NATION-STATE MONEYMULE'S HUNTING SEASON – APT ATTACKS TARGETING FINANCIAL INSTITUTION
2017-12-07 • FSI •
Attachments
The presentation describes nation-state actors including Lazarus, Bluenoroff, and Andariel shifting into financially motivated operations against banks, ATM operators, and cryptocurrency exchanges. A March 2017 Bluenoroff case targeted employees of a top South Korean bank responsible for SWIFT operations, using spear-phishing and a hidden NamedPipe file-sharing feature in VDI software to move data from an internal segregated network to C2 infrastructure. The bank malware is identified as Manuscrypt, with files such as corems.dll and amanuv.dll searching for SWIFT-related hosts, activating the vmsal.exe named pipe path, collecting files, and posting data as multipart form submissions. The Andariel-linked VANXATM operation targeted a South Korean ATM operator, abusing an antivirus zero-day and ATM update-server weaknesses to deploy RAT and exfiltration components and leak card data from journal files. The cryptocurrency-exchange section describes phishing that impersonated Korean public institutions, malicious HWP attachments using Ghostscript, and mobile malware used to bypass SMS authentication during attacks on four South Korean exchanges.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://foodforu.heliohost.org/b… | 2017-12-07 | 2018-03-23 |
| URL | http://foodforu.heliohost.org/b… | 2017-12-07 | 2018-03-23 |
| URL | https://www.unsunozo.org | 2017-12-07 | 2018-03-23 |
| URL | http://foodforu.heliohost.org/b… | 2017-12-07 | 2018-03-23 |
| URL | https://www.kbautosys.com | 2017-12-07 | 2018-03-23 |
| IPv4 | 49.239.189.45 | 2017-12-07 | 2018-03-23 |
| IPv4 | 115.92.103.37 | 2017-12-07 | 2018-03-23 |
| URL | http://old.jrchina.com/btob_asi… | 2017-10-05 | 2018-03-23 |
| URL | http://old.jrchina.com/btob_asi… | 2017-10-05 | 2018-03-23 |
| URL | http://old.jrchina.com/btob_asi… | 2017-10-05 | 2018-03-23 |
| DOMAIN | old.jrchina.com | 2017-10-05 | 2018-03-23 |
| DOMAIN | foodforu.heliohost.org | 2017-10-05 | 2018-03-23 |
| URL | https://niebezpiecznik.pl/post/… | 2017-12-07 | 2017-12-07 |
| DOMAIN | niebezpiecznik.pl | 2017-12-07 | 2017-12-07 |