Attackers target dozens of global banks with new malware
2017-02-12 • Symantec •
Symantec investigated a watering-hole campaign that targeted banks and related organizations in 31 countries, beginning with compromises observed in Poland and extending to blocked infection attempts in Mexico, Uruguay, and Poland. The attackers used compromised websites, including the Polish financial regulator’s site, to redirect selected visitors to an exploit kit configured to infect only about 150 IP addresses belonging mostly to financial institutions. The malware family Ratankba contacted eye-watch[.]in for command-and-control and downloaded a Hacktool whose code strings overlapped with tools previously associated with Lazarus. Symantec later identified additional tentative Lazarus links, including malware found at a Polish target, a Ratankba sample submitted alongside Destover, and the distinctive "del /a %1" trait also seen in Lazarus-linked malware families. The activity matters because it showed a focused intrusion campaign against global financial institutions using selective watering-hole delivery and tooling with multiple overlaps to prior Lazarus activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 4fe3c853ab237005f7d62324535dd64… | 2017-02-12 | 2026-04-03 |
| HASH | 95c8ffe03547bcb0afd4d025fb14908… | 2017-02-12 | 2020-03-09 |
| HASH | 99017270f0af0e499cfeb19409020bf… | 2017-02-12 | 2020-03-09 |
| HASH | 7fe80cee04003fed91c02e3a372f4b01 | 2017-02-12 | 2017-02-12 |
| HASH | 3af4e21bbbeb846ca295143e03ec0054 | 2017-02-12 | 2017-02-12 |
| HASH | 91b2558f5319960c85522dc8e372a2b9 | 2017-02-12 | 2017-02-12 |
| HASH | 7c77ec259162872bf9ab18f6754e0e8… | 2017-02-12 | 2017-02-12 |
| HASH | 18a451d70f96a1335623b385f0993bcc | 2017-02-12 | 2017-02-12 |
| HASH | efa57ca7aa5f42578ab83c9d510393f… | 2017-02-12 | 2017-02-12 |
| HASH | 200c0f4600e54007cb4707c9727b117… | 2017-02-12 | 2017-02-12 |
| HASH | 825624d8a93c88a811262bd32cc51e1… | 2017-02-12 | 2017-02-12 |
| HASH | 1507e7a741367745425e0530e23768e6 | 2017-02-12 | 2017-02-12 |
| HASH | 911de8d67af652a87415f8c0a30688b2 | 2017-02-12 | 2017-02-12 |
| HASH | cb52c013f7af0219d45953bae663c9a2 | 2017-02-12 | 2017-02-12 |
| HASH | 1f7897b041a812f96f1925138ea38c46 | 2017-02-12 | 2017-02-12 |