FASTCash and INJX_Pure: How Threat Actors Use Public Standards for Financial Fraud

2020-08-05 Kevin Perlow

https://i.blackhat.com/USA-20/Wednesday/us-20-Perlow-FASTCash-And-INJX_Pure-How-Threat-Actors-Use-Public-Standards-For-Financial-Fraud-wp.pdf

Attachments

us-20-Perlow-FASTCash-And-INJX_Pure-How-Threat-Actors-Use-Public-S_UTNTH02.pdf (2 MB)

Thumbnail for FASTCash and INJX_Pure: How Threat Actors Use Public Standards for Financial Fraud

The FASTCash paper explains how a DPRK-nexus group abused ISO 8583 payment-switch messaging to force approval of fraudulent ATM withdrawals. FASTCash malware is injected into a bank payment switch process and hooks send and recv so attacker-controlled cards can receive forged approvals while normal transactions continue to pass through. The analyzed AIX variants use whitelisting and response-generation routines for withdrawals and balance inquiries, including randomized amounts and environment-specific ISO 8583 fields. A later Windows variant closely follows the AIX Type 2 logic but adds a working blacklist, additional request validation, support for private field 127, and a Turkish-lira balance response path.

Indicators of Compromise

Type Value First Seen Last Seen
HASH c4141ee8e9594511f528862519480d36 2020-08-05 2020-08-05
HASH b3efec620885e6cf5b60f72e66d908a9 2020-08-05 2020-08-05
HASH d790997dd950bb39229dc5bd3c2047ff 2020-08-05 2020-08-05
HASH a38c1e24eaf34c944c11d9968427c74… 2020-08-05 2020-08-05
HASH d13c15016b5ea2a88434d427bb47110d 2020-08-05 2020-08-05
HASH a042e53edd734b6a96ef9ab82bec8193 2020-08-05 2020-08-05
HASH 4c26b2d0e5cd3bfe0a3d07c4b85909a4 2020-08-05 2020-08-05
HASH d1d779314250fab284fd348888c2f955 2020-08-05 2020-08-05
HASH a827d598b4d13005526839473f38a01b 2020-08-05 2020-08-05
HASH 3122b0130f5135b6f76fca99609d5cbe 2020-08-05 2020-08-05
HASH 46b318bbb72ee68c9d9183d78e79fb5a 2020-08-05 2020-08-05
URL http://www.fintrnmsgtool.com/en… 2020-08-05 2020-08-05
URL http://www.lytsing.org/download… 2020-08-05 2020-08-05
URL http://www.fintrnmsgtool.com/de… 2020-08-05 2020-08-05
URL https://adeo.com.tr/wp-content/… 2020-08-05 2020-08-05
URL https://www.admfactory.com/iso8… 2020-08-05 2020-08-05
DOMAIN adeo.com.tr 2020-08-05 2020-08-05
HASH 89081f2e14e9266de8c042629b764926 2019-10-02 2020-08-05
HASH b9ad0cc2a2e0f513ce716cdf037da907 2019-07-22 2020-08-05
HASH b12325a1e6379b213d35def383da2986 2019-04-10 2020-08-05
HASH 7c651d115109fd8f35fddfc44fd24518 2019-04-10 2020-08-05
HASH d45931632ed9e11476325189ccb6b530 2019-01-22 2020-08-05
HASH 34404a3fb9804977c6ab86cb991fb130 2019-01-13 2020-08-05
HASH b484b0dff093f358897486b58266d069 2019-01-13 2020-08-05

Related Reports

« Back