Trend Micro discovered a threat actor they named Water Labbu that was targeting cryptocurrency scam websites. Typically, cryptocurrency scammers use social engineering techniques, interacting with victims to gain their trust and then manipulating them into providing the permissions needed to transfer cryptocurrency assets. While Water Labbu managed to steal cryptocurrencies via a similar method by obtaining access permissions and token allowances from their victim’s wallets, unlike other similar campaigns, they did not use any kind of social engineering — at least not directly. Instead, Water Labbu lets other scammers use their social engineering tricks to scam unsuspecting victims.
Executive Summary
Water Labbu is a cryptocurrency-focused threat actor identified by Trend Micro through their unique modus operandi of targeting individuals who have already been scammed by cryptocurrency fraud schemes. Unlike other actors, Water Labbu refrains from direct social engineering; instead, they exploit the trust and permissions provided by victims as a result of being scammed, allowing them to steal cryptocurrencies without directly engaging in phishing or similar tactics.
Goals & Targeting
The primary goal of Water Labbu is to steal cryptocurrencies, capitalizing on existing fraud schemes to target individuals who have been manipulated by other scammers within the cryptocurrency sector. Their targeting profile focuses on sectors and countries where cryptocurrency usage and scams are prevalent, preying on victims who are already in a compromised state.
Enhanced Description
Water Labbu operates by capitalizing on the psychological vulnerability of individuals who have already fallen victim to cryptocurrency scams. Instead of employing social engineering themselves, they wait for other fraudsters to manipulate victims into granting access permissions. By leveraging these compromised trust relationships, Water Labbu gains unauthorized access to victims' crypto assets, effectively piggybacking on the social engineering efforts of other scammers. This method reduces direct risk exposure for Water Labbu but still poses a significant threat to users and financial institutions involved in cryptocurrency transactions.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Water Labbu's campaigns are relatively new and have not been extensively documented. Their operational tempo appears to be reactive, targeting individuals who have recently fallen victim to other scams. Campaigns may involve low-profile activities to avoid detection while achieving their objective of stealing assets.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Water Labbu's intelligence is medium as their operational details are limited. Gaps include exact attack vectors used beyond exploiting compromised permissions and specific tools they employ.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics