Lazarus(APT-C-26)

2016-08-25 Qihoo360

https://apt.360.net/orgDetail/9

Thumbnail for Lazarus(APT-C-26)

360’s report links the 2016 Bangladesh Central Bank theft and the attempted attacks on Vietnam’s Tien Phong Bank and other banks through shared focus on SWIFT operations and malware code commonality. The Bangladesh case involved fraudulent SWIFT transfer instructions sent to the Federal Reserve Bank of New York, with $81 million ultimately stolen after some transactions were blocked or recovered. The malware described in the excerpt tampered with SWIFT MT900 messages, altered database and printer-related artifacts, patched liboradb.dll to bypass Alliance Access permission checks, and deleted logs, data, and services after a timed cleanup window. The authors assess that the related malware used against Bangladesh Central Bank and Tien Phong Bank is associated with Lazarus, while noting they cannot confirm Lazarus itself was the operator behind the activity.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://www.swift.com/insights/… 2016-08-25 2016-08-25
URL https://ibanking.standardbank.c… 2016-08-25 2016-08-25
URL http://bobao.360.cn/learning/de… 2016-08-25 2016-08-25
URL https://www.newyorkfed.org/news… 2016-08-25 2016-08-25
URL https://www.swift.com/insights/… 2016-08-25 2016-08-25
URL https://www.swift.com/insights/… 2016-08-25 2016-08-25
URL https://www.swift.com/insights/… 2016-08-25 2016-08-25
IPv4 196.202.103.174 2016-04-25 2016-08-25

Related Actors

Related Reports

« Back