NATION-STATE MONEYMULE'S HUNTING SEASON – APT ATTACKS TARGETING FINANCIAL INSTITUTION

2017-12-07 FSI

https://www.blackhat.com/docs/eu-17/materials/eu-17-Shen-Nation-State%20Moneymules-Hunting-Season-APT-Attacks-Targeting-Financial-Institutions.pdf

Attachments

eu-17-Shen-Nation-State20Moneymules-Hunting-Season-APT-Attacks-Tar_sZ1gbHY.pdf (3 MB)

Thumbnail for NATION-STATE MONEYMULE'S HUNTING SEASON – APT ATTACKS TARGETING FINANCIAL INSTITUTION

The presentation describes nation-state actors including Lazarus, Bluenoroff, and Andariel shifting into financially motivated operations against banks, ATM operators, and cryptocurrency exchanges. A March 2017 Bluenoroff case targeted employees of a top South Korean bank responsible for SWIFT operations, using spear-phishing and a hidden NamedPipe file-sharing feature in VDI software to move data from an internal segregated network to C2 infrastructure. The bank malware is identified as Manuscrypt, with files such as corems.dll and amanuv.dll searching for SWIFT-related hosts, activating the vmsal.exe named pipe path, collecting files, and posting data as multipart form submissions. The Andariel-linked VANXATM operation targeted a South Korean ATM operator, abusing an antivirus zero-day and ATM update-server weaknesses to deploy RAT and exfiltration components and leak card data from journal files. The cryptocurrency-exchange section describes phishing that impersonated Korean public institutions, malicious HWP attachments using Ghostscript, and mobile malware used to bypass SMS authentication during attacks on four South Korean exchanges.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://foodforu.heliohost.org/b… 2017-12-07 2018-03-23
URL http://foodforu.heliohost.org/b… 2017-12-07 2018-03-23
URL https://www.unsunozo.org 2017-12-07 2018-03-23
URL http://foodforu.heliohost.org/b… 2017-12-07 2018-03-23
URL https://www.kbautosys.com 2017-12-07 2018-03-23
IPv4 49.239.189.45 2017-12-07 2018-03-23
IPv4 115.92.103.37 2017-12-07 2018-03-23
URL http://old.jrchina.com/btob_asi… 2017-10-05 2018-03-23
URL http://old.jrchina.com/btob_asi… 2017-10-05 2018-03-23
URL http://old.jrchina.com/btob_asi… 2017-10-05 2018-03-23
DOMAIN old.jrchina.com 2017-10-05 2018-03-23
DOMAIN foodforu.heliohost.org 2017-10-05 2018-03-23
URL https://niebezpiecznik.pl/post/… 2017-12-07 2017-12-07
DOMAIN niebezpiecznik.pl 2017-12-07 2017-12-07

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

« Back