TAIWAN HEIST: LAZARUS TOOLS AND RANSOMWARE
2017-10-16 • Bae Systems •
http://baesystemsai.blogspot.kr/2017/10/taiwan-heist-lazarus-tools.html
BAE Systems linked the Far Eastern International Bank intrusion to a cyber-enabled heist in which attackers abused systems connected to the SWIFT network and moved funds to overseas beneficiaries. Malware samples uploaded after the incident included known Lazarus tools and Hermes ransomware, with the ransomware assessed as possibly serving as a distraction or cover while the theft was underway. The Bitsran loader established registry persistence, attempted to kill Trend Micro services, unpacked an embedded polyglot ZIP payload, and spread across the internal network using hardcoded FEIB-related credentials and SMB access to a list of more than 5,000 IP addresses. Hermes deleted shadow copies and backup files before encrypting local and network resources, while other samples matched Lazarus backdoors previously associated with watering-hole activity in Poland and Mexico. The case matters because it combined bank-fraud operations, internal reconnaissance, credential use, lateral movement, destructive ransomware behavior, and Lazarus-linked tooling in one intrusion.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| YARA | Hermes2_1 | 2017-10-16 | 2017-10-16 |
| HASH | b27881f59c8d8cc529fa80a58709db36 | 2017-10-16 | 2017-10-16 |