Demystifying targeted malware used against Polish banks

2017-02-16 ESET

https://www.welivesecurity.com/2017/02/16/demystifying-targeted-malware-used-polish-banks/

Thumbnail for Demystifying targeted malware used against Polish banks

ESET examined targeted malware delivered through watering-hole attacks against Polish banks and related financial targets, including redirects from compromised financial regulator websites. The payload chain used multi-stage droppers and loaders, dynamic API loading, RC4 or Spritz-like decryption, Enigma packing, service-based persistence, and modules that injected into Windows sessions. The final RAT module communicated with encrypted C2 infrastructure and supported operator commands for file movement, execution, deletion, process control, download, upload, and configuration changes. ESET described the toolkit as Lazarus-like based on overlaps noted by BAE Systems, Symantec, and Novetta, but cautioned that Russian transliterated operator commands could be a false flag. The analysis helped characterize the malware family behind the banking attacks beyond the initial watering-hole vector and highlighted practical traits defenders could hunt for in endpoint telemetry.

Indicators of Compromise

Type Value First Seen Last Seen
HASH a107f1046f5224fdb3a5826fa6f940a… 2017-02-16 2017-04-03
HASH aa115e6587a535146b7493d6c02896a… 2017-02-16 2017-04-03
HASH 4f0d7a33d23d53c0eb8b34d102cdd66… 2017-02-03 2017-04-03
HASH bedceafa2109139c793cb158cec9fa4… 2017-02-03 2017-04-03
HASH 50b4f9a8fa6803f0aabb6fd9374244a… 2017-02-16 2017-02-16
HASH 11568dffd6325ade217fbe49ce56a3e… 2017-02-16 2017-02-16
HASH fa4f2e3f7c56210d1e380ec6d74a0b6… 2017-02-16 2017-02-16
HASH e45ca027635f904101683413dd58fbd… 2017-02-16 2017-02-16

Related Reports

« Back