Lazarus Under The Hood
First seen: 2017-04 •
Last seen: 2026-05
#CosmosBank • 2018-08
Cosmos Bank suffered an August 2018 financial intrusion combining ATM cash-out and SWIFT abuse, with linked reporting describing compromise of ATM/POS switch infrastructure, malicious ISO 8583 libraries, process injection, a parallel malicious switch, and fraudulent MT103 transfers. Some sources associated the activity with Lazarus or DPRK-linked Hidden Cobra and FASTCash-style indicators, while the Indian investigation cited in the evidence had not confirmed that attribution.
5
Related Reports
1
Affected Countries
94
Months Since
Lazarus Under The Hood