Showing posts with label dark web. Show all posts
Showing posts with label dark web. Show all posts

Friday, October 27, 2017

Dark Web Site Selling ATM Malware

Wapack Labs observed ATM malware being sold on a dark web site. The malware targets all models of Wincore Nixdorf ATMs. The website explains that the Wincore 200xe ATMs are the easiest cash machines to exploit. The malware currently costs $1500.00 in Bitcoin for the first month (beginning 15 October 2017). After the first month, the ‘registration’ fee will be doubled. $1500.00 buys the buyer one credit, which is valid for a one time use on one ATM. To execute the attack users must log-in to their account on the website and receive a code (for one credit). The malware will then show the attacker the amount of cash in each money cassette that resides inside the ATM. The malware will then bypass the normal ATM system processes and the ATM will dispense all the bills in a desired cassette. The website also provides video links on their Tor site, demonstrating the method to fraudulently withdraw money, along with a free 10-page step-by-step Word document which explains how to use the malware. This guide describes in detail the tools required, software instructions, and details referencing different types of ATMs. This includes how the ATMs operate and how to find the interior USB ports...READ MORE

Wapack Labs has cataloged and reported on ATM malware in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
  
WWW.WAPACKLABS.COM

Wednesday, October 18, 2017

CVE-2017-12615

Wapack labs observed a recent Common Vulnerabilities and Exploit (CVE), CVE-2017-12615, being discussed in a Romanian hacker forum. A moderator on the forum posted an explanation of the exploit, a link to the National Vulnerability Database, and a GitHub link documenting how to weaponize the exploit in the Metasploit-framework. CVE-2017-12615 is assessed with a high severity rating (8.1/10) as it allows an attacker unauthorized modification to Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled. HTTP PUT places a file or resource at a specific URI, and exactly at that URI. If there is already a file or resource at that URI, PUT replaces that file or resource. If there is no file or resource there, PUT will create one. PUT is idempotent, but, paradoxically, PUT responses are not cacheable. Successful exploitation enables an attacker to upload a JSP file, request the file and execute its contents to gain remote access to the system. Wapack Labs is providing this report to Red Sky Alliance members for situation awareness. With the CVE and methods being posted in the wild, hackers may be more likely to attempt this attack. Wapack Labs recommends all Red Sky Members who use Apache Tomcat apply a security update and ask their Red Team members to test network assets to ensure the patch updated correctly...READ MORE

Wapack Labs has cataloged and reported CVEs in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Friday, April 14, 2017

Steal from the Rich, to Give to the Poor: A Cyber Brotherhood's Tale

Wapack Labs is researching a self-proclaimed cyber brotherhood that has pledged to halt the unjust distribution of money. For the past year, this brotherhood has been hosting a dark web domain where they provide stolen financial information. They offer stolen PayPal accounts, money-back guarantee, and a discount if more than one account is purchased. Before being granted access, prospective users are required to submit an application via TorBox email.

Wapack Labs has cataloged and reported extensively on carders in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Tuesday, February 28, 2017

For Sale: W-2s and the GozNym Botnet

On February 17, 2017 Wapack Analysts observed a deep web market vendor advertising 2016 U.S. W-2’s with dates of birth (DOB) and U.S./EU bank accounts for sale. Additionally, the vendor is also selling the GozNym botnet. The vendor maintains good feedback in deep web markets. GozNym, though underground, received media attention in late September 2016 when CISCO’s Talos team cracked the Domain Generation Algorithm (DGA) of GozNym. This exposure may be the reason for the vendor's current public sale - utilizing dark web market escrow systems. Though the vendor sells on these sites, business is conducted over Jabber/E-Mail using PGP encryption...READ MORE

Wapack Labs has extensively reported on botnets in the past. An archive of related reporting can be found in the Red Sky Alliance Portal.

TLP: AMBER
ACTOR TYPE: (III)
SERIAL: IA-004-2017
COUNTRIES: US, EU
INDUSTRIES: Financial
REPORT DATE: 20170221

Saturday, October 8, 2016

Threat Actor Offers Variety of Tools for Free

Wapack analysts have observed a threat actor who has been advertising his coding abilities (and potential services) in both the public Internet and the dark web. The threat actor typically writes his programs in Python, uses Kali Linux and also appears to be able to speak Japanese. Wapack analysts have observed the threat actor using several OPSEC techniques indicating that he is more sophisticated than script kiddie-level (novice or beginner) threat actors.

Publication date:                            6 October 2016

Handling requirements:                  Traffic light protocol (TLP) GREEN

Attribution/Threat Actors:              N/A

Actor Type:                                     Adversary capabilities have been assessed as Tier II*

Potential Targets:                            N/A

Past Reporting:                                N/A

*Practitioners with a greater depth of experience, with the ability to develop their own tools (from publicly known vulnerabilities). 

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.

Wednesday, October 5, 2016

Exploit Kit Author


Wapack Labs has discovered an exploit kit author, selling within the Dark Web.  Analysts encountered this kit in September 2016, as the most popular/sought after exploit kit amongst Brazilian hackers during the 2016 Rio Olympics.  Wapack Labs analysts often research breaches of cyber security in numerous corporate and government cyber-attack incidents.  This report contains identity, Dox and TTP information of actor - provided for your situational awareness.


Publication date:                        03 October 2016

Handling requirements:            Traffic light protocol (TLP) GREEN

Attribution/Threat Actors:       Russian author

Actor Type:                                 Adversary capabilities have been assessed as Tier IV*

Potential Targets:                       Worldwide individuals, corporation and/or governments

Past Reporting:                           N/A

*Criminal or state actors who are organized, highly technical, proficient, well-funded professionals working in teams to discover new vulnerabilities and develop exploits.

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.


About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.

Monday, September 12, 2016

Cyber Pirates - Hacking on the High Seas


www.marsecreview.com
On 9 September 2016, OSINT provided a vivid reminder of how malicious actors use various malware tools to obtain shipping information that is often used in pirating on the high seas or within maritime ports.  When pirates raid ships, they generally have a good idea what they're after, because shipping databases are often surprisingly insecure.  Wapack Labs have proven such with past collection and analysis.  Professional hackers break in online, steal ships' manifestos and sell them on the dark web.  This information is in support of a 2015 Wapack Labs analysis of maritime key-logged data from a European port company; the results of which resulted in suspected fraudulent activity.  This information is being supplied for your situational awareness.


Publication date:                         9 September2016

Handling requirements:               Traffic light protocol (TLP) GREEN

Attribution/Threat Actors:           Cyber Pirates

Actor Type:                                  Tier III to IV

Potential Targets:                        USA / International

Past Reporting:                            DOC-3151, DOC-3881

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.


About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.

Thursday, August 18, 2016

US Defense Company Researcher Attracting Undesired Attention from Underground Actors

On 16 August 2016, Wapack Labs became privy to conversations in the dark web that appears to have identified a US Defense Company (DIBCO) conducting anti-botnet activities and active research;  exposing the address from which they operated. As a result of this activity, adversary operators (who own the botnet) appear to have taken notice.  

Wapack Labs believes, with medium-high confidence, that there will be retaliatory threat posed to the DIBCO –regardless of the accuracy of the underground chatter.


Publication date: 16 August 2016
Handling requirements: Traffic light protocol (TLP) AMBER
Actor Type: Tier II   

This report was published in its entirety to the Financial Services ISAC and Red Sky Alliance portal on August 16, 2016.  For more information, contact Wapack Labs at 844-4-WAPACK.