Bank-Attack Hackers Use Russian Decoys

The hackers behind a sophisticated attack campaign that has recently targeted financial organisations around the world have intentionally inserted Russian words and commands into their malware in an attempt to throw investigators off.

Researchers from cybersecurity firm BAE Systems have recently obtained and analysed additional malware samples related to an attack campaign that has targeted 104 organisations, most of them banks, from 31 different countries.

They found multiple commands and strings in the malware that appear to have been translated into Russian using online tools, the results making little sense to a native Russian speaker.

"In some cases the inaccurate translations have transformed the meaning of the words entirely," the researchers said in a blog post. 

"This strongly implies that the authors of this attack are not native Russian speakers and, as such, the use of Russian words appears to be a 'false flag'."

This unusual behaviour is most likely intended to make attribution harder and throw investigators on a false lead. In reality there is technical evidence to link these malware samples and the overall attack campaign to a group known in the security industry as Lazarus.

This group has been active since at least 2009 and has been responsible for various attacks against government and private organizations from South Korea and the US over the years.

Lazarus is believed to have been responsible for the 2014 attack against Sony Pictures Entertainment that resulted in sensitive data being leaked from the company and many of the company's computers being rendered inoperable. The FBI and other U.S. intelligence agencies attributed that attack to North Korea.

The Lazarus group has also been linked to the theft of US$81 million from the central bank of Bangladesh last year. In that attack, hackers used malware to manipulate the computers used by the bank to operate money transfers over the SWIFT network. They attempted to move $951 million in total, but some transactions failed and others were successfully reversed after the heist was detected.

Recently a malware attack that affected multiple banks in Poland came to light. The attack is believed to have involved exploits launched from the compromised website of the Polish Financial Supervision Authority.

Researchers from BAE Systems and Symantec have tied the Polish attack to a larger campaign that has been going on since October and involved multiple watering-hole-style compromises. The websites of the National Banking and Stock Commission of Mexico and the largest state-owned bank from Uruguay have also been infected in a similar manner.

The malware programs used in these attacks bear code similarities to tools attributed in the past to the Lazarus group.

There are several cyber-criminal gangs of Russian origin that specialise in targeting banks. These groups use spear-phishing to gain a foothold into banks' networks and then learn the organisations' internal procedures before they begin to steal money. 
BAE Systems' research suggests that Lazarus might be trying to make its activity blend in with that of these Russian-speaking cyber-criminals.

Computerworld:

Banks Lack Confidence They Can Detect Data Breaches:

Security Directly Impacts The Bottom Line At Banks:

 

« Estonian Honey Trap
Keeping The Cloud Safe: Exclusive Report »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

QATestLab

QATestLab

QATestLab is a leading International software testing company offering a full range of software testing services including security testing.

DG Technology

DG Technology

DG Technology is a customer-centric technology expert and business consultant that delivers services and products to minimize your information security, compliance, and business risks.

Swiss CyberSecurity

Swiss CyberSecurity

Swiss CyberSecurity is a non-profit group based in Geneva, set up to provide information and as a forum for discussion of topics related to CyberSecurity.

Ravelin Technology

Ravelin Technology

Ravelin prevents chargebacks, fraud, and account takeover. Machine learning and human insight combine for highly accurate fraud detection and prevention.

Sectra Communications

Sectra Communications

Sectra successfully develops and sells cutting-edge solutions in the expanding niche segments of medical IT and cybersecurity.

Vortiv

Vortiv

Vortiv Ltd (formerly known as Transaction Solutions International Ltd) is a technology based company focused on the cybersecurity and the cloud services sector.

doIT Solutions

doIT Solutions

doIT solutions specialize in IT security and infrastructure, security automation, data center, and cybersecurity.

Xalient

Xalient

Xalient is an IT consulting and managed services business, specialising in modern, software-defined networking, security and communications technologies.

Seemplicity

Seemplicity

Seemplicity revolutionizes the way security teams work by automating, optimizing and scaling all risk reduction workflows in one workspace.

Guardey

Guardey

Guardey protects thousands of SME's environments. Whether your team works at the office, at home, at the customer or remotely. We protect your business. We do this in an accessible and affordable way.

Endure Secure

Endure Secure

Endure Secure is a managed cyber security & information security consultancy. Our passion for IS and our understanding of the threat landscape is reflected in the services that we provide.

GISEC Global

GISEC Global

GISEC Global provides vendors and companies from around the world with access to lucrative opportunity to capitalize on what's set to become one of the world's booming markets.

Bulletproof Solutions

Bulletproof Solutions

Bulletproof provides IT expert support, services, and guidance to businesses small and large as they grow and adapt to today’s complex IT, cybersecurity, and compliance needs.

2021.AI

2021.AI

2021.AI serves the growing business need for full oversight and management of applied AI.

Silobreaker

Silobreaker

Silobreaker is a SaaS platform that enables threat intelligence teams to produce high-quality and relevant intelligence at a faster pace.

Ryan Financial Lines

Ryan Financial Lines

Ryan Financial Lines Cyber provides risk transfer solutions for complex cyber and technology exposures, globally.