Showing posts with label government. Show all posts
Showing posts with label government. Show all posts

Friday, March 23, 2018

China Government Hacker Resurgent

In 2015, China and the United States pledged a bilateral Cyber Agreement that they would refrain from conducting cyber operations to steal intellectual property from one another. In 2016, a major drop in such intrusions was noted. By 2017, however, several new cases of cyber intrusion against defense contractors and other commercial entities were identified, which raises the question of whether the Chinese have in fact been constrained by the 2015 agreement. Wapack Labs reviewed the major cyber operations cases of 2017, that appeared to have Chinese origins, to assess the current trends in government-sponsored operations and answer the question: is China currently abiding by this agreement? Has being a signatory to the agreement constrained Chinese government behavior in any meaningful way?...READ MORE

Wapack Labs has cataloged and reported on Chinese state-sponsored cyber operations in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
  
WWW.WAPACKLABS.COM

Tuesday, February 20, 2018

Huawei and ZTE Phones and Other Devices – Security Up for Sale

TLP AMBER ANNOUNCEMENT: 

Huawei, a long time Chinese telecommunications equipment competitor to the U.S. Cisco Systems, has earned a reputation for selling equipment that contains various cybersecurity, intellectual property, and quality control issues. Wapack Labs concurs with U.S. government agencies that Huawei and ZTE equipment are a cause for concern when considering supply chain equipment. Huawei and ZTE have higher than normal rates of cybersecurity issues due to a range of root causes. The United States, United Kingdom, Canada, Australia and South Korea began instituting measures to limit Huawei, and ZTE equipment from being used relative to government and military related communications as far back as 2003. The warnings were issued via reports to the U.S. Congress from the Intelligence Community, with ZTE officially banned for use by U.S. government agencies in 2013. They further started instituting that government contractors and vendors also comply with contracting restrictions against vendor and contractor utilization of Huawei and ZTE equipment for security reasons even before the national security issues were made openly public in 2011...READ MORE

Wapack Labs has cataloged and reported on Huawei and telecommunications in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM


This TLP AMBER report is available only to Red Sky Alliance members.

Monday, September 11, 2017

Profile: Arrested Chinese Cyber Actor Yu Pingan

TLP AMBER ANNOUNCEMENT: 

On 22 August 2017, a Chinese national named Yu Pingan was arrested and charged with cyber intrusions into four U.S. corporations between 2011 and 2014 that included the use of Sakula malware, known for its use in the major breaches of Anthem patient records and the Office of Personnel Management (OPM). Yu Pingan operates under the principle persona “Goldsun.” Analysts believe (high confidence) that he is in fact the Goldsun that was active at the Chinese hacker website Xfocus.net from 2004 to 2009. He is credited with and likely authored several pieces of malware that he posted during this period. His real identity remained unknown, but email addresses in some of his posts correspond to other accounts identified in the charges that led to his arrest. The charges against Yu Pingan do not identify any organization he was working for nor any connection to the Chinese government. Wapack Labs believes with medium confidence that Yu is affiliated with the Chinese civilian hacker group Wekby. The Chinese Government has not issued any statements and there has been no coverage of his arrest in official media...READ MORE

Wapack Labs has cataloged and reported extensively on China, Wekby, APT, and cyber intrusions in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

This TLP AMBER report is available only to Red Sky Alliance members.

Monday, June 19, 2017

U.S. Corporate Concerns with China’s New Cybersecurity Law

On 1 June 2017, the Chinese government put an extensive new Cybersecurity law into effect. This law applies to all network operations in China, by Chinese citizens and foreign business operations alike. Many U.S. corporations operating in China have expressed concerns about how this law will impact their ability to operate under the more intrusive Chinese government control. The provisions with the potential for the greatest negative impact on foreign firms include:
  • Definition of network operators. The scope of the Cybersecurity Law provides control over not just telecom operators and internet firms but also banking institutions, insurance companies, securities companies, providers of cybersecurity products and services, and essentially any enterprise with a website in China or that provides network services. The American Chamber of Commerce in China has said the Law “will impact almost every company that operates in China.”
  • Requirements for “critical information infrastructure” operators. The Law defines these to include “public communications and information services, energy, finance, transportation, water conservation, public services, e-governance,” and other enterprises that could harm national security or the economy if damaged. Foreign corporations included in this category now face restrictions on equipment and services they can use, and they are vulnerable to inspection and intrusion by the Chinese government.
  • Restrictions on sending data outside China. The Law states that “personal information and other important data from operations within the PRC shall be stored within mainland China.” Business information and data on Chinese citizens cannot be transferred abroad without permission, and that would be contingent on intrusive “security assessments” by the Chinese government. Some U.S. analysis suggests that this could also prohibit the export of economic, technological, or scientific data considered to “pose a threat to national security or the public interest.”
The situation for foreign firms is uncertain at present because details on the scope of the Law and how it will be enforced are still unavailable. The initial impression among U.S. businesses is that the potential for intrusion and interruption is certainly considerable.

Wapack Labs has cataloged and reported extensively on China's cybersecurity in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Tuesday, October 18, 2016

MetaData Exposed – Cruise, Merchant and Gov. Vessels


Wapack Labs analyzed vital metadata which began through an instructional video explaining cyber concerns on cruise ships.  The video revealed an Autonomous System Number (ASN), which subsequently identified a U.S. based telecommunication company.  Research confirmed this company, an Internet Service Provider (ISP), had exposed numerous Internet Protocols (IP) which were directly connected to cruise, merchant and government/MIL vessels.  Negative implications to this open IP metadata are serious and could be used in many nefarious ways.  This information is being supplied for your situational awareness.  

Publication date:                  12 October 2016

Handling requirements:        Traffic light protocol (TLP) AMBER

Attribution/Threat Actors:    Unknown at this time

Actor Type:                           Adversary capabilities have been assessed as Tier III & IV*

Potential Targets:                  Cruise ships, merchant vessels, and Govt/MIL vessels

Past Reporting:                      Red Sky Alliance: DOC-4266, DOC-3881

*Practitioners who focus on the discovery and use of unknown malicious code, are adept at installing user and kernel mode root kits10, frequently use data mining tools, target corporate executives and key users (government and industry) for the purpose of stealing personal and corporate data with the expressed purpose of selling the information to other criminal elements. 

*Criminal or state actors who are organized, highly technical, proficient, well-funded professionals working in teams to discover new vulnerabilities and develop exploits.

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.