Lazarus(APT-C-26)
2016-08-25 • Qihoo360 •
360’s report links the 2016 Bangladesh Central Bank theft and the attempted attacks on Vietnam’s Tien Phong Bank and other banks through shared focus on SWIFT operations and malware code commonality. The Bangladesh case involved fraudulent SWIFT transfer instructions sent to the Federal Reserve Bank of New York, with $81 million ultimately stolen after some transactions were blocked or recovered. The malware described in the excerpt tampered with SWIFT MT900 messages, altered database and printer-related artifacts, patched liboradb.dll to bypass Alliance Access permission checks, and deleted logs, data, and services after a timed cleanup window. The authors assess that the related malware used against Bangladesh Central Bank and Tien Phong Bank is associated with Lazarus, while noting they cannot confirm Lazarus itself was the operator behind the activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://www.swift.com/insights/… | 2016-08-25 | 2016-08-25 |
| URL | https://ibanking.standardbank.c… | 2016-08-25 | 2016-08-25 |
| URL | http://bobao.360.cn/learning/de… | 2016-08-25 | 2016-08-25 |
| URL | https://www.newyorkfed.org/news… | 2016-08-25 | 2016-08-25 |
| URL | https://www.swift.com/insights/… | 2016-08-25 | 2016-08-25 |
| URL | https://www.swift.com/insights/… | 2016-08-25 | 2016-08-25 |
| URL | https://www.swift.com/insights/… | 2016-08-25 | 2016-08-25 |
| IPv4 | 196.202.103.174 | 2016-04-25 | 2016-08-25 |