TAIWAN HEIST: LAZARUS TOOLS AND RANSOMWARE

2017-10-16 Bae Systems

http://baesystemsai.blogspot.kr/2017/10/taiwan-heist-lazarus-tools.html

Thumbnail for TAIWAN HEIST: LAZARUS TOOLS AND RANSOMWARE

BAE Systems linked the Far Eastern International Bank intrusion to a cyber-enabled heist in which attackers abused systems connected to the SWIFT network and moved funds to overseas beneficiaries. Malware samples uploaded after the incident included known Lazarus tools and Hermes ransomware, with the ransomware assessed as possibly serving as a distraction or cover while the theft was underway. The Bitsran loader established registry persistence, attempted to kill Trend Micro services, unpacked an embedded polyglot ZIP payload, and spread across the internal network using hardcoded FEIB-related credentials and SMB access to a list of more than 5,000 IP addresses. Hermes deleted shadow copies and backup files before encrypting local and network resources, while other samples matched Lazarus backdoors previously associated with watering-hole activity in Poland and Mexico. The case matters because it combined bank-fraud operations, internal reconnaissance, credential use, lateral movement, destructive ransomware behavior, and Lazarus-linked tooling in one intrusion.

Indicators of Compromise

Type Value First Seen Last Seen
YARA Hermes2_1 2017-10-16 2017-10-16
HASH b27881f59c8d8cc529fa80a58709db36 2017-10-16 2017-10-16

Related Actors

Related Reports

« Back