Lazarus Under The Hood
First seen: 2017-04 •
Last seen: 2026-05
#HSBCMalta • 2018-10
Group-IB described an attempted attack on HSBC's Maltese office that was detected and stopped, then linked the activity to the same Lazarus SWIFT-focused cluster behind later thefts from Mexican banks, Banco de Chile, AkBank, and Bank of Valletta. The reporting frames the HSBC Malta case as part of a North Korea-linked campaign against financial institutions that relied on SWIFT access and carefully prepared cash-out operations rather than opportunistic banking malware.
1
Related Reports
1
Affected Countries
92
Months Since
Lazarus Under The Hood