Demystifying targeted malware used against Polish banks

2017-02-16 • ESET •

https://www.welivesecurity.com/2017/02/16/demystifying-targeted-malware-used-polish-banks/

Thumbnail for Demystifying targeted malware used against Polish banks

ESET examined targeted malware delivered through watering-hole attacks against Polish banks and related financial targets, including redirects from compromised financial regulator websites. The payload chain used multi-stage droppers and loaders, dynamic API loading, RC4 or Spritz-like decryption, Enigma packing, service-based persistence, and modules that injected into Windows sessions. The final RAT module communicated with encrypted C2 infrastructure and supported operator commands for file movement, execution, deletion, process control, download, upload, and configuration changes. ESET described the toolkit as Lazarus-like based on overlaps noted by BAE Systems, Symantec, and Novetta, but cautioned that Russian transliterated operator commands could be a false flag. The analysis helped characterize the malware family behind the banking attacks beyond the initial watering-hole vector and highlighted practical traits defenders could hunt for in endpoint telemetry.

Indicators of Compromise

Type Value First Seen Last Seen
HASH a917c1cc198cf36c0f2f6c24652e5c2… 2017-02-16 2020-08-26
HASH d4616f9706403a0d5a2f9a8726230a4… 2017-02-03 2020-03-09
HASH b8fdafa96dec645bb54d4a4593c9bea… 2017-02-16 2017-04-03
HASH 8578a73ca08c708b8242d58cdb4579c… 2017-02-16 2017-04-03
HASH bedceafa2109139c793cb158cec9fa4… 2017-02-03 2017-04-03
HASH 752b8e93a8f6803b265dd3a7cd39df8… 2017-02-16 2017-02-20
HASH cd10ffb7a88f0d2ec69326e7a13f00b… 2017-02-16 2017-02-20
HASH e45ca027635f904101683413dd58fbd… 2017-02-16 2017-02-16

Related Reports

« Back