana Telephone and Telegraph, rebranded as GTT+ in late 2015, is controlled by Atlantic Tele-Network (ATN). GTT+’s mobile unit Cellink competes with Digicel Guyana for market share and both operate the GSM/GPRS networks.
  • Digicel openly criticized GTT in 2016 for operating a government monopoly and hinted at corruption...READ MORE
Publication Date: 10 January 2017
Handling Requirements: Traffic light protocol (TLP) GREEN
Attribution/Threat Actors: Caribbean black hat actors/UKN
Actor Type: Adversary capabilities have been assessed as Tier II
Potential Targets: PayPal; Bank of America and Google Pay
Past Reporting: Red Sky Alliance: DOC-3314

The full report may be viewed in the Red Sky Alliance as DOC-4598. 
Contact Wapack Labs for more information.

Tuesday, December 6, 2016

Nigeria & Cyber Security: Two Steps Forward, One Step Back


Nigeria has long been a haven for highly talented and successful hackers, scammers, and their many spin off groups. Having developed this negative cyber reputation, Nigeria has in recent years enacted cyber laws to combat these groups and help protect their businesses and reputation. These laws were recently used for unfortunate political purposes, yet demonstrate a positive direction toward improved cyber security efforts.
  • Nigeria has a historical negative reputation for cyber hackers and scammers.
  • New cyber security legislation has been enacted to curb cybercrime.
  • Nigeria has recently arrested a popular blogger under the cyber laws, which was viewed as a political more than law enforcement measure.

While our Wapack Labs African Desk sees Nigeria making real progress in cyber security, we still see a country facing an increasing domestic and international threat in all domains of cyber security. When considerations of terrorism and the ongoing Boko Haram activities are brought into the equation, the pursuit of bloggers seems quite petty at best, and at worst, negligently misguided. While Nigeria continues to make very real steps forward in cyber security, it also tends to take a few steps backwards along the way.  This information is being supplied for your situational awareness.

Publication Date: 3 December 2016
Handling Requirements: Traffic light protocol (TLP) GREEN
Attribution/Threat Actors: Hackers & Scammers
Actor Type: Adversary capabilities have been assessed as Tier III
Potential Targets: Worldwide targets using Nigerian networks; connections to terrorism
Past Reporting: DOC-4283, DOC-4002, DOC-4486

The full report is available on our Executive Readboard.

Thursday, October 27, 2016

NFC – Friend or Foe


Wapack Labs has previously exposed the hazards of using near-field communication (NFC) devices in our support during the 2016 Summer Olympics in Rio De Janeiro and other collection and research projects.  NFCs are now being supplied in the United Kingdom (UK) to rapidly order pizzas through a swipe of a smart phone.  The “tattoos,” as they are being marketed, are being affixed to objects which enable smart phone users to quickly order pizzas and other food products. If corrupted, as with past USB jump drive compromises, an NFC device could run in the background of a cell phone and secretly forward personal identifying and financial information during a food order.  This information is being supplied for your situational awareness.

  • Near-field communication devices have been used for the past several years with low security parameters and are currently marketed for ease and convenience of e-transactions. 
  • NFC’s can be corrupted at the production level, similar to the past jump drive virus launches.
  • Heightened NFC cyber security awareness, education and training is desired for future use.

Publication date:                           25 October 2016
Handling requirements:               Traffic light protocol (TLP) GREEN
Attribution/Threat Actors:           Unknown hackers

Actor Type:                                     Adversary capabilities have been assessed as Tier II*

Potential Targets:                           Smart Phone users using NFC devices

Past Reporting:                               Red Sky Alliance: DOC-4113, DOC-3718, msg/3507 and blog/2016/09/30/nato-and-europol-cyber-reports-of-interest



*Practitioners with a greater depth of experience, with the ability to develop their own tools from publicly known vulnerabilities.


The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.



About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.