FASTCash for Linux
2024-10-13 • Doubleagent •
DoubleAgent analyzes a newly identified Linux variant of DPRK-attributed FASTCash malware built for payment-switch environments that process card transactions. The Ubuntu 20.04 sample adds to earlier AIX and Windows FASTCash variants and appears related to Windows samples through shared fraudulent transaction-response properties. Its core function is to intercept declined magnetic-stripe transaction messages for predefined cardholder account numbers and authorize withdrawals with random Turkish-lira amounts. The report places the malware on compromised bank or interbank switch infrastructure, where weak or missing message-integrity checks can allow transaction tampering that enables ATM cash-out activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f43d4e7e2ab1054d46e2a93ce37d03a… | 2024-10-13 | 2024-10-13 |
| HASH | afff4d4deb46a01716a4a3eb7f80da5… | 2024-10-13 | 2024-10-13 |
| HASH | 7f3d046b2c5d8c008164408a24cac7e… | 2024-10-13 | 2024-10-13 |
| HASH | f34b532117b3431387f11e3d92dc9ff… | 2024-10-13 | 2024-10-13 |
| HASH | 129b8825eaf61dcc2321aad7b846322… | 2024-10-13 | 2024-10-13 |
| HASH | 5232d942da0a86ff4a7ff29a9affbb5… | 2024-10-13 | 2024-10-13 |
| HASH | 3a5ba44f140821849de2d82d5a137c3… | 2018-08-28 | 2024-10-13 |
| HASH | 10ac312c8dd02e417dd24d53c99525c… | 2018-08-28 | 2024-10-13 |