Showing posts with label network. Show all posts
Showing posts with label network. Show all posts

Monday, October 2, 2017

Browser-Side JavaScript Miners Affect Computer Performance

Browser-side mining of cryptocurrencies, which uses parallel processing CPU power for profit, was developed in the 2011-2014 time-frame. In September 2017, it was distinguished as part of malicious campaigns. Some content providers test this technology as a way to monetize their traffic. The SafeBrowse Chrome extension was allegedly hacked to include a mining functionality. These mining scripts pose a moderate cyber threat, as they significantly slow down the computer while the page is open in the browser. Detecting these malvertising campaigns and disabling mining scripts is advised...READ MORE

Wapack Labs has cataloged and reported extensively on mining cryptocurrencies in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Thursday, August 17, 2017

Compromised Brazilian Government Account Advertising Hacker Shops

Wapack Labs' “Operation 8-ball” identified a hacker forum being advertised through a compromised government email account located in Para, Brazil. One of the advertised hacker shop domains was also tweeted by a novice, Canadian carder. Originating IPs were located in Kosovo. Kosovo is listed in the hacker forum's WHOIS data. The exact attribution for the Brazilian government compromise is absent...READ MORE

Wapack Labs has cataloged and reported extensively on compromised accounts and hacker forums in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Friday, June 9, 2017

IBNS Malicious Infrastructure Targets Financial Institutions

In the last days of May, Wapack Labs identified a large email delivery infrastructure targeting multiple industries including finance and transportation. Wapack Labs dubbed this network “IBNS”. The infrastructure consists of a single name server and over 17k typo-squatted domains. The size of this recently discovered IBNS network is unprecedented. Wapack Labs believes that IBNS is a malicious provider that uses web automation and reseller services to facilitate their criminal activities. The actors sell through channels, using resellers instead of selling direct, creating a level of separation between themselves and the users. Tactics Techniques and Procedures (TTPs) associated with the activity suggest attribution to a known Nigerian fraud group. 

+++++++++++++++++++++++++++++

I hear every day about the stupid users clicking through, and the CISO that talks about the problem being in the human. Honestly? I get kinda mad when I hear it. Why? These guys are using automated psychology to overwhelm, confuse and take advantage of unsuspecting users.

It means to me that the CISO who said it has never seen well crafted emails meant to slip past the goalie.  Or perhaps they don't understand the idea that users only have so much will power, or that my own out-of-band email account (an AOL account that I've had for probably 20 years) receives far more spam than it does legitimate email.

Bad guys are smart. They know that users have only a limited amount of will power, and after seeing hundreds of spam per day, the idea that some of them are going to be opened —out of sheer exhaustion and confusion, is 100%.

Overwhelm, confuse, create fatigue, repeat, add additional sources of confusion, repeat again.

ONE typosquat dump that we identified had over 17,000 domains that look a heck of a lot like credit card and payment company domains. CapitalOne? Capital1? CapitalONE? Capital-one? My typo squats are terrible but you get the idea. Imagine dozens of variations created programmatically and then used to overwhelm.

Folks, it's not about stupid users. It's about information security folks not understanding the strategy of fatigue and confusion and then how to protect those (your) lambs as they're being lead (by Nigerian scammers, Lazarus actors, or APT) to slaughter.  It's like the door to door salesman that keeps throwing features, prices, and deals at you until you sign just together the guy out of your house.  There's psychology involved.

…and you only need one to slip past the goalie to be infected, and many times, you'll have absolutely no idea that you've been p0wned.

Wapack Labs has been running this thing that we call the Cyber Threat Analysis Center. We scour primary sources to identify intended victims before they become victims. The graphic above is a sample of a report that we provide on a weekly basis to one of our folks. We give them normalized blacklists in periodic chunks of that they can drop into their defenses —either their intrusion prevention systems, SEIM, or whatever they have.  They can wait for us to give it to them or they can pull it programmatically via API on whatever frequency that they desire.

Want to know more? Drop us a note through the website, or at jmckee@wapacklabs.com.

OK folks.. it's our first nice day in a while up here in NH and that lawn (hay field?) isn't going to mow itself.

Oh, before I forget, if you're local, I hope to see some of you at our Granite State Security cookout Monday afternoon… nothing heavy, just burgers and beer but it's supposed to be nice. Let's have some fun! Here's the link to the meet up… I've invited the local Open Source community and security folks.

Have a great weekend!
Jeff




Monday, March 20, 2017

Circling the Wagons Against Apache Struts2 0-Day

Apache Struts is an open source framework for creating Java applications. A new Apache Struts 0-day is currently being exploited in the wild. Multiple variants of attack code, as well as pastes of Proof of Concept (PoC) code, have already been discovered in open sources. The Apache Struts2 vulnerability affects numerous industries and potentially worldwide critical infrastructure. We assess with high confidence that the Apache Struts2 vulnerability will continue to be heavily exploited until network systems are patched. Members are highly encouraged to implement countermeasures and install patches as soon as possible.

Wapack Labs has cataloged and reported extensively on Apache Struts in the past. An archive of related reporting can be found in the Red Sky Alliance portal in the Red Sky Alliance Portal.

WWW.WAPACKLABS.COM

Thursday, November 17, 2016

Morocco: Business in Sub-Saharan Africa

Morocco has recently initiated the Octopus Development Plan: an economic strategy designed to better assist Senegal.  Experts believe the underlying purpose for this plan is to further link banking and communication industries under Morocco and the United Arab Emirates (UAE) conglomerates.  The ability to control, disrupt or influence banking and communications on these networks by extremists or radicals is a major concern.  This information is being supplied for your situational awareness.
  • Morocco is a major investor and developer in the banking and telecommunications industries in Africa.
  • The Octopus Development Plan will further expand their interests in banking and communication is Western Africa.
  • The United Arab Emirates and Morocco own controlling interests in the banking and communications industries in Northern, Western, and Sub Saharan Africa.

Publication Date:                    14 November 2016
Handling Requirements:        Traffic light protocol (TLP) GREEN
Attribution/Threat Actors:     Unknown
Actor Type:                              Adversary capabilities have been assessed as Tier II*
Potential Targets:                    Morocco, West Africa and Sub Saharan Africa
Past Reporting:                        DOC-4360, DOC-4423

* Practitioners with a greater depth of experience, with the ability to develop their own tools (from publicly known vulnerabilities).


The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.

Tuesday, October 25, 2016

Mauritania: Recent E-mail Scam Exposes Weaknesses

Mauritania, specifically their capital Nouakchott, face numerous cyber challenges to their banking/corporate, government and personal communications due to outside dependence on network infrastructure.  A recent cyber-attack directed towards their Communication Director and his staff demonstrate this vulnerability.  Simple cyber-attacks as this, illustrate weaknesses to many developing African nations; and in reality, many developing nations.  This information is being supplied for your situational awareness.

  • Mauritania and West Africa must rely on outside network providers which present many vulnerabilities.
  • Developing nations face many basic cyber security related challenges.
  • Heightened cyber security education, training and experience is desired for many developing nations.


Publication date:                            21 October 2016

Handling requirements:                  Traffic light protocol (TLP) GREEN

Attribution/Threat Actors:              Stranded Traveler actors

Actor Type:                                     Adversary capabilities have been assessed as Tier II*

Potential Targets:                           Mauritania and neighboring West African nations

Past Reporting:                               Red Sky Alliance: DOC-4365

*Practitioners with a greater depth of experience, with the ability to develop their own tools (from publicly known vulnerabilities).

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.