Wednesday, November 16, 2016

Russian Hacker Monetizes Traffic

A Russian hacker has been operating in the Russian underground for over 10 years; carrying out activities that range from stealing and distributing credit card data to hacking pharmacy-related websites in order to monetize their traffic. Known actor was observed working with another Russian speaking hacker, which possibly connects actor to the gang that operated several botnets.

Thursday, November 10, 2016

@AnPoland and the Bradley Foundation

On 29 October 2016, Anonymous Poland (@AnPoland) claimed to have hacked and downloaded e-files from the Bradley Foundation (BF).  A letter was posted by numerous Anonymous groups which presented a letter explaining a donation of $150 million USD made by the Rothschild Assets Management Company, through the BF, to the Hillary Clinton Campaign.  BF, a traditional conservative foundation, is currently claiming that the posted letter is a fake.  This information is being provided for your situational awareness.

  • Anonymous Poland (@AnPoland) was created during 2016 Summer Olympics to hack the World Anti-doping Administration.
  • Wapack Labs assesses with moderate confidence that AnPoland is Russian APT.
  • Anonymous Poland was the first to report the hack of the Bradley Foundation, placing moderate confidence they are responsible.

Publication date:                           4 November 2016
Handling requirements:               Traffic light protocol (TLP) GREEN
Attribution/Threat Actors:          Anonymous Poland [suspected Russian APT]

Actor Type:                                    Adversary capabilities have been assessed as Tier IV*

Potential Targets:                          Bradley Foundation (other U.S. politically tied foundations)

Past Reporting:                             DOC-4287, DOC-4211

*States with the ability to successfully execute full spectrum (cyber capabilities in combination with all of their military and intelligence capabilities) operations to achieve a specific outcome in political, military, economic, etc. domains and apply at scale.

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.


Wednesday, November 9, 2016

Cyber in Nigeria: Local Hub of Crime with Deep Roots


Nigeria continues to be known globally as the lead in Internet scams.  The Nigerian government has stepped up efforts to combat these crimes and recently arrested “Mike” who headed the infamous cyber hacking group using 419 scams.   Mike is alleged to be a major operator within a global network of cybercriminals that included money laundering in the U.S., Europe and China.   This information is being supplied for your situational awareness.
  • Nigerian 419 scams have evolved into a wider range of cybercrime and terrorist support.
  • Worldwide militant extremists often take every advantage in the unstable cyber environment.
  • A recent Nigerian arrest shines a spotlight on their old problem, yet shows positive international solutions.

Publication date:                   5 November 2016
Handling requirements:       Traffic light protocol (TLP) GREEN
Attribution/Threat Actors:   419 type Nigerian hacker group (collusion w/Boko Haram)
Actor Type:                            Adversary capabilities have been assessed as Tier III*
Potential Targets:                  Worldwide unsuspecting victims
Past Reporting:                      DOC-3993, DOC-4283, DOC-3931
 
* Practitioners who focus on the discovery and use of unknown malicious code, are adept at installing user and kernel mode root kits10, frequently use data mining tools, target corporate executives and key users (government and industry) for the purpose of stealing personal and corporate data with the expressed purpose of selling the information to other criminal elements.

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.