Bank-Attack Hackers Use Russian Decoys

The hackers behind a sophisticated attack campaign that has recently targeted financial organisations around the world have intentionally inserted Russian words and commands into their malware in an attempt to throw investigators off.

Researchers from cybersecurity firm BAE Systems have recently obtained and analysed additional malware samples related to an attack campaign that has targeted 104 organisations, most of them banks, from 31 different countries.

They found multiple commands and strings in the malware that appear to have been translated into Russian using online tools, the results making little sense to a native Russian speaker.

"In some cases the inaccurate translations have transformed the meaning of the words entirely," the researchers said in a blog post. 

"This strongly implies that the authors of this attack are not native Russian speakers and, as such, the use of Russian words appears to be a 'false flag'."

This unusual behaviour is most likely intended to make attribution harder and throw investigators on a false lead. In reality there is technical evidence to link these malware samples and the overall attack campaign to a group known in the security industry as Lazarus.

This group has been active since at least 2009 and has been responsible for various attacks against government and private organizations from South Korea and the US over the years.

Lazarus is believed to have been responsible for the 2014 attack against Sony Pictures Entertainment that resulted in sensitive data being leaked from the company and many of the company's computers being rendered inoperable. The FBI and other U.S. intelligence agencies attributed that attack to North Korea.

The Lazarus group has also been linked to the theft of US$81 million from the central bank of Bangladesh last year. In that attack, hackers used malware to manipulate the computers used by the bank to operate money transfers over the SWIFT network. They attempted to move $951 million in total, but some transactions failed and others were successfully reversed after the heist was detected.

Recently a malware attack that affected multiple banks in Poland came to light. The attack is believed to have involved exploits launched from the compromised website of the Polish Financial Supervision Authority.

Researchers from BAE Systems and Symantec have tied the Polish attack to a larger campaign that has been going on since October and involved multiple watering-hole-style compromises. The websites of the National Banking and Stock Commission of Mexico and the largest state-owned bank from Uruguay have also been infected in a similar manner.

The malware programs used in these attacks bear code similarities to tools attributed in the past to the Lazarus group.

There are several cyber-criminal gangs of Russian origin that specialise in targeting banks. These groups use spear-phishing to gain a foothold into banks' networks and then learn the organisations' internal procedures before they begin to steal money. 
BAE Systems' research suggests that Lazarus might be trying to make its activity blend in with that of these Russian-speaking cyber-criminals.

Computerworld:

Banks Lack Confidence They Can Detect Data Breaches:

Security Directly Impacts The Bottom Line At Banks:

 

« Estonian Honey Trap
Keeping The Cloud Safe: Exclusive Report »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

MetaCompliance

MetaCompliance

MetaCompliance is a cyber security and compliance organisation that helps transform your company culture and safeguard your data and values.

SolarWinds

SolarWinds

SolarWinds as a worldwide leader in solutions for network and IT service management, application performance, and managed services.

AON

AON

Aon is a leading global provider of risk management (including cyber), insurance and reinsurance brokerage, human resources solutions and outsourcing services.

Cyber adAPT

Cyber adAPT

Cyber adAPT offers a leading network threat detection platform (NTD) to the enterprise and ODM/OEM markets.

Foresite

Foresite

Foresite is a global service provider, delivering a range of managed security and consulting solutions.

Caretower

Caretower

Caretower is one of Europe’s leading value added managed service provider in cyber security.

SecureKey Technologies

SecureKey Technologies

SecureKey is a leading identity and authentication provider that simplifies consumer access to online services and applications.

Slovak Security Policy Institute (SSPI)

Slovak Security Policy Institute (SSPI)

Slovak Security Policy Institute is an independent non-governmental organization that focuses on research and analysis of security challenges including defence and cyber security.

National Cyber Security Centre (NCSC) - Ireland

National Cyber Security Centre (NCSC) - Ireland

The National Cyber Security Centre (NCSC) is the operational side of the Department of Communications in regard to network and information security in the Republic of Ireland.

GuardianKey

GuardianKey

GuardianKey is a solution to protect systems against authentication attacks.

Thridwayv

Thridwayv

Thirdwayv helps your enterprise realize the full potential of loT connectivity. All while neutralizing security threats that can run ruin the customer experience - and your reputation.

Telsy

Telsy

Telsy is a security partner for ICT solutions and services. We help you implement effective security solutions that increase your risk mitigation ability and your responsiveness.

Redsquid

Redsquid

At Redsquid we are all about making a difference to our customers with the use of technology, as an innovative provider of solutions within IoT, Cyber security, ICT, Data Connectivity & Voice.

Core4ce

Core4ce

Core4ce is a mission-oriented company that serves as a trusted partner to the national security community.

Technology Mindz

Technology Mindz

Technology Mindz is a leading provider of cybersecurity services. We offer a wide range of services to help businesses. Our services are Identity and access management, Governance risk and compliance.

Trovent Security

Trovent Security

Trovent was founded with a clear goal: to support medium-sized companies in significantly increasing their IT security level.