Attackers target dozens of global banks with new malware

2017-02-12 Symantec

https://community.broadcom.com/symantecenterprise/viewdocument/attackers-target-dozens-of-global-b?CommunityKey=1ecf5f55-9545-44d6-b0f4-4e4a7f5f5e68&tab=librarydocuments

Thumbnail for Attackers target dozens of global banks with new malware

Symantec investigated a watering-hole campaign that targeted banks and related organizations in 31 countries, beginning with compromises observed in Poland and extending to blocked infection attempts in Mexico, Uruguay, and Poland. The attackers used compromised websites, including the Polish financial regulator’s site, to redirect selected visitors to an exploit kit configured to infect only about 150 IP addresses belonging mostly to financial institutions. The malware family Ratankba contacted eye-watch[.]in for command-and-control and downloaded a Hacktool whose code strings overlapped with tools previously associated with Lazarus. Symantec later identified additional tentative Lazarus links, including malware found at a Polish target, a Ratankba sample submitted alongside Destover, and the distinctive "del /a %1" trait also seen in Lazarus-linked malware families. The activity matters because it showed a focused intrusion campaign against global financial institutions using selective watering-hole delivery and tooling with multiple overlaps to prior Lazarus activity.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 4fe3c853ab237005f7d62324535dd64… 2017-02-12 2026-04-03
HASH 95c8ffe03547bcb0afd4d025fb14908… 2017-02-12 2020-03-09
HASH 99017270f0af0e499cfeb19409020bf… 2017-02-12 2020-03-09
HASH 7fe80cee04003fed91c02e3a372f4b01 2017-02-12 2017-02-12
HASH 3af4e21bbbeb846ca295143e03ec0054 2017-02-12 2017-02-12
HASH 91b2558f5319960c85522dc8e372a2b9 2017-02-12 2017-02-12
HASH 7c77ec259162872bf9ab18f6754e0e8… 2017-02-12 2017-02-12
HASH 18a451d70f96a1335623b385f0993bcc 2017-02-12 2017-02-12
HASH efa57ca7aa5f42578ab83c9d510393f… 2017-02-12 2017-02-12
HASH 200c0f4600e54007cb4707c9727b117… 2017-02-12 2017-02-12
HASH 825624d8a93c88a811262bd32cc51e1… 2017-02-12 2017-02-12
HASH 1507e7a741367745425e0530e23768e6 2017-02-12 2017-02-12
HASH 911de8d67af652a87415f8c0a30688b2 2017-02-12 2017-02-12
HASH cb52c013f7af0219d45953bae663c9a2 2017-02-12 2017-02-12
HASH 1f7897b041a812f96f1925138ea38c46 2017-02-12 2017-02-12

Related Reports

« Back