Showing posts with label malicious email. Show all posts
Showing posts with label malicious email. Show all posts

Wednesday, December 13, 2017

Fraudulent Banking Website Part of Larger BEC Infrastructure

TLP AMBER ANNOUNCEMENT:

Business Email Compromise scams (BEC or BES) are a lucrative way for cybercriminals to gain high value credentials and commit fraud. Losses resulting from BEC scams surpassed 5 billion dollars this year and rising. BEC scams target groups and individuals by masquerading as legitimate services and organizations. Recent activity in Iceland involves the use of a fake website with ties to a larger infrastructure of domains designed for use in BEC scams. In this incident over 100 people were victimized with the use of the fake website, tricking victims into giving up financial credentials. These scams are difficult to defend against because they rely on social engineering and deceit instead of malware that can be detected by early warning software. The best defense against BEC scams is information sharing and networking...READ MORE

Wapack Labs has cataloged and reported on Business Email Compromise scams in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

This TLP AMBER report is available only to Red Sky Alliance members.

Tuesday, October 10, 2017

Auto-Update Malware Delivery TTP

TLP AMBER ANNOUNCEMENT: 

Malicious Microsoft Word documents are one of the most prevalent malware delivery mechanisms, and typically use embedded Visual Basic (VBA) macros to download and install malware on a victim’s machine. In late August and September 2017, Wapack Labs observed an uptick in an alternative Word doc based malware delivery method being leveraged in malicious email campaigns. The tactic involves using auto-updating links, instead of macros, to download additional malware payloads. Due to the prevalence of Office-based malware delivery, this new method will likely affect multiple industries, including Red Sky Alliance members. This report provides analysis on related specimens, including common artifacts and observed campaigns, as well as a generic mitigation that detects most variants...READ MORE

Wapack Labs has cataloged and reported malware delivery tactics in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

This TLP AMBER report is available only to Red Sky Alliance members.

Thursday, August 18, 2016

Malicious Infrastructure Targeting Multiple Sectors – Possible Keylogger Connection


On 12 August, 2016, Wapack Labs analysts discovered a new malicious email within its keylogger collections that appear to target entities in the maritime sector. Wapack Labs believes that the email is part of a larger infrastructure targeting entities in various sectors including maritime, logistics, and energy.



Publication date: 17 August 2016; information cutoff date: 12 August 2016
Handling requirements: Traffic light protocol (TLP) AMBER. 
Attribution/Threat Actors: Unknown
Industries Targeted: Maritime
Previous Reporting: N/A

Companies mentioned in this report:

  • CMA-CGM 
  • Spar Shipping
  • Exxon Mobile
  • Alek Shipping
  • Royal Blue
  • Amos Connect
  • Trafigura
  • Liebherr Group
  • Toyo Sangyo
  • Comeca Group
  • GM Ships
  • Expo Freight
  • Bunge
  • Dolphin Kuwait
  • Global Logistics
  • SAK & Associates
This report was published in its entirety to the Financial Services ISAC and Red Sky Alliance portal on August 18, 2016.  For more information, contact Wapack Labs at 844-4-WAPACK.