Showing posts with label underground. Show all posts
Showing posts with label underground. Show all posts

Wednesday, December 6, 2017

Underground Market Selling Stolen Credit Cards

Wapack Labs recently identified a new private underground market. The market is targeting Amazon buyer gift cards and is also selling cloned credit and debit cards. The market only accepts Bitcoin as payment for these stolen goods and ships worldwide. It offers unique discreet shipping methods of cloned credit cards at different price points: $15 to mail the card in a birthday card, $25 to stuff the card inside a teddy bear, $50 to hide the card inside a calculator, and $100 to hide the card in non-working smartphone. They also offer a service that involves sending the product to abandoned houses or to a neighbor’s house. These physical delivery methods show diverse stolen credit card smuggling innovations. Each cloned card has a $4,000 - $7,000 balance with the correct PIN and a daily $500.00 cash withdrawal limit or $3,000.00 on line spending limit...READ MORE

Wapack Labs has cataloged and reported on underground markets and credit card theft in the past. An archive of related reporting can be found in the Red Sky Alliance portal. 

Friday, November 17, 2017

New Underground Market

Wapack Labs recently observed a new underground market that trades a variety of illegal goods including credit cards, fullz, exploits, botnet builders/installs, and other cyber crime related goods. The forum’s structure and listings resemble another well-known market and may be owned by the same individuals. One seller in the market is selling GozNym 2.0 botnet installs. This seller is selling this botnet on other Tor-based black markets and is operating under same alias. The fraud sections of the market are extremely active. Despite being heavily dominated by drugs and other illegal non-cyber sales, these cyber fraud-based sellers appear highly rated. Wapack Labs has discovered that most high-rated sellers primarily deal with stolen discount gift cards obtained through carding, or with stolen electronic goods, such as like-new Apple and Samsung products. Additionally, this level of fraud sellers are often observed making bulk sales of bank accounts and credit cards...READ MORE

Wapack Labs has cataloged and reported on underground Tor markets in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Monday, October 23, 2017

Anonymous Sub-Group

A small sub-group of the Anonymous collective has recently initiated underground offerings of hackers-for-hire. The group is known for their past experiences in website defacement and for their participation in #opISIS, #OpIceISIS, #OpKillingBay, and #OpFunKill, which are all official Anonymous operations. The group has a forum based on Tor, which is believed to be for clients to interact with the team, however, no clients have yet posted. Wapack Labs believes the leader and founder of the group has advanced hacking skills. His Instagram and Twitter accounts provide several videos exposing DDoS attacks against websites. The group's leader also has used numerous aliases, which are provided in the report. He was once a member of several other groups, including, Powerful Greek Army (P.G.A), Phantom Squad, and Zero0d3. Wapack Labs will continue to monitor the group, their leader, and their hacker- for-hire Tor based service...READ MORE

Wapack Labs has cataloged and reported on Tor based groups and threat actors in the past. An archive of related reporting can be found in the Red Sky Alliance portal. 

WWW.WAPACKLABS.COM

Monday, September 25, 2017

New Tor Forum Recruiting Members

On 21 September 2017, Wapack labs observed a new tor based forum. The discovery was made while monitoring another space where members post and review dark web markets. The forum is recently new and has three main discussion sections within the forum: Drugs, Fraud, and General. With the forum recently opening for registration, the number of members is likely to grow. If members from other forums have migrated to the new forum, it has potential to become a reliable replacement market on the dark web. Wapack Labs will monitor the new forum and report on any activities affecting Red Sky Alliance members...READ MORE 

Wapack Labs has cataloged and reported extensively on Tor forums and markets in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

TOR "Skimmer Shop"


On 20 September 2017, Wapack Labs observed a Tor site selling a variety of credit card skimming devices. The owners of the Tor site claim to produce and modify all the products in their own workshops, which are purported to be located in the U.S. and Europe. The website states the business began in early 2015 and now consists of eleven (11) technically trained employees. The skimmer shop sells a variety of skimmers based on the shopper’s interests. The website presents various skimmer sections: ATM, gas pump, GSM (Global System for Mobile communication) receivers, POS, RFID, readers, and other skimmer accessories. Prices range from $800.00 USD to $1800.00 USD, depending on the skimmer wanted. Wapack Labs will continue to monitor this dark net skimmer shop in attempt to identify and monitor the threat actors and their activities...READ MORE

Wapack Labs has cataloged and reported extensively on Tor network shops in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Wednesday, April 26, 2017

Assessing the Multiple Personalities of an APT Actor

Wapack Labs assesses with medium confidence that an identified Advanced Persistent Threat (APT) "group" is actually a lone, nefarious actor using numerous personas. The "group's" forum was rumored to be operated by a foreign military unit and used as a place to re-sell data no longer needed to conduct operations. During the months of March and April 2017, Wapack Analysts observed the lone actor's activities across multiple underground forums and were able to tie said activities to aliases used by other group members...READ MORE

Wapack Labs has cataloged and reported extensively on APT's in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Tuesday, April 18, 2017

New Kids on the Block

Wapack Labs is researching a new card vendor in the underground going by the name “18th Street Gang Shop” (18SGS). The actual 18th Street Gang is one of the largest youth gangs in the western hemisphere, and has close ties to the Mexican Mafia. It is unclear if the actual street gang is operating this site or if someone is co-opting their name. Users may visit the 18SGS shop, create a free account, and access their stolen credit card database. Wapack Labs filtered records and discovered thousands of credit cards belonging to numerous U.S. banks and one major home improvement store.

Wapack Labs has cataloged and reported extensively on hackers and carders in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Tuesday, March 14, 2017

AlphaBay: Avenue on the “new” Silk Road?

Carding forum AlphaBay’s (AB) rules, posted on Twitter, have sparked debate in the underground that the forum is controlled by malicious actors in Russia. Rumors of AB being linked to Russian organized crime are not new, but rules prohibiting malware that targets Russian citizens or the sale of financial information on Russian citizens lends credence to such claims. Russian carding forums routinely include rules of this type to avoid drawing the attention of Russian authorities. AB’s adoption of such rules can only help them in their efforts to become the dominant underground marketplace for illicit goods and activities online. 

Wapack Labs has cataloged and extensively reported on Russian cyber activity in the past. An archive of related reporting can be found in the Red Sky Alliance Portal.

WWW.WAPACKLABS.COM

Tuesday, December 20, 2016

PayPal Balance Reseller en Espanol


A member of a Spanish speaking underground forum is promoting a PayPal balance transfer/payback scheme to clients. This type of financial transaction is illegal and commonly supported by illicit funds. The forum member operates in Latin America, yet promotes business in worldwide Spanish forums. This report is being provided for your situational awareness.
  • Spanish forum supports malicious cyber tools and activity.
  • Spanish forum member operates in Mexico, Central, and South America
  • Spanish forum member accepts payments via Bitcoin, Western Union and OXXO. 
Forum member prefers to communicate via Facebook and accepts payments via Bitcoin, Western Union, and OXXO (a chain of convenience stores from Mexico with over 14,000 stores across Latin America. It also offers money wire transferring services like Western Union). We assess with high confidence that this forum member lives in Latin America, likely Mexico.

Publication Date: 16 December 2016
Handling Requirements: Traffic light protocol (TLP) GREEN
Attribution/Threat Actors: PayPal balance transfer scheme
Actor Type: Adversary capabilities have been assessed as Tier II
Potential Targets: Financial and PayPal
Past Reporting: The full reports may be viewed in Red Sky Alliance as DOC-3969.  Contact Wapack Labs for more information.  

Saturday, December 10, 2016

Black Hat Hackers: Counterfeit Coupons

Wapack Labs research into the hacker underground has uncovered a group of black hat hackers who claim to have taken over a coupon counterfeiting business. This black hat collective may have an affiliation with another threat actor who operated in the dark web marketplace, SilkRoad, and was sentenced to prison for selling counterfeit coupons. This information is being provided for your situational awareness. 
  • Collective is a self-described all female, black hat hacking group.
  • Collective appears to have taken over coupon counterfeiting cyber business.
  • Collective offers a variety of counterfeit coupons to be exploited at self-checkout lanes in retail stores.

Publication Date: 7 December 2016
Handling Requirements: Traffic light protocol (TLP) GREEN
Attribution/Threat Actors: Black Hat Hacking Collective
Actor Type: Adversary capabilities have been assessed as Tier II
Potential Targets: Financial, business and retail sectors
Past Reporting: Msg/#8168 & 8722