Showing posts with label exploit. Show all posts
Showing posts with label exploit. Show all posts

Tuesday, October 30, 2018

InfusedAppe Malware

InfusedAppe malware was observed by Wapack Labs attempting an Apache Struts CVE-2017-5638 exploit against a client network. The malware is titled InfusedAppe because it writes several files to C:\Windows\InfusedAppe\ upon execution of the executable payload.

InfusedAppe follows Chinese preference for multi-stage payloads. Its configuration suggests plans to expand in targeting US and Republic of Korea (KR) users.

Want to know more? Webinar tomorrow at Noon EST.

REGISTER HERE


Contact Wapack Labs for more information:
603-606-1246, or feedback@wapacklabs.com 

Thursday, August 24, 2017

Ursnif Campaign Targets Logistics and Finance

TLP AMBER ANNOUNCEMENT:

Wapack Labs recently identified a large scale Ursnif campaign, affecting multiple companies in the logistics, finance, and IT sectors. The campaign, which began in May 2017, consists of spear-phishing emails with a malicious document attached that, when opened, delivers malware identified as Ursnif. Active since 2012, Ursnif malware has undergone several variations. The current variant implements data exfiltration and sends encrypted victim data to a C2 server. By using compromised accounts and exploiting existing trust relationships, the actors are likely able to achieve a high open-rate. While additional user-interaction is required to enable the malicious macro, it probably resulted in a few installations because the delivery email was not unsolicited. Additionally, the clever social engineering exhibits a moderate to advanced level of tradecraft by the actor. Tactics, Techniques, and Procedures (TTPs) and shared infrastructure in this campaign suggest a single actor or group with Chinese attribution executed this campaign...READ MORE

Wapack Labs has cataloged and reported extensively on spear-fishing, Ursnif, and China in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

This TLP AMBER report is available only to Red Sky Alliance members.

Friday, May 12, 2017

Equation Group's Exploit is Operating Globally: #WannaCry Ransomware

Wapack Labs is tracking a reported ransomware attack on various countries affecting operations in the health and financial sectors. The malware has been titled: WCry, WannaCry or WanaCrypt0r ransomware. Open source reporting indicates that Russia, Ukraine, Taiwan, Spain, and the United Kingdom are being targeted. CCN-CERT (SP) has confirmed the malware propagates through the leaked Equation Group ETERNALBLUE SMB exploit. Microsoft Security Bulletin MS17-010 details mitigations for this exploit.

Wapack Labs has cataloged and reported extensively on ransomware in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM