NATION-STATE MONEYMULE'S HUNTING SEASON
2018-03-23 • FSI •
Attachments
The Black Hat presentation links Lazarus, Bluenoroff, Andariel, and Reaper/APT37 to financially motivated and espionage-focused attacks against banks, cryptocurrency exchanges, ATM operators, defense, government, and South Korean users. It describes a March 2017 Bluenoroff intrusion into a top South Korean bank where spear-phishing and a VDI named-pipe file-sharing weakness allowed Manuscrypt components such as corems.dll and amanuv.dll to search for SWIFT-related hosts and move data toward C2 infrastructure. The Andariel-linked VANXATM case abused an antivirus zero-day and ATM update-server weaknesses, including unauthenticated updates and unencrypted FTP credentials, leading to large-scale card-data leakage from an ATM operator. The cryptocurrency-exchange campaign used phishing that impersonated public institutions, malicious HWP files leveraging Ghostscript behavior, stolen or attacker-created email accounts, and mobile malware to bypass SMS authentication.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://foodforu.heliohost.org/b… | 2017-12-07 | 2018-03-23 |
| URL | http://foodforu.heliohost.org/b… | 2017-12-07 | 2018-03-23 |
| URL | https://www.unsunozo.org | 2017-12-07 | 2018-03-23 |
| URL | http://foodforu.heliohost.org/b… | 2017-12-07 | 2018-03-23 |
| URL | https://www.kbautosys.com | 2017-12-07 | 2018-03-23 |
| IPv4 | 49.239.189.45 | 2017-12-07 | 2018-03-23 |
| IPv4 | 115.92.103.37 | 2017-12-07 | 2018-03-23 |
| URL | http://old.jrchina.com/btob_asi… | 2017-10-05 | 2018-03-23 |
| URL | http://old.jrchina.com/btob_asi… | 2017-10-05 | 2018-03-23 |
| URL | http://old.jrchina.com/btob_asi… | 2017-10-05 | 2018-03-23 |
| DOMAIN | old.jrchina.com | 2017-10-05 | 2018-03-23 |
| DOMAIN | foodforu.heliohost.org | 2017-10-05 | 2018-03-23 |