Bank-Attack Hackers Use Russian Decoys

The hackers behind a sophisticated attack campaign that has recently targeted financial organisations around the world have intentionally inserted Russian words and commands into their malware in an attempt to throw investigators off.

Researchers from cybersecurity firm BAE Systems have recently obtained and analysed additional malware samples related to an attack campaign that has targeted 104 organisations, most of them banks, from 31 different countries.

They found multiple commands and strings in the malware that appear to have been translated into Russian using online tools, the results making little sense to a native Russian speaker.

"In some cases the inaccurate translations have transformed the meaning of the words entirely," the researchers said in a blog post. 

"This strongly implies that the authors of this attack are not native Russian speakers and, as such, the use of Russian words appears to be a 'false flag'."

This unusual behaviour is most likely intended to make attribution harder and throw investigators on a false lead. In reality there is technical evidence to link these malware samples and the overall attack campaign to a group known in the security industry as Lazarus.

This group has been active since at least 2009 and has been responsible for various attacks against government and private organizations from South Korea and the US over the years.

Lazarus is believed to have been responsible for the 2014 attack against Sony Pictures Entertainment that resulted in sensitive data being leaked from the company and many of the company's computers being rendered inoperable. The FBI and other U.S. intelligence agencies attributed that attack to North Korea.

The Lazarus group has also been linked to the theft of US$81 million from the central bank of Bangladesh last year. In that attack, hackers used malware to manipulate the computers used by the bank to operate money transfers over the SWIFT network. They attempted to move $951 million in total, but some transactions failed and others were successfully reversed after the heist was detected.

Recently a malware attack that affected multiple banks in Poland came to light. The attack is believed to have involved exploits launched from the compromised website of the Polish Financial Supervision Authority.

Researchers from BAE Systems and Symantec have tied the Polish attack to a larger campaign that has been going on since October and involved multiple watering-hole-style compromises. The websites of the National Banking and Stock Commission of Mexico and the largest state-owned bank from Uruguay have also been infected in a similar manner.

The malware programs used in these attacks bear code similarities to tools attributed in the past to the Lazarus group.

There are several cyber-criminal gangs of Russian origin that specialise in targeting banks. These groups use spear-phishing to gain a foothold into banks' networks and then learn the organisations' internal procedures before they begin to steal money. 
BAE Systems' research suggests that Lazarus might be trying to make its activity blend in with that of these Russian-speaking cyber-criminals.

Computerworld:

Banks Lack Confidence They Can Detect Data Breaches:

Security Directly Impacts The Bottom Line At Banks:

 

« Estonian Honey Trap
Keeping The Cloud Safe: Exclusive Report »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Orolia

Orolia

Orolia are experts in deploying high precision GPS time through network infrastructure to synchronize critical operations.

Electus Recruitment Solutions

Electus Recruitment Solutions

Electus is a leading recruitment specialist in the Engineering, Technology & Digital and Cyber & Security sectors.

TEISS

TEISS

Teiss.co.uk is a website dedicated to providing information about cyber security. TEISS also provide a series of conferences and events focused on cyber security.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

CRYPTTECH

CRYPTTECH

CRYPTTECH specializes in Information Security and Intelligence, Risk Evaluation and Vulnerability Recognition against Cyber-Attacks and APTs.

APT Search

APT Search

APT Search is a recruitment company specialising within the Legal Technology, Cybersecurity and Privacy sectors.

CPP Group UK

CPP Group UK

CPP Group UK develops products to help insurers add further value to their products and services through its innovative suite of new products in FinTech, InsurTech and cyber security.

Sequoia Capital

Sequoia Capital

Sequoia Capital is a venture capital firm focused mainly on technology. We partner both with young companies finding their stride and established ones looking for growth.

Raqmiyat

Raqmiyat

Raqmiyat provides end-to-end IT Services and business solutions including consultancy, digital transformation, infrastructure and cybersecurity.

Robert Walters

Robert Walters

Robert Walters is one of the world's leading global specialist professional recruitment and recruitment process outsourcing consultancies.

Towerwall

Towerwall

Towerwall offers a comprehensive suite of security services and solutions using best-of-breed tools and information security services.

ActZero

ActZero

ActZero’s security platform leverages proprietary AI-based systems and full-stack visibility to detect, analyze, contain, and disrupt threats.

Digitale Gründerinitiative Oberpfalz (DGO)

Digitale Gründerinitiative Oberpfalz (DGO)

Digital Founder Initiative Oberpfalz's goal is to build a sustainable start-up culture in the field of digitization throughout the Upper Palatinate district of Bavaria.

ViewDS Identity Solutions

ViewDS Identity Solutions

ViewDS Identity Solutions develops innovative identity software including cloud identity management solutions, directory services, access and authorization management solutions.

Bastion Technologies

Bastion Technologies

All your cyber defense. One platform. Keep your business assets and employees safe under one roof. Manage your cyber defense quickly, easily & efficiently.

Interpres Security

Interpres Security

Interpres Security operationalizes TTP-based threat intelligence and automates continuous exposure monitoring to help CISOs and security practitioners reduce threat exposure.