Showing posts with label ttp. Show all posts
Showing posts with label ttp. Show all posts

Thursday, October 26, 2017

In Search of Router Scanner Used in Cyber Campaign

TLP AMBER ANNOUNCEMENT:  

Wapack Labs has attempted to identify the router scanner used in a cyber campaign conducted by a threat actor group who is believed to be a Chinese hacker group targeting Taiwan and Japan. All of the reports on this group on the Chinese Internet are translations of the June 2017 report by Trend Micro that identified the group. No independent analysis of the group was found, and no references to the name were found that predate the Trend Micro reporting. Searches on the Chinese term for “router vulnerability scanner” all returned the same tool called RouterhunterBR, that was written by a Brazilian security researcher named Jhonathan Davi who lives in Brasilia. Further investigation could confirm this threat actor group's use of this tool by checking whether the targeted routers contained any of the vulnerabilities listed by the tool’s author. The identification of RouterhunterBR as possibly used in this cyber campaign is circumstantial. Further investigation could help confirm the connection if targeted routers were checked for the vulnerabilities that the author stated were searched for by the tool...READ MORE

Wapack Labs has cataloged and reported on Chinese hacking groups in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM
  
This TLP AMBER report is available only to Red Sky Alliance members.

Friday, October 20, 2017

Key Reinstallation Attacks (KRACK)

Wapack Labs has identified a new research paper regarding a Key Reinstallation Attack (KRACK),  a cryptographic attack that can be used to attack all modern Android and Linux-based Wi- Fi routers utilizing the WPA2 protocol - 41% of Android devices are vulnerable to this type of attack. If the attacker is within range of the victim's Wi-Fi, KRACK makes it possible to inject and manipulate data and eavesdrop on communications. This is done by tricking the devices to re-install a zero value for the encryption key. This attack is carried out against the 4-way handshake of the WPA2 protocol. When a client connects to a network, a 4-way handshake between the client and server (router) is performed. A fresh encryption key is then issued and used to encrypt all subsequent traffic. A KRACK attacker tricks the victim into re-installing an already-in-use key. By replaying the cryptographic handshake messages, the cryptographic keys can be re-used. Wapack Labs has observed Linux patches being released and expects major distributions to have updates within the next 24-48 hours. As of yet, there is no available Proof-of-Concept (PoC) code or scanners for this vulnerability. Microsoft has issued a patch, but Apple has not yet publicly addressed this vulnerability. Many router manufacturers have issued public statements, yet no patch information has been provided. An additional concern is that many variations of operating systems are maintained by countless distributors, making the release of patch information a complicated task...READ MORE

Wapack Labs has cataloged and reported on cryptographic attacks in the past. An archive of related reporting can be found in the Red Sky Alliance portal. 

Tuesday, October 10, 2017

Auto-Update Malware Delivery TTP

TLP AMBER ANNOUNCEMENT: 

Malicious Microsoft Word documents are one of the most prevalent malware delivery mechanisms, and typically use embedded Visual Basic (VBA) macros to download and install malware on a victim’s machine. In late August and September 2017, Wapack Labs observed an uptick in an alternative Word doc based malware delivery method being leveraged in malicious email campaigns. The tactic involves using auto-updating links, instead of macros, to download additional malware payloads. Due to the prevalence of Office-based malware delivery, this new method will likely affect multiple industries, including Red Sky Alliance members. This report provides analysis on related specimens, including common artifacts and observed campaigns, as well as a generic mitigation that detects most variants...READ MORE

Wapack Labs has cataloged and reported malware delivery tactics in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

This TLP AMBER report is available only to Red Sky Alliance members.

Friday, March 31, 2017

APT's Code Used Against Global Government Financial Websites

The code, tactics, techniques, and procedures (TTP) used against government financial regulatory websites in Poland, Mexico, and Uruguay are all too similar to be coincidental. These attacks are almost certainly being carried out by a known APT Group. Security researchers in Poland are uncovering artifacts from a recent breach where attackers used that country’s financial regulatory organization’s website to spread malware. Indicators of Compromise (IOCs) that led to the discovery included abnormal network traffic and unknown encrypted executables resident on victim machines. This APT Group has targeted Asian based financial institutions and manufacturing companies since at least 2009; in addition to stealing $81M from global financial institutions. They were also attributed with cyber espionage campaigns. Technical details of the attack in Poland, and mitigations are provided herein...READ MORE

Wapack Labs has cataloged and reported extensively on APT malware in the past. An archive of related reporting can be found in the Red Sky Alliance portal.


WWW.WAPACKLABS.COM

Wednesday, October 5, 2016

Exploit Kit Author


Wapack Labs has discovered an exploit kit author, selling within the Dark Web.  Analysts encountered this kit in September 2016, as the most popular/sought after exploit kit amongst Brazilian hackers during the 2016 Rio Olympics.  Wapack Labs analysts often research breaches of cyber security in numerous corporate and government cyber-attack incidents.  This report contains identity, Dox and TTP information of actor - provided for your situational awareness.


Publication date:                        03 October 2016

Handling requirements:            Traffic light protocol (TLP) GREEN

Attribution/Threat Actors:       Russian author

Actor Type:                                 Adversary capabilities have been assessed as Tier IV*

Potential Targets:                       Worldwide individuals, corporation and/or governments

Past Reporting:                           N/A

*Criminal or state actors who are organized, highly technical, proficient, well-funded professionals working in teams to discover new vulnerabilities and develop exploits.

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.


About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.