Showing posts with label europe. Show all posts
Showing posts with label europe. Show all posts

Thursday, March 1, 2018

Bosnia and Herzegovina Cyber Profile

Bosnia and Herzegovina is a country in Southeastern Europe formerly under the Republic of Yugoslavia. After the dissolution of Yugoslavia, Bosnia and Herzegovina has experienced infighting of ethnically and religiously motivated hacktivist groups, as well as commercially motivated hackers. Current cyberlaws are not fully enacted, yet the country completely cooperates to fight cybercrime. Bosnian hackers use Bosnian, Serbian, German, English, and other languages to communicate. Due to recent international arrests, many Bosnian groups have been driven underground. The current Western threat of Bosnian hackers is low, based on our current data...READ MORE

Wapack Labs has cataloged and reported on international cyber profiles in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Thursday, July 20, 2017

Financially Motivated APT-style Actors Target Retail & Hospitality

A new wave of financially motivated, APT-style group, of cyber threat actors are targeting large restaurant chains with phishing emails containing malicious attachments. As early as April 2017, a new wave of the group's activity has been targeting the retail and hospitality sectors. The APT-style group has been active since 2015 and is known for their use of the Carbanak malware. The most recent campaigns leverage two new RTF droppers to deliver a variant of a known backdoor. Early campaigns were known for targeting financial institutions and banks; in 2015, targeting European banks through a banking application called the Internet Front End Banking System (iFOBS). This report describes TTPs leveraged in the recent campaigns...READ MORE

Wapack Labs has cataloged and reported extensively on APTs, cyber threat actors, phishing, malware, financial institutions, and Carbanak in the past. An archive of related reporting can be found in the Red Sky Alliance portal.



Tuesday, May 30, 2017

Cyber Espionage Targets Managed Service Providers (MSPs)

Wapack Labs Analysts assess with high confidence a growing cyber espionage campaign, with a Chinese nexus, that has been targeting Managed Service Providers (MSPs) in order to compromise multiple organizations. This campaign is responsible for intrusions in the United States, Europe, and Japan. Typical targets include construction, engineering, aerospace, telecom, and government institutions. The actors involved leverage a wide variety of tools and custom malware, allowing flexibility when it comes to the methods used for intrusion...READ MORE

Wapack Labs has cataloged and reported extensively on espionage campaigns in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Tuesday, March 7, 2017

Russian Cyber-Influence in the 2017 European Elections

Wapack Labs assess with high confidence that Russia is behind influence campaigns to support right-wing nationalist candidates in Dutch, French, and German national elections who are campaigning on anti-immigration platforms, reducing participation in the European Union (EU) and NATO. The nationalist parties likely have little chance of winning a majority (medium confidence) in parliamentary elections or the second round of the French presidency; however, gaining seats provides them the opportunity to influence policy in a coalition government.

We assess, with medium confidence, that Russian cyber actors will conduct espionage and media manipulation operations to influence the outcome of each country’s election, but will modify the previous Tactics, Techniques, and Procedures (TTPs) used against the U.S. in 2016. Russian threat actors will dedicate additional resources to improving operational security to avoid discovery or blowback, and will avoid mimicking the tactics used in Ukraine and Montenegro...READ MORE

Wapack Labs has extensively reported on election interference in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

TLP: AMBER
ACTOR TYPE: (VI)
SERIAL: PIR-00x-2017
COUNTRIES: Europe, NL, FR, DE, RU
INDUSTRIES: Gov, Political
REPORT DATE: 20170303

Thursday, September 29, 2016

Credit Card Fraud & EMV Security Chip

Mobile banking fraud in Europe has increased by a factor of 20; a trend that could follow in the U.S.  Credit card fraud has hit critical mass in the U.S., causing a push in technology in new mobile apps, which could create a virtual playground for criminals.  A recent surge in the volume of U.S. credit card fraud has forced industries to adopt the European EuroPay, MasterCard and Visa (EMV) card system.  The resistance to the EMV conversion will result in higher merchant costs and ATM manufacturer resistance, which has prompted a growth in mobile banking apps.

Publication date:                        26 September 2016

Handling requirements:              Traffic light protocol (TLP) GREEN

Attribution/Threat Actors:          Unknown at this time

Actor Type:                                 Adversary capabilities have been assessed as Tier III*

Potential Targets:                        USA

Past Reporting:                            Red Sky Alliance: DOC-3952, DOC-4265

*Practitioners who focus on the discovery and use of unknown malicious code, are adept at installing user and kernel mode root kits10, frequently use data mining tools, target corporate executives and key users (government and industry) for the purpose of stealing personal and corporate data with the expressed purpose of selling the information to other criminal elements. 

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.