Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Thursday, September 13, 2018

CHANNEL 001:CYBER BRIEF: The Missing Link in the Supply Chain Webinar

Introducing a NEW Wapack Labs Monthly Cyber Brief Webinar Series - called 'Channel 001'. We will host a webinar every month on prevailing cyber topics. These webinars are open to everyone and are free to attend. First up, we have a Supply Chain webinar - 'The Missing Link in the Supply Chain'.

September 19th, 10:00 AM EDT REGISTER NOW


In recent years, the global supply chain has become the new "playground for hackers". With chain inherently having numerous links (from suppliers to manufacturers to distributors), the number of potentially exploitable relationships makes it an attractive target. This presentation includes the 'how' and the 'why' of supply chain attacks and describes several notable malware campaigns affecting supply chain in multiple industries.

Viewers will:
• Understand the basic nature of cyber supply chains
• Gain insight into cyber supply chain vulnerabilities
• Learn how to begin protecting our cyber supply chains 


Your presenter Chris Hall, Co-Owner and Principal Engineer at Wapack Labs, has been in the intelligence community for over 18 years in various capacities including SIGINT, network defense, reverse-engineering, and fusion. In 2012, Chris moved from the government to the private sector to help form the Red Sky alliance and then co-found Wapack Labs in 2013. As a partner at Wapack Labs, Chris's main responsibility is to oversee the production, sourcing, and collection of intelligence.

Please join us for this webinar and many more to come. September 19th, 10:00 AM EDT.

REGISTER NOW


Contact Wapack Labs for more information:
603-606-1246, or info@wapacklabs.com 


WWW.WAPACKLABS.COM 

Friday, February 9, 2018

AZORult Stealer

AZORult is a publicly available information-stealing malware that is popular among hackers. AZORult is delivered via phishing e-mails and with the use of Exploit Kits (EK), most notably the Rig EK. It collects information from victims by targeting a variety of applications for credential harvesting. In January 2018, Wapack Labs started analysis of AZORult nodes in an effort to identify stolen data. As part of this research, Wapack Labs gained insight into AZORult Command and Controls (C2). This report includes details on the AZORult malware and provides trending on the identified infrastructure. Wapack Labs analysts were able to recover over a million AZORult logs, which include data on victim IPs, e-mails, credentials, and attack server data. This information is listed in the Wapack Labs Blacklist Slack channel and searchable via our CTAC tool to provide situational awareness...READ MORE

Wapack Labs has cataloged and reported on AZORult malware in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Friday, June 9, 2017

IBNS Malicious Infrastructure Targets Financial Institutions

In the last days of May, Wapack Labs identified a large email delivery infrastructure targeting multiple industries including finance and transportation. Wapack Labs dubbed this network “IBNS”. The infrastructure consists of a single name server and over 17k typo-squatted domains. The size of this recently discovered IBNS network is unprecedented. Wapack Labs believes that IBNS is a malicious provider that uses web automation and reseller services to facilitate their criminal activities. The actors sell through channels, using resellers instead of selling direct, creating a level of separation between themselves and the users. Tactics Techniques and Procedures (TTPs) associated with the activity suggest attribution to a known Nigerian fraud group. 

+++++++++++++++++++++++++++++

I hear every day about the stupid users clicking through, and the CISO that talks about the problem being in the human. Honestly? I get kinda mad when I hear it. Why? These guys are using automated psychology to overwhelm, confuse and take advantage of unsuspecting users.

It means to me that the CISO who said it has never seen well crafted emails meant to slip past the goalie.  Or perhaps they don't understand the idea that users only have so much will power, or that my own out-of-band email account (an AOL account that I've had for probably 20 years) receives far more spam than it does legitimate email.

Bad guys are smart. They know that users have only a limited amount of will power, and after seeing hundreds of spam per day, the idea that some of them are going to be opened —out of sheer exhaustion and confusion, is 100%.

Overwhelm, confuse, create fatigue, repeat, add additional sources of confusion, repeat again.

ONE typosquat dump that we identified had over 17,000 domains that look a heck of a lot like credit card and payment company domains. CapitalOne? Capital1? CapitalONE? Capital-one? My typo squats are terrible but you get the idea. Imagine dozens of variations created programmatically and then used to overwhelm.

Folks, it's not about stupid users. It's about information security folks not understanding the strategy of fatigue and confusion and then how to protect those (your) lambs as they're being lead (by Nigerian scammers, Lazarus actors, or APT) to slaughter.  It's like the door to door salesman that keeps throwing features, prices, and deals at you until you sign just together the guy out of your house.  There's psychology involved.

…and you only need one to slip past the goalie to be infected, and many times, you'll have absolutely no idea that you've been p0wned.

Wapack Labs has been running this thing that we call the Cyber Threat Analysis Center. We scour primary sources to identify intended victims before they become victims. The graphic above is a sample of a report that we provide on a weekly basis to one of our folks. We give them normalized blacklists in periodic chunks of that they can drop into their defenses —either their intrusion prevention systems, SEIM, or whatever they have.  They can wait for us to give it to them or they can pull it programmatically via API on whatever frequency that they desire.

Want to know more? Drop us a note through the website, or at jmckee@wapacklabs.com.

OK folks.. it's our first nice day in a while up here in NH and that lawn (hay field?) isn't going to mow itself.

Oh, before I forget, if you're local, I hope to see some of you at our Granite State Security cookout Monday afternoon… nothing heavy, just burgers and beer but it's supposed to be nice. Let's have some fun! Here's the link to the meet up… I've invited the local Open Source community and security folks.

Have a great weekend!
Jeff




Wednesday, March 22, 2017

Stolen Credit Cards for Sale Via CryptoCheck Payments

A member of a clear web hacker forum is hosting an active website advertising services.  The website provides links to stolen credit/debit card databases from banks around the world.  This individual is linked to an infamous Ukrainian hacker (indicating actor's popularity) who has long specialized in the sale of stolen credit card information.  Services within this website can be purchased via Bitcoin (BTC), Western Union, Money Gram, and by a service called CyptoCheck.  CryptoCheck is a Russian payment service, which is being researched further.

Wapack Labs has cataloged and reported extensively on carding forums in the past. An archive of related reporting can be found in the Red Sky Alliance Portal.

Monday, February 13, 2017

Threats Associated with an Air Traffic Overhaul

Many aviation experts in the U.S. are urging the current administration to draft a plan to privatize the airline traffic control system. It is hoped that privatization would lead to modernization, which would almost certainly include greater use of information technology. We recently reported on airline “computer glitches” at airlines such as Delta, Southwest, United and Air France that were actual hacking incidents. Hackers have broken into FAA air traffic control mission-support systems in the past. The FAA has made improvements in its cybersecurity posture, but a major modernization effort would increase attack surfaces and introduce numerous new vulnerabilities.

Wapack Labs has reported on airline cyber hacking in the past. An archive of related reporting can be found in the Red Sky Alliance Portal.

The following organizations were cited in this report: United, Delta, SWA, & Air France

TLP: AMBER
ACTOR TYPE: (V)
SERIAL: TR-033-2017
COUNTRIES: US, FR, CN, XZ
INDUSTRIES: Transportation, Financial
REPORT DATE: 20170210

Thursday, January 26, 2017

Insider Trading in the Underground

Wapack Lab research has uncovered an underground forum with experienced grey and black hat hackers and coders who specialize and host an “Insider Trading” sub-forum. A variety of hackers and coders make their skills available in the various rooms. The forum claims to have a robust vetting process in place to preclude script kiddies, law enforcement, journalists, IT researchers, and “lurkers.” The Insider Trading forum claims to take advantage of talented users with expertise in advanced math, economics, quantum theories, and business entrepreneurship to facilitate insider trading.

TLP: GREEN
ACTOR TYPE: (V)
SERIAL: TR-017-2017
COUNTRIES: ANY
REPORT DATE: 20170125

Wednesday, January 18, 2017

Italian Hackers and Eye Pyramid Malware

Italian authorities have arrested a brother and sister hacking team in connection with the hacking of over 18,000 emails; to include Italian politicians, Vatican officials, and the European Central Bank. Giulio Occhionero and his sister Francesca Maria are alleged to have committed cyber-crimes which began in 2012. G. Occhionero developed a proprietary keylogger malware named Eye Pyramid. This information is being supplied for your situational awareness.
  • The Eye Pyramid malware operation began in 2012 via the Occhionero’s.
  • Eye Pyramid is keylogger malware which captured over 1,700 passwords.
  • This very basic malware demonstrates the ease of utilization, with high consequences...READ MORE
Publication Date: 11 January 2017
Handling Requirements: Traffic light protocol (TLP) GREEN
Attribution/Threat Actors: Eye Pyramid/Giulio Occhionero, Francesca Maria Occhionero
Actor Type: Adversary capabilities have been assessed as Tier III
Potential Targets: Italian politicians, Vatican officials and European Central Bank
Past Reporting: Red Sky Alliance: DOC-2971, 3331, 3254

The full report may be viewed in the Red Sky Alliance as DOC-4612. 
Contact Wapack Labs for more information.

Tuesday, December 20, 2016

27 Chinese Hackers Profiled


Hacker use information sharing and collaboration, and there is a large community of Chinese coders are doing just that -- exchanging ideas, and tools, and sharing software development. This week, Wapack Labs published a study of 27 of the most active Chinese coders, revealing the some common characteristics of this community:
  • These coders are not lone hackers. They are mostly employed in major corporations or network security entities. This includes Alibaba, TenCent, and Huawei, and security entities KnownSec, Keen Team, and Evil Octal.
  • They are not anonymous. Real names were found for 18 of the 27 coders studied.
  • Many are well known in China and abroad. Several of those studied had more than 400 followers, and one had about 1,800.
  • Many are contributing regularly; Several updating ideas and code more than 200 times over a year period.
In addition, the white-hat posture taken by these coders appears to have been accepted so far by the Chinese government. This community does not appear to fear suppression by the government, similar to the shutdown of the Wooyun vulnerability-hunter website earlier this year.

Publication Date: 8 December 2016
Handling Requirements: Traffic light protocol (TLP) AMBER
Attribution/Threat Actors: Criminal or state actors who are organized, highly technical, proficient, well-funded professionals working in teams to discover new vulnerabilities and develop exploits.
Actor Type: Adversary capabilities have been assessed as Tier IV
Industries Targeted: Multi-industry targets/International
Past Reporting: The full reports may be viewed in Red Sky Alliance as DOC-2098, DOC-4350, and comment-7187.  Contact Wapack Labs for more information.  

Tuesday, December 6, 2016

Nigeria & Cyber Security: Two Steps Forward, One Step Back


Nigeria has long been a haven for highly talented and successful hackers, scammers, and their many spin off groups. Having developed this negative cyber reputation, Nigeria has in recent years enacted cyber laws to combat these groups and help protect their businesses and reputation. These laws were recently used for unfortunate political purposes, yet demonstrate a positive direction toward improved cyber security efforts.
  • Nigeria has a historical negative reputation for cyber hackers and scammers.
  • New cyber security legislation has been enacted to curb cybercrime.
  • Nigeria has recently arrested a popular blogger under the cyber laws, which was viewed as a political more than law enforcement measure.

While our Wapack Labs African Desk sees Nigeria making real progress in cyber security, we still see a country facing an increasing domestic and international threat in all domains of cyber security. When considerations of terrorism and the ongoing Boko Haram activities are brought into the equation, the pursuit of bloggers seems quite petty at best, and at worst, negligently misguided. While Nigeria continues to make very real steps forward in cyber security, it also tends to take a few steps backwards along the way.  This information is being supplied for your situational awareness.

Publication Date: 3 December 2016
Handling Requirements: Traffic light protocol (TLP) GREEN
Attribution/Threat Actors: Hackers & Scammers
Actor Type: Adversary capabilities have been assessed as Tier III
Potential Targets: Worldwide targets using Nigerian networks; connections to terrorism
Past Reporting: DOC-4283, DOC-4002, DOC-4486

The full report is available on our Executive Readboard.