FASTCash: How the Lazarus Group is Emptying Millions from ATMs
2018-11-08 • Symantec •
https://www.symantec.com/blogs/threat-intelligence/fastcash-lazarus-atm-malware
Symantec details Lazarus/Hidden Cobra FASTCash attacks against banks in Asia and Africa, where attackers breached financial networks and compromised switch application servers that process ATM transactions. The key malware, Trojan.Fastcash, is an AIX executable injected into a legitimate process on the transaction network to inspect ISO 8583 messages, intercept attacker-generated withdrawal requests, and return fake approval responses. The report says FASTCash activity had been observed since at least 2016, including incidents where cash was withdrawn from ATMs in more than 30 countries in 2017 and 23 countries in 2018. Its tailored response logic and targeting of unsupported AIX switch servers show how Lazarus converted server compromise into large-scale fraudulent ATM cash-outs worth tens of millions of dollars.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 3a5ba44f140821849de2d82d5a137c3… | 2018-08-28 | 2024-10-13 |
| HASH | 10ac312c8dd02e417dd24d53c99525c… | 2018-08-28 | 2024-10-13 |
| HASH | d465637518024262c063f4a82d799a4… | 2018-08-28 | 2021-12-02 |
| HASH | ca9ab48d293cc84092e8db8f0ca99cb… | 2018-08-28 | 2021-12-02 |