Bank-Attack Hackers Use Russian Decoys

The hackers behind a sophisticated attack campaign that has recently targeted financial organisations around the world have intentionally inserted Russian words and commands into their malware in an attempt to throw investigators off.

Researchers from cybersecurity firm BAE Systems have recently obtained and analysed additional malware samples related to an attack campaign that has targeted 104 organisations, most of them banks, from 31 different countries.

They found multiple commands and strings in the malware that appear to have been translated into Russian using online tools, the results making little sense to a native Russian speaker.

"In some cases the inaccurate translations have transformed the meaning of the words entirely," the researchers said in a blog post. 

"This strongly implies that the authors of this attack are not native Russian speakers and, as such, the use of Russian words appears to be a 'false flag'."

This unusual behaviour is most likely intended to make attribution harder and throw investigators on a false lead. In reality there is technical evidence to link these malware samples and the overall attack campaign to a group known in the security industry as Lazarus.

This group has been active since at least 2009 and has been responsible for various attacks against government and private organizations from South Korea and the US over the years.

Lazarus is believed to have been responsible for the 2014 attack against Sony Pictures Entertainment that resulted in sensitive data being leaked from the company and many of the company's computers being rendered inoperable. The FBI and other U.S. intelligence agencies attributed that attack to North Korea.

The Lazarus group has also been linked to the theft of US$81 million from the central bank of Bangladesh last year. In that attack, hackers used malware to manipulate the computers used by the bank to operate money transfers over the SWIFT network. They attempted to move $951 million in total, but some transactions failed and others were successfully reversed after the heist was detected.

Recently a malware attack that affected multiple banks in Poland came to light. The attack is believed to have involved exploits launched from the compromised website of the Polish Financial Supervision Authority.

Researchers from BAE Systems and Symantec have tied the Polish attack to a larger campaign that has been going on since October and involved multiple watering-hole-style compromises. The websites of the National Banking and Stock Commission of Mexico and the largest state-owned bank from Uruguay have also been infected in a similar manner.

The malware programs used in these attacks bear code similarities to tools attributed in the past to the Lazarus group.

There are several cyber-criminal gangs of Russian origin that specialise in targeting banks. These groups use spear-phishing to gain a foothold into banks' networks and then learn the organisations' internal procedures before they begin to steal money. 
BAE Systems' research suggests that Lazarus might be trying to make its activity blend in with that of these Russian-speaking cyber-criminals.

Computerworld:

Banks Lack Confidence They Can Detect Data Breaches:

Security Directly Impacts The Bottom Line At Banks:

 

« Estonian Honey Trap
Keeping The Cloud Safe: Exclusive Report »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

NextLabs

NextLabs

NextLabs provides data-centric security software to protect business-critical data and applications.

ASU Online - Information Technology Program

ASU Online - Information Technology Program

The Information Technology program at ASU Online provides you with the expertise to design, select, implement and administer computer-based information solutions.

TechDefence Labs

TechDefence Labs

TechDefence Labs provide pentesting and security assessment services for networks, web apps, mobile apps and source code reviews.

Cyberint

Cyberint

Cyberint, the Impactful Intelligence company, fuses open-deep-and darkweb Threat Intelligence with Attack Surface Management to deliver maximum protection from external threats.

Salient CRGT

Salient CRGT

Salient CRGT is a leading provider of health, data analytics, cloud, agile software development, mobility, cyber security, and infrastructure solutions.

Sabasai

Sabasai

Sabasai specialises in all aspects of insider threat management from training and education to building security frameworks and insider threat programs to on-site risk & vulnerability assessments.

Quadron  Cybersecurity Services

Quadron Cybersecurity Services

Quadron Cybersecurity Services is a specialist in digital security, data and system protection.

QNu Labs

QNu Labs

QNu Labs’s quantum-safe cryptography products and solutions assure unconditional security of critical data on the internet and cloud across all industry verticals, globally.

CyberX9

CyberX9

CyberX9 helps you protect against a wide range of cyber attacks whether you are a business or a high-net worth individual under risk.

Moore ClearComm

Moore ClearComm

Moore ClearComm is part of Moore Kingston Smith a leading UK firm of accountants and business advisers. Our services include Data Privacy, Cyber Security, Business Continuity and Information Security.

Brennan IT

Brennan IT

For over 25 years, Brennan’s expert team has helped businesses achieve real success through innovative and secure technology solutions.

TRM Labs

TRM Labs

TRM enables risk management and compliance for a global community of financial institutions, cryptocurrency businesses and government agencies.

Skillfield

Skillfield

Skillfield is a Melbourne based Cyber Security and Data Services consultancy and professional services company.

System360

System360

System360 is one of Houston's top suppliers of network administration, design, security, and support services.

Validia

Validia

Validia is a deepfake cybersecurity service that provides proactive and reactive defense to the deepfake threat enterprises increasingly face with the rapid growth of generative AI.

Scinary Cybersecurity

Scinary Cybersecurity

Scinary was founded in 2015 on the premise that cybersecurity should not be limited to just large corporations or large government entities.