Showing posts with label exploit kit. Show all posts
Showing posts with label exploit kit. Show all posts

Monday, February 27, 2017

The Economical RAT: Luminosity.Link


The Luminosity.Link Remote Administration Tool (RAT) has been observed by a number of companies over the past year being spread through phishing emails. The Luminosity.Link RAT is sold openly online and contains numerous features that make it popular among cyber criminals. Luminosity.Link is designed using the .NET framework for use on Windows Operating systems. 

The Key Findings of our analysis revealed:
  • Recent samples leverage the AutoIt scripting tool
  • Luminosity.Link uses the SundownEK (Exploit Kit) for delivery
  • Luminosity.Link samples contain encrypted configurations
Luminosity.Link is an economical RAT for cyber criminals. Coupling it with Exploit Kits targeting Windows systems further increases infection success rates. We assess with high confidence that the development and use of the Luminosity.Link RAT will continue...READ MORE

Wapack Labs has extensively reported on Remote Access Tools (RAT) in the past. An archive of related reporting can be found in the Red Sky Alliance Portal. 

TLP: AMBER
ACTOR TYPE: (I&II)
SERIAL: FR17-002 
COUNTRIES: Worldwide 
INDUSTRIES: Any, DIB 
REPORT DATE: 20170221

Wednesday, October 5, 2016

Exploit Kit Author


Wapack Labs has discovered an exploit kit author, selling within the Dark Web.  Analysts encountered this kit in September 2016, as the most popular/sought after exploit kit amongst Brazilian hackers during the 2016 Rio Olympics.  Wapack Labs analysts often research breaches of cyber security in numerous corporate and government cyber-attack incidents.  This report contains identity, Dox and TTP information of actor - provided for your situational awareness.


Publication date:                        03 October 2016

Handling requirements:            Traffic light protocol (TLP) GREEN

Attribution/Threat Actors:       Russian author

Actor Type:                                 Adversary capabilities have been assessed as Tier IV*

Potential Targets:                       Worldwide individuals, corporation and/or governments

Past Reporting:                           N/A

*Criminal or state actors who are organized, highly technical, proficient, well-funded professionals working in teams to discover new vulnerabilities and develop exploits.

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.


About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.