Showing posts with label infrastructure. Show all posts
Showing posts with label infrastructure. Show all posts

Tuesday, March 16, 2021

Water Treatment Attacks & the Effects of Cyber Attacks on Critical Infrastructure

2021 REDSHORT #11

CYBER INTELLIGENCE REPORT

This week's SPECIAL REDSHORT webinar will be a Team Jaeger PANEL DISCUSSION.  Join us on our webinar to find out more.

Team Jaeger is Red Sky Alliance's underground cyber collection and analysis squad. The panel discussion is on recent Water Treatment Attacks and the effects of cyber attacks on critical infrastructure. 

Joining Team Jaeger for this panel discussion is Joe Fleming, CEO & Jim Conway, Managing Director of Straife Risk Management. Join us on our webinar to find out more.

Friday, February 9, 2018

AZORult Stealer

AZORult is a publicly available information-stealing malware that is popular among hackers. AZORult is delivered via phishing e-mails and with the use of Exploit Kits (EK), most notably the Rig EK. It collects information from victims by targeting a variety of applications for credential harvesting. In January 2018, Wapack Labs started analysis of AZORult nodes in an effort to identify stolen data. As part of this research, Wapack Labs gained insight into AZORult Command and Controls (C2). This report includes details on the AZORult malware and provides trending on the identified infrastructure. Wapack Labs analysts were able to recover over a million AZORult logs, which include data on victim IPs, e-mails, credentials, and attack server data. This information is listed in the Wapack Labs Blacklist Slack channel and searchable via our CTAC tool to provide situational awareness...READ MORE

Wapack Labs has cataloged and reported on AZORult malware in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Tuesday, October 25, 2016

Mauritania: Recent E-mail Scam Exposes Weaknesses

Mauritania, specifically their capital Nouakchott, face numerous cyber challenges to their banking/corporate, government and personal communications due to outside dependence on network infrastructure.  A recent cyber-attack directed towards their Communication Director and his staff demonstrate this vulnerability.  Simple cyber-attacks as this, illustrate weaknesses to many developing African nations; and in reality, many developing nations.  This information is being supplied for your situational awareness.

  • Mauritania and West Africa must rely on outside network providers which present many vulnerabilities.
  • Developing nations face many basic cyber security related challenges.
  • Heightened cyber security education, training and experience is desired for many developing nations.


Publication date:                            21 October 2016

Handling requirements:                  Traffic light protocol (TLP) GREEN

Attribution/Threat Actors:              Stranded Traveler actors

Actor Type:                                     Adversary capabilities have been assessed as Tier II*

Potential Targets:                           Mauritania and neighboring West African nations

Past Reporting:                               Red Sky Alliance: DOC-4365

*Practitioners with a greater depth of experience, with the ability to develop their own tools (from publicly known vulnerabilities).

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.       

Wednesday, October 12, 2016

419 Attackers Leveraging New Undetected Pony Infrastructure for Possible Swift Targeting


Wapack labs analyzed two recent Pony/Fareit downloader samples that were submitted to Virus Total in late September.  The samples provided insight into recently registered attacker infrastructure imitating a number of European, US and Bangladeshi companies.  This infrastructure was recently registered and only one domain is currently detected (low detection) as malicious on Virus Total. Further collection identified additional 2015 and 2016 infrastructure registered by 419 actors imitating banking, US Government, military, and oil and gas organizations.  This PIR provides forewarning on infrastructure that will likely be activated as command and control (C2) in the future.


Publication Date: 7 October 2016

Handling requirementsTraffic light protocol (TLP) AMBER

Attribution/Threat Actors: Criminal

Actor type:  Adversary capabilities have been assessed as Tier 1*

Previous reporting: None

*Practitioners who rely on others to develop the malicious code, delivery mechanisms, and execution strategy (use known exploits). 

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.