FASTCash 2.0: North Korea's BeagleBoyz Robbing Banks

2020-08-26 • USCISA •

https://us-cert.cisa.gov/ncas/alerts/aa20-239a

Thumbnail for FASTCash 2.0: North Korea's BeagleBoyz Robbing Banks

CISA, Treasury, FBI, and USCYBERCOM attributed FASTCash 2.0 ATM cash-out activity to North Korea’s BeagleBoyz, a HIDDEN COBRA subset overlapping with Lazarus, APT38, Bluenoroff, and Stardust Chollima. The advisory says the group has targeted financial institutions since at least 2015, attempted to steal nearly $2 billion, abused SWIFT endpoints, and expanded FASTCash from Unix-like switch servers to Windows-hosted switch applications and interbank payment processors. BeagleBoyz operations use spear-phishing, watering holes, public-facing exploitation, valid accounts, remote services, credential theft, lateral movement, destructive anti-forensics, and proxy tunneling to reach SWIFT terminals and payment switch systems. The report describes malware and tools such as CROWDEDFLOUNDER, HOPLIGHT, ECCENTRICBANDWAGON, ELECTRICFISH, VIVACIOUSGIFT, and FASTCash for Windows.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 4a740227eeb82c20286d9c112ef95f0… 2018-08-28 2020-08-26
HASH 820ca1903a30516263d630c7c08f2b9… 2018-08-28 2020-08-26

Related Actors

Related Reports

« Back