Associated with: Bluenoroff
First seen: 2020-08 •
Last seen: 2021-03
#FastCash2 • 2020-10
CISA, Treasury, FBI, and USCYBERCOM attributed FASTCash 2.0 ATM cash-out activity to North Korea's BeagleBoyz, a HIDDEN COBRA subset overlapping with Lazarus, APT38, Bluenoroff, and Stardust Chollima. The campaign targeted financial institutions and payment switch infrastructure, expanding from Unix-like switch servers to Windows-hosted switch applications and interbank payment processors while using spear-phishing, watering holes, public-facing exploitation, credential theft, lateral movement, destructive anti-forensics, proxy tunneling, and FASTCash-related malware.
1
Related Reports
38
Affected Countries
68
Months Since