Showing posts with label threat actor. Show all posts
Showing posts with label threat actor. Show all posts

Thursday, July 20, 2017

Financially Motivated APT-style Actors Target Retail & Hospitality

A new wave of financially motivated, APT-style group, of cyber threat actors are targeting large restaurant chains with phishing emails containing malicious attachments. As early as April 2017, a new wave of the group's activity has been targeting the retail and hospitality sectors. The APT-style group has been active since 2015 and is known for their use of the Carbanak malware. The most recent campaigns leverage two new RTF droppers to deliver a variant of a known backdoor. Early campaigns were known for targeting financial institutions and banks; in 2015, targeting European banks through a banking application called the Internet Front End Banking System (iFOBS). This report describes TTPs leveraged in the recent campaigns...READ MORE

Wapack Labs has cataloged and reported extensively on APTs, cyber threat actors, phishing, malware, financial institutions, and Carbanak in the past. An archive of related reporting can be found in the Red Sky Alliance portal.



Saturday, October 8, 2016

Threat Actor Offers Variety of Tools for Free

Wapack analysts have observed a threat actor who has been advertising his coding abilities (and potential services) in both the public Internet and the dark web. The threat actor typically writes his programs in Python, uses Kali Linux and also appears to be able to speak Japanese. Wapack analysts have observed the threat actor using several OPSEC techniques indicating that he is more sophisticated than script kiddie-level (novice or beginner) threat actors.

Publication date:                            6 October 2016

Handling requirements:                  Traffic light protocol (TLP) GREEN

Attribution/Threat Actors:              N/A

Actor Type:                                     Adversary capabilities have been assessed as Tier II*

Potential Targets:                            N/A

Past Reporting:                                N/A

*Practitioners with a greater depth of experience, with the ability to develop their own tools (from publicly known vulnerabilities). 

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.