FASTCash 2.0: North Korea's BeagleBoyz Robbing Banks
2020-08-26 • USCISA •
CISA, Treasury, FBI, and USCYBERCOM attributed FASTCash 2.0 ATM cash-out activity to North Korea’s BeagleBoyz, a HIDDEN COBRA subset overlapping with Lazarus, APT38, Bluenoroff, and Stardust Chollima. The advisory says the group has targeted financial institutions since at least 2015, attempted to steal nearly $2 billion, abused SWIFT endpoints, and expanded FASTCash from Unix-like switch servers to Windows-hosted switch applications and interbank payment processors. BeagleBoyz operations use spear-phishing, watering holes, public-facing exploitation, valid accounts, remote services, credential theft, lateral movement, destructive anti-forensics, and proxy tunneling to reach SWIFT terminals and payment switch systems. The report describes malware and tools such as CROWDEDFLOUNDER, HOPLIGHT, ECCENTRICBANDWAGON, ELECTRICFISH, VIVACIOUSGIFT, and FASTCash for Windows.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 4f67f3e4a7509af1b2b1c6180a03b3e4 | 2020-08-26 | 2020-08-26 |
| HASH | 5cfa1c2cb430bec721063e3e2d144feb | 2020-08-26 | 2020-08-26 |