Showing posts with label financial. Show all posts
Showing posts with label financial. Show all posts

Monday, June 17, 2019

Newly Identified Phishing Malware, Allantibots, Can Fool Even The Most Eagle-eyed User.

Apple IDs are a popular target for hackers because they can enable theft of financial data and other personally identifiable information (PII). These are often obtained through phishing campaigns intended to trick users into entering their personal data. In June 2019, Wapack Labs identified one such campaign that is leveraging a large infrastructure and a phishing kit dubbed ‘Allantibots’. Allantibots is a sophisticated phishing package and is characterized by its ability to spoof the Apple URL. This results in a phishing URL that looks completely legitimate, even to a cautious user. To read the article go here: https://redskyalliance.org/finished-analysis/allantibots

To read the full article and find an archive of related cyber reporting, follow this link to  Allantibots Article 

Be sure to check out our cyber portal for other related articles Red Sky Alliance.org

Thursday, March 15, 2018

SWIFT: India City Union Bank Heist

TLP AMBER ANNOUNCEMENT:

On Saturday 17 February 2018, India’s City Union Bank disclosed that its systems were hacked. They discovered that three fraudulent remittances, totaling nearly $2 million, were sent to accounts in Dubai, Turkey, and China via the SWIFT financial platform. SWIFT, or the Society for Worldwide Interbank Financial Telecommunication, is the world’s largest electronic payment messaging system, facilitating the exchange of more than $6 trillion a day. The majority of international interbank messages use the SWIFT network. This network enables financial institutions worldwide to send and receive information about financial transactions in a secure, standardized and reliable format. SWIFT sends payment orders, which must be settled by correspondent accounts that the institutions maintain with each other. SWIFT bank heists in the past have been attributed, with medium confidence, to North Korean actors...READ MORE

Wapack Labs has cataloged and reported on cyber threats targeting SWIFT in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

This TLP AMBER report is available only to Red Sky Alliance members.

Wednesday, February 28, 2018

China Bank Regulation and Foreign Bank Access

During 2017, Chinese banking regulatory agencies have issued a series of new banking restrictions with serious impact on Chinese banking practices and potential impact on foreign financial institutions as well. They have been forcing compliance with the new regulations with USD $400 million in fines on banking institutions in 2017 alone. The key measures introduced include:

• Stamping out cryptocurrencies - The government has ordered all bitcoin/cryptocurrency exchanges in China to cease operations, and it was using electrical power control to close bitcoin mining operations.
• Suppression of underground banks - To prevent foreign exchange transactions by unauthorized entities abroad, the government blacklisted 40 entities and apparently blocked access to their websites from inside China.
• Slowing capital outflow - The government targeted capital outflows by cracking down on underground money transfers and restricting large overseas mergers and acquisitions.
• Foreign bank access - However, one component of this effort involved a relaxation of regulations rather than a tightening up. In November 2017 China announced that it would soon allow foreign companies to own Chinese banks and investment firms. The cap on foreign investment in Chinese banks will be removed and foreign investors will be allowed to own 51% in financial institutions. Now, foreign banks which set up branches in China will be allowed to conduct business directly with Chinese in Chinese yuan...READ MORE

Wapack Labs has cataloged and reported on Chinese banking regulations in the past. An archive of related reporting can be found in the Red Sky Alliance portal.  

Wednesday, December 13, 2017

Fraudulent Banking Website Part of Larger BEC Infrastructure

TLP AMBER ANNOUNCEMENT:

Business Email Compromise scams (BEC or BES) are a lucrative way for cybercriminals to gain high value credentials and commit fraud. Losses resulting from BEC scams surpassed 5 billion dollars this year and rising. BEC scams target groups and individuals by masquerading as legitimate services and organizations. Recent activity in Iceland involves the use of a fake website with ties to a larger infrastructure of domains designed for use in BEC scams. In this incident over 100 people were victimized with the use of the fake website, tricking victims into giving up financial credentials. These scams are difficult to defend against because they rely on social engineering and deceit instead of malware that can be detected by early warning software. The best defense against BEC scams is information sharing and networking...READ MORE

Wapack Labs has cataloged and reported on Business Email Compromise scams in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

This TLP AMBER report is available only to Red Sky Alliance members.

Monday, November 13, 2017

B.I.T.S Loader Attracting Cybercriminals

TLP AMBER ANNOUNCEMENT:

The Background Intelligent Transfer Service (BITS) is a legitimate Microsoft program used for creating and monitoring jobs over the network. Since it is a Windows legacy program it isn’t widely detected by AV solutions, making it attractive to cybercriminals for malware delivery and persistence. Recent emails targeting the Financial sector utilize BITS functionality by embedding it in heavily obfuscated Word documents, and with the use of LNK files. Monitoring BITS jobs in work environments is important to identify unwanted or unauthorized downloads and uploads. In the past, BITS was used to deliver banking trojans like DarkComet and GlobeImposter ransomware, and it is assessed with high confidence that it will continue to be utilized for both malware delivery and persistence, particularly against Windows based systems that would otherwise be considered highly locked down or security hardened. This report focuses on these two recent implementations of BITS, and looks at other ways BITS is leveraged in the wild...READ MORE

Wapack Labs has cataloged and reported on malware targeting the financial sector in the past. An archive of related reporting can be found in the Red Sky Alliance portal.  

WWW.WAPACKLABS.COM

This TLP AMBER report is available only to Red Sky Alliance members.

Thursday, August 24, 2017

Ursnif Campaign Targets Logistics and Finance

TLP AMBER ANNOUNCEMENT:

Wapack Labs recently identified a large scale Ursnif campaign, affecting multiple companies in the logistics, finance, and IT sectors. The campaign, which began in May 2017, consists of spear-phishing emails with a malicious document attached that, when opened, delivers malware identified as Ursnif. Active since 2012, Ursnif malware has undergone several variations. The current variant implements data exfiltration and sends encrypted victim data to a C2 server. By using compromised accounts and exploiting existing trust relationships, the actors are likely able to achieve a high open-rate. While additional user-interaction is required to enable the malicious macro, it probably resulted in a few installations because the delivery email was not unsolicited. Additionally, the clever social engineering exhibits a moderate to advanced level of tradecraft by the actor. Tactics, Techniques, and Procedures (TTPs) and shared infrastructure in this campaign suggest a single actor or group with Chinese attribution executed this campaign...READ MORE

Wapack Labs has cataloged and reported extensively on spear-fishing, Ursnif, and China in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

This TLP AMBER report is available only to Red Sky Alliance members.

Thursday, May 25, 2017

Tor-base Site Operates Illegal Sales Under AES 256-bit Encryption

Wapack Labs discovered a Tor-based website conducting illegal financial sector activities; ranging from carding and counterfeit money to electronics and narcotics. The site, which requires no registration, claims that the forum is totally anonymous and highly secure; largely in part to encrypting all data with AES 256-bit encryption. The site provides a multi-signature escrow for all transactions; allowing safe Bitcoin (BTC) transactions between both parties...READ MORE

Wapack Labs has cataloged and reported extensively on Tor-based and carding activities in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Free Online Payment System Credentials: Contact Señor

Wapack Labs analysts exposed a threat to the financial sector, one who is actively posting in several clear web and underground forums. Within these forums, the actor creates threads of free, downloadable log-in credentials, for an online payment system. Analysts assess that it is likely that the actor is brute-forcing the accounts to obtain the passwords. A brute force attack is a trial and error method used by application programs to decode encrypted data such as passwords - highly effective if the account uses simple passwords. The language, emails, and passwords indicate that the actor is a Spanish or Portuguese speaker, likely operating in South America...READ MORE

Wapack Labs has cataloged and reported extensively on Spanish speaking, threat actors in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Tuesday, October 18, 2016

DNS and Africa: Part II – Senegal / Finance and Government

Observations in Senegal has provided Wapack Labs Africa Desk a glimpse into a developing country’s execution of Domain Name System (DNS) controls.  These developments are on the heels of the U.S. abandoning control of ICANN and IANA.  This information is being supplied for your situational awareness.

  • The U.S. relinquished control of the Internet Committee for Assigned Names and Numbers (ICANN’s), Internet Assigned Numbers Authority (IANA) function on 30 September 2016.
  • Many countries worldwide must now manage their own DNS controls, triggering potential disorder. 
  • The developing country of Senegal is experiencing challenges in the management of cyber security issues affecting financial and government institutions.  

Publication date:                       15 October 2016

Handling requirements:             Traffic light protocol (TLP) GREEN

Attribution/Threat Actors:         Unknown at this time

Actor Type:                                Adversary capabilities have been assessed as Tier II*

Potential Targets:                       Senegal and neighboring West African nations

Past Reporting:                           Red Sky Alliance: DOC-4365


*Practitioners with a greater depth of experience, with the ability to develop their own tools (from publicly known vulnerabilities). 

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.