TWO BYTES TO $951M
2016-04-25 • Bae Systems •
http://baesystemsai.blogspot.kr/2016/04/two-bytes-to-951m.html
BAE Systems analyzed custom malware linked to the Bangladesh Bank SWIFT heist, where attackers attempted to transfer $951 million and $81 million remained unaccounted for. The malware was built for an environment running SWIFT Alliance Access with an Oracle database, registered itself as a service, and parsed local SWIFT FIN messages to identify attacker-defined transaction strings. It could patch a SWIFT Alliance module in memory to bypass a conditional authorization check, then generate SQL statements to delete transaction records or manipulate balance-reporting data. The tooling also used an encrypted configuration file, local logging paths, and command-and-control callbacks tied to SWIFT login and logout events, showing detailed knowledge of the victim payment infrastructure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 196.202.103.174 | 2016-04-25 | 2016-08-25 |
| HASH | 76bab478dcc70f979ce62cd306e9ba5… | 2016-04-25 | 2016-04-25 |
| HASH | 525a8e3ae4e3df8c9c61f2a49e38541… | 2016-04-25 | 2016-04-25 |
| HASH | 70bf16597e375ad691f2c1efa194dbe… | 2016-04-25 | 2016-04-25 |
| HASH | 6207b92842b28a438330a2bf0ee8dca… | 2016-04-25 | 2016-04-25 |