Showing posts with label hacker. Show all posts
Showing posts with label hacker. Show all posts

Wednesday, December 6, 2017

BINs Sold at Hacker Shop

TLP AMBER ANNOUNCEMENT:
 
A new hacker/carder shop was discovered by Wapack Labs. The shop sells credit card data, hacking tools and compromised dating accounts. It accepts Bitcoins, and Perfect Money, which are automatically exchanged to Bitcoins via an exchange service. The shop has advertised via direct e-mails to hackers since October 2017 and an advertisement was detected on a hacker forum in November 2017. This hacker/carder shop is currently a medium threat and has thousands of items listed for sale. Financial organizations whose BINs match those of the compromised credit cards for sale, should take notice...READ MORE

Wapack Labs has cataloged and reported on hacker and carder shops in the past. An archive of related reporting can be found in the Red Sky Alliance portal. 


 This TLP AMBER report is available only to Red Sky Alliance members. 

Friday, June 16, 2017

OpIcarus2017, a Limited Risk

In June 2017, Wapack Labs Analysts observed a faction of the Anonymous collective attempting to launch OpSacred, which is the fifth phase of OpIcarus2017; a multiphase operation aimed to target central banks and other financial institutions (i.e.: International Monetary Fund and the World Bank). The campaign attracted hundreds of participants, yet failed to attract AnonOps support, create a dedicated IRC channel, attract experienced organizers, or followup after their initial start day - producing limited effects. While the operation has been badly organized, it may become a training ground for future hacker collaborations, especially since the Anonymous collective has been observed using GitHub to collect and share tools...READ MORE

Wapack Labs has cataloged and reported extensively on Anonymous' operations in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Thursday, May 25, 2017

The LinkedIn, Dropbox, and Formspring Hacker: Yevgeniy Nikulin

Yevgeniy Nikulin is a potent Russian hacker responsible for major breaches including Linkedin, Dropbox and Formspring, as well as less known funds theft from a Bitcoin hedge fund and from individuals. After his arrest in Prague, Russia filed its own extradition request to fight the one from the US. There are unconfirmed allegations that Nikulin may have some insights on the 2016 Presidential Elections related hacking. Nikulin is a high-skilled dangerous hacker. While the true nature of his connections to the Russian government is unproven, it is possible that it prompted the legal help that he is getting...READ MORE

Wapack Labs has cataloged and reported extensively on hackers in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Monday, April 10, 2017

Russian Hacker: DDoS Services for Hire

Wapack Labs is researching an established Russian hacker who provides DDoS services for hire. The hacker offers a wide variety of DDoS attacks which can be accomplished on any specified port - guarantees 100% anonymity and a 100% refund for a failed DDoS attack. The cost for services vary. Payments may be made in Webmoney, Qiwi, and Bitcoin. All communication is over ICQ, Jabber, or Telegram.

Wapack Labs has cataloged and reported extensively on DDoS hackers in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Friday, March 3, 2017

The Amateur from Algeria

On March, 1, 2017 Wapack Labs Researcher observed a hacker providing malicious tools on various Arabic, Russian, and English hack-forums. He was observed selling gift cards for Bitcoin (BTC), promoting phishing scams, and posting website defacements. The hacker has the necessary skills to create basic exploits. The fact that his malicious software is free, may speak to its quality - or people’s trust in a novice...READ MORE

Wapack Labs has extensively reported on carders in the past. An archive of related reporting can be found in the Red Sky Alliance Portal.

TLP: AMBER
ACTOR TYPE: (II)
SERIAL: TR-042-2017
COUNTRIES: DZ
INDUSTRIES: Financial
REPORT DATE: 20170301

Saturday, December 10, 2016

Black Hat Hackers: Counterfeit Coupons

Wapack Labs research into the hacker underground has uncovered a group of black hat hackers who claim to have taken over a coupon counterfeiting business. This black hat collective may have an affiliation with another threat actor who operated in the dark web marketplace, SilkRoad, and was sentenced to prison for selling counterfeit coupons. This information is being provided for your situational awareness. 
  • Collective is a self-described all female, black hat hacking group.
  • Collective appears to have taken over coupon counterfeiting cyber business.
  • Collective offers a variety of counterfeit coupons to be exploited at self-checkout lanes in retail stores.

Publication Date: 7 December 2016
Handling Requirements: Traffic light protocol (TLP) GREEN
Attribution/Threat Actors: Black Hat Hacking Collective
Actor Type: Adversary capabilities have been assessed as Tier II
Potential Targets: Financial, business and retail sectors
Past Reporting: Msg/#8168 & 8722

Wednesday, November 16, 2016

Russian Hacker Monetizes Traffic

A Russian hacker has been operating in the Russian underground for over 10 years; carrying out activities that range from stealing and distributing credit card data to hacking pharmacy-related websites in order to monetize their traffic. Known actor was observed working with another Russian speaking hacker, which possibly connects actor to the gang that operated several botnets.

Friday, November 4, 2016

Chinese Military and Aerospace Smart Tech. Conference


Wapack Labs received information that a senior Chinese hacker received an invitation to attend a Chinese military and aerospace technologies exposition in Beijing in September 2016.  This expo was sponsored by the China Aerospace Science and Technology Corporation (CASC) as part of its military-to-civilian technology transfer effort.  Equipment scheduled for exhibit included smart terminals, smart wearable equipment and systems, robotic systems, advanced sensors, security warning equipment, satellite communications, battlefield and soldier communications systems, imagery processing and visualization technologies, nano-materials, and stealth materials.  Invitees included the Central Military Commission (CMC) Joint Staff Department, CMC Logistics Support Department, CMC Equipment Development Department, as well as Navy, Army, Air Force, and Rocket Forces organizations.  Media reports of the event indicated there were about 200 attendees, although photo coverage of the event did not show any military present in uniform.


This event highlights the role that CASC plays for China in technology transfer from aerospace and the military into the civilian sector.  The fact that a hacker received the invitation at least suggests that collection operations related to the technologies exhibited at the expo could have been part of the discussion.  If some military representatives attended, including organizations with a cyber collection role, it would probably be part of the CMC Joint Staff Department representation.


Publication date:                            29 October 2016
Handling requirements:                Traffic light protocol (TLP) AMBER.
Attribution/Threat Actors:           State Actors
Actor Type:                                     Adversary capabilities have been assessed as Tier IV*
Previous Reporting:                       PIR 4.21.16; PIR 2.25.15
Industries Targeted:                       Aerospace manufacturing, Government Contractors.


*Criminal or state actors who are organized, highly technical, proficient, well-funded professionals working in teams to discover new vulnerabilities and develop exploits.

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.

Tuesday, November 1, 2016

Indetectables RAT Receives Help from Several White Hat Hackers


In late September 2016, a Spanish speaking hacker released an updated version of a popular white hat developed Remote Access Tool (RAT) named “Indetectables RAT” on the Spanish language hacker forum Indetectables.net. This tool is posted to dozens of international hacker groups who have targeted US and international institutions and has a low anti-virus detection payload (13/56) for samples submitted to Virus Total. The hacker also received the advice of several well-known international white hat hackers whom he/she credits in the latest builder version (v.0.9.2).

Publication date:                        24 October 2016
Handling requirements:            Traffic light protocol (TLP) AMBER
Attribution/Threat Actors:       Indectables hacker
Actor Type:                                 Adversary capabilities have been assessed as Tier III*

Potential Targets:                       US/International institutions

Past Reporting:                           N/A

Indicators:                                   https://www.threatrecon.co/search?keyword= Indetectables_RAT

*Practitioners who focus on the discovery and use of unknown malicious code, are adept at installing user and kernel mode root kits10, frequently use data mining tools, target corporate executives and key users (government and industry) for the purpose of stealing personal and corporate data with the expressed purpose of selling the information to other criminal elements. 

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs


Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.

Friday, October 7, 2016

Defacement Campaigns: Turkey-based Hacking Group

Wapack Labs has discovered a very active hacking group based in Turkey.  This group appears to be loyal to the Erdogan regime and has attacked, with defacement campaigns, in Western Europe and the U.S.  The group was discovered by Wapack analysts during routine collection efforts. This information is being provided for your situational awareness.



Publication date:                          4 October 2016

Handling requirements:                Traffic light protocol (TLP) GREEN

Attribution/Threat Actors:            Turkey-based hacking group

Actor Type:                                   Adversary capabilities have been assessed as Tier IV*

Potential Targets:                          Turkey, Middle East, Western Europe and USA

Past Reporting:                              Red Sky Alliance: DOC-4195

*Criminal or state actors who are organized, highly technical, proficient, well-funded professionals working in teams to discover new vulnerabilities and develop exploits.

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.

Wednesday, October 5, 2016

Exploit Kit Author


Wapack Labs has discovered an exploit kit author, selling within the Dark Web.  Analysts encountered this kit in September 2016, as the most popular/sought after exploit kit amongst Brazilian hackers during the 2016 Rio Olympics.  Wapack Labs analysts often research breaches of cyber security in numerous corporate and government cyber-attack incidents.  This report contains identity, Dox and TTP information of actor - provided for your situational awareness.


Publication date:                        03 October 2016

Handling requirements:            Traffic light protocol (TLP) GREEN

Attribution/Threat Actors:       Russian author

Actor Type:                                 Adversary capabilities have been assessed as Tier IV*

Potential Targets:                       Worldwide individuals, corporation and/or governments

Past Reporting:                           N/A

*Criminal or state actors who are organized, highly technical, proficient, well-funded professionals working in teams to discover new vulnerabilities and develop exploits.

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.


About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.