Demystifying targeted malware used against Polish banks
2017-02-16 • ESET •
https://www.welivesecurity.com/2017/02/16/demystifying-targeted-malware-used-polish-banks/
ESET examined targeted malware delivered through watering-hole attacks against Polish banks and related financial targets, including redirects from compromised financial regulator websites. The payload chain used multi-stage droppers and loaders, dynamic API loading, RC4 or Spritz-like decryption, Enigma packing, service-based persistence, and modules that injected into Windows sessions. The final RAT module communicated with encrypted C2 infrastructure and supported operator commands for file movement, execution, deletion, process control, download, upload, and configuration changes. ESET described the toolkit as Lazarus-like based on overlaps noted by BAE Systems, Symantec, and Novetta, but cautioned that Russian transliterated operator commands could be a false flag. The analysis helped characterize the malware family behind the banking attacks beyond the initial watering-hole vector and highlighted practical traits defenders could hunt for in endpoint telemetry.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | a107f1046f5224fdb3a5826fa6f940a… | 2017-02-16 | 2017-04-03 |
| HASH | aa115e6587a535146b7493d6c02896a… | 2017-02-16 | 2017-04-03 |
| HASH | 4f0d7a33d23d53c0eb8b34d102cdd66… | 2017-02-03 | 2017-04-03 |
| HASH | bedceafa2109139c793cb158cec9fa4… | 2017-02-03 | 2017-04-03 |
| HASH | 50b4f9a8fa6803f0aabb6fd9374244a… | 2017-02-16 | 2017-02-16 |
| HASH | 11568dffd6325ade217fbe49ce56a3e… | 2017-02-16 | 2017-02-16 |
| HASH | fa4f2e3f7c56210d1e380ec6d74a0b6… | 2017-02-16 | 2017-02-16 |
| HASH | e45ca027635f904101683413dd58fbd… | 2017-02-16 | 2017-02-16 |