Showing posts with label supply chain. Show all posts
Showing posts with label supply chain. Show all posts

Thursday, September 13, 2018

CHANNEL 001:CYBER BRIEF: The Missing Link in the Supply Chain Webinar

Introducing a NEW Wapack Labs Monthly Cyber Brief Webinar Series - called 'Channel 001'. We will host a webinar every month on prevailing cyber topics. These webinars are open to everyone and are free to attend. First up, we have a Supply Chain webinar - 'The Missing Link in the Supply Chain'.

September 19th, 10:00 AM EDT REGISTER NOW


In recent years, the global supply chain has become the new "playground for hackers". With chain inherently having numerous links (from suppliers to manufacturers to distributors), the number of potentially exploitable relationships makes it an attractive target. This presentation includes the 'how' and the 'why' of supply chain attacks and describes several notable malware campaigns affecting supply chain in multiple industries.

Viewers will:
• Understand the basic nature of cyber supply chains
• Gain insight into cyber supply chain vulnerabilities
• Learn how to begin protecting our cyber supply chains 


Your presenter Chris Hall, Co-Owner and Principal Engineer at Wapack Labs, has been in the intelligence community for over 18 years in various capacities including SIGINT, network defense, reverse-engineering, and fusion. In 2012, Chris moved from the government to the private sector to help form the Red Sky alliance and then co-found Wapack Labs in 2013. As a partner at Wapack Labs, Chris's main responsibility is to oversee the production, sourcing, and collection of intelligence.

Please join us for this webinar and many more to come. September 19th, 10:00 AM EDT.

REGISTER NOW


Contact Wapack Labs for more information:
603-606-1246, or info@wapacklabs.com 


WWW.WAPACKLABS.COM 

Tuesday, December 12, 2017

NoobBoy Downloader Campaign

TLP AMBER ANNOUNCEMENT:
 
Starting in mid-October 2017, a new variant of macro downloader malware was leveraged in large-scale fraud driven email campaigns. The attacks appear to target the supply chain of multiple industries and have used an assortment of payloads, including keylogger malware. The common use of the macro variant as well as shared infrastructure and network artifacts indicate a common actor. Wapack Labs has dubbed this activity "NoobBoy" for future tracking. NoobBoy attacks appear to target the supply chain in the shipping, energy and infrastructure sectors. Companies targeted include international companies participating in global markets, including an equipment manufacturer who supplies equipment globally and an oil, gas and mineral resource company that participates in the global marketplace...READ MORE

Wapack Labs has cataloged and reported on macro downloader malware and campaigns in the past. An archive of related reporting can be found in the Red Sky Alliance portal.   

WWW.WAPACKLABS.COM 

This TLP AMBER report is available only to Red Sky Alliance members.

Wednesday, August 16, 2017

Indian Physical Security Company Compromise

TLP AMBER ANNOUNCEMENT: 

On 15 July 2017, Wapack Labs identified, with high confidence, four keylogged email accounts identified as compromised, including username and password, belonging to an Indian physical security company. These email accounts were used to harvest information from multiple internal systems and external portals. Both the sales and customer relationship management systems may have been compromised. Since many of the keylogger infections have spread through automation, there is a potential for compromise within customer, partner, and supply chain relationships...READ MORE

Wapack Labs has cataloged and reported extensively on keyloggers in the past. An archive of related reporting can be found in the Red Sky Alliance portal.
This TLP AMBER report is available only to Red Sky Alliance members.