FASTCash 2.0: North Korea's BeagleBoyz Robbing Banks

2020-08-26 USCISA

https://us-cert.cisa.gov/ncas/alerts/aa20-239a

Thumbnail for FASTCash 2.0: North Korea's BeagleBoyz Robbing Banks

CISA, Treasury, FBI, and USCYBERCOM attributed FASTCash 2.0 ATM cash-out activity to North Korea’s BeagleBoyz, a HIDDEN COBRA subset overlapping with Lazarus, APT38, Bluenoroff, and Stardust Chollima. The advisory says the group has targeted financial institutions since at least 2015, attempted to steal nearly $2 billion, abused SWIFT endpoints, and expanded FASTCash from Unix-like switch servers to Windows-hosted switch applications and interbank payment processors. BeagleBoyz operations use spear-phishing, watering holes, public-facing exploitation, valid accounts, remote services, credential theft, lateral movement, destructive anti-forensics, and proxy tunneling to reach SWIFT terminals and payment switch systems. The report describes malware and tools such as CROWDEDFLOUNDER, HOPLIGHT, ECCENTRICBANDWAGON, ELECTRICFISH, VIVACIOUSGIFT, and FASTCash for Windows.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 4f67f3e4a7509af1b2b1c6180a03b3e4 2020-08-26 2020-08-26
HASH 5cfa1c2cb430bec721063e3e2d144feb 2020-08-26 2020-08-26

Related Actors

Related Reports

« Back