Showing posts with label spear phishing. Show all posts
Showing posts with label spear phishing. Show all posts

Thursday, August 24, 2017

Ursnif Campaign Targets Logistics and Finance

TLP AMBER ANNOUNCEMENT:

Wapack Labs recently identified a large scale Ursnif campaign, affecting multiple companies in the logistics, finance, and IT sectors. The campaign, which began in May 2017, consists of spear-phishing emails with a malicious document attached that, when opened, delivers malware identified as Ursnif. Active since 2012, Ursnif malware has undergone several variations. The current variant implements data exfiltration and sends encrypted victim data to a C2 server. By using compromised accounts and exploiting existing trust relationships, the actors are likely able to achieve a high open-rate. While additional user-interaction is required to enable the malicious macro, it probably resulted in a few installations because the delivery email was not unsolicited. Additionally, the clever social engineering exhibits a moderate to advanced level of tradecraft by the actor. Tactics, Techniques, and Procedures (TTPs) and shared infrastructure in this campaign suggest a single actor or group with Chinese attribution executed this campaign...READ MORE

Wapack Labs has cataloged and reported extensively on spear-fishing, Ursnif, and China in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

This TLP AMBER report is available only to Red Sky Alliance members.

Tuesday, January 17, 2017

Japan Spear Phished by Trojan: BKDR_ChChes

In November 2016, a string of spear phishing attacks targeted Japanese governmental agencies. The Trojan in this attack was dubbed BKDR_ChChes by the anti-virus vendor Trend Miro. Tactics, Techniques, and Procedures (TTP’s) show this was a targeted campaign using custom malware attributed to a known hacking group. Whether the Trojan was developed from the hacking group source code leak in 2015, or if it was designed by the hacking group on behalf of the attackers, is an intelligence gap.


Publication Date: January 10, 2016
Handling Requirements: Traffic light protocol (TLP) AMBER
Attribution/Threat Actors: known hacking group, unknown Chinese threat actors
Actor Type: Adversary capabilities have been assessed as TIER III
Potential Targets: Japanese Government, Worldwide Governments / Worldwide Businesses
Previous Reporting: Red Sky Alliance: DOC-2343

The full report may be viewed in the Red Sky Alliance as DOC-4606. 
Contact Wapack Labs for more information.