NATION-STATE MONEYMULE'S HUNTING SEASON

2018-03-23 FSI

https://i.blackhat.com/briefings/asia/2018/asia-18-shen-kwak-jang-nation-state-moneymule-hunting-season-thursday.pdf

Attachments

asia-18-shen-kwak-jang-nation-state-moneymule-hunting-season-thursday.pdf (2 MB)

Thumbnail for NATION-STATE MONEYMULE'S HUNTING SEASON

The Black Hat presentation links Lazarus, Bluenoroff, Andariel, and Reaper/APT37 to financially motivated and espionage-focused attacks against banks, cryptocurrency exchanges, ATM operators, defense, government, and South Korean users. It describes a March 2017 Bluenoroff intrusion into a top South Korean bank where spear-phishing and a VDI named-pipe file-sharing weakness allowed Manuscrypt components such as corems.dll and amanuv.dll to search for SWIFT-related hosts and move data toward C2 infrastructure. The Andariel-linked VANXATM case abused an antivirus zero-day and ATM update-server weaknesses, including unauthenticated updates and unencrypted FTP credentials, leading to large-scale card-data leakage from an ATM operator. The cryptocurrency-exchange campaign used phishing that impersonated public institutions, malicious HWP files leveraging Ghostscript behavior, stolen or attacker-created email accounts, and mobile malware to bypass SMS authentication.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://foodforu.heliohost.org/b… 2017-12-07 2018-03-23
URL http://foodforu.heliohost.org/b… 2017-12-07 2018-03-23
URL https://www.unsunozo.org 2017-12-07 2018-03-23
URL http://foodforu.heliohost.org/b… 2017-12-07 2018-03-23
URL https://www.kbautosys.com 2017-12-07 2018-03-23
IPv4 49.239.189.45 2017-12-07 2018-03-23
IPv4 115.92.103.37 2017-12-07 2018-03-23
URL http://old.jrchina.com/btob_asi… 2017-10-05 2018-03-23
URL http://old.jrchina.com/btob_asi… 2017-10-05 2018-03-23
URL http://old.jrchina.com/btob_asi… 2017-10-05 2018-03-23
DOMAIN old.jrchina.com 2017-10-05 2018-03-23
DOMAIN foodforu.heliohost.org 2017-10-05 2018-03-23

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

« Back