Showing posts with label exploits. Show all posts
Showing posts with label exploits. Show all posts

Friday, August 11, 2017

Shadowbrokers and the Scylla Hacking Store

The ShadowBrokers (SB) have recently started a new Tor based market called Scylla Hacking Store. SB is selling several APT stolen exploits (US, Russian and Chinese exploits), crimewave exploit kits, and other crimewave hacking tools: bots, hash cracking, and Microsoft Office exploits. Analysts believe, with medium confidence, the recent Petya activity may be related to SB sales of all the payload source code for the FuzzBunch framework, which included, EternalBlue...READ MORE

Wapack Labs has cataloged and reported extensively on the ShadowBrokers in the past. An archive of related reporting can be found in the Red Sky Alliance portal.


Wednesday, January 25, 2017

WhatsApp - What’s up?

It has been demonstrated that a deliberate design decision for the WhatsApp messaging application created a vulnerable condition that could allow for entire conversations or calls to be intercepted. Exploitation of this condition would require a very highly skilled threat actor to access to WhatsApp servers in order to execute a man-in-the-middle attack.

Wapack Labs has reported on WhatsApp privacy in the past. An archive of related reporting can be found in the Red Sky Alliance portal. 


TLP: GREEN
ACTOR TYPE: (V)
SERIAL: TIR-016-2017
COUNTRIES: All
REPORT DATE: 20170125

Monday, August 29, 2016

The Shadow Brokers Target Equation Group


www.bestvpn.com
On 13 August of 2016, a persona calling themselves “theshadowbrokers” announced the leak of Equation Group tools.  The leak appears to be authentic and includes several exploits used by Equation Group.  Three CVEs (2016-6366, 2016-6367, 2016-6909) have been assigned to the exploits and one, EXTRABACON (CVE-2016-6366), was considered a zero-day vulnerability when released.  Affected products and software versions are listed for each exploit.
This report provides analysis and mitigations for the exploits included in the leak. 
Wapack Labs is providing this analysis as situational awareness of tools leaked from a Tier VI adversary.


Publication date:                            26 August 2016

Handling requirements:                  Traffic light protocol (TLP) AMBER

Attribution/Threat Actors:              Equation Group

Actor Type:                                     Tier VI   

Potential Targets:                           USA / International

Past Reporting:                               DOC-4133

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.