MAR-10201537 – HIDDEN COBRA FASTCash-Related Malware
2018-10-02 • USCISA •
CISA analyzed HIDDEN COBRA malware used in the DPRK-linked FASTCash operation to facilitate fraudulent ATM withdrawals. Malicious XCOFF components injected into legitimate processes on IBM AIX financial systems and modified ISO 8583 transaction messages. Supporting Windows malware provided proxy, remote-command, file-transfer, payload-installation, and data-exfiltration capabilities while modifying firewall settings. One remote-access Trojan contained the hard-coded command-and-control address 75.99.63.27 and listened on TCP port 443.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 3a5ba44f140821849de2d82d5a137c3… | 2018-08-28 | 2024-10-13 |
| HASH | 10ac312c8dd02e417dd24d53c99525c… | 2018-08-28 | 2024-10-13 |
| HASH | d465637518024262c063f4a82d799a4… | 2018-08-28 | 2021-12-02 |
| HASH | ca9ab48d293cc84092e8db8f0ca99cb… | 2018-08-28 | 2021-12-02 |
| HASH | 820ca1903a30516263d630c7c08f2b9… | 2018-08-28 | 2020-03-09 |
| HASH | a9bc09a17d55fc790568ac864e38854… | 2018-08-28 | 2020-03-09 |
| HASH | 4a740227eeb82c20286d9c112ef95f0… | 2018-08-28 | 2020-03-09 |
| HASH | 9ddacbcd0700dc4b9babcd09ac1cebe… | 2018-10-02 | 2019-01-23 |
| HASH | 1f2cd2bc23556fb84a51467fedb89cb… | 2018-10-02 | 2019-01-23 |
| HASH | e03dc5f1447f243cf1f305c58d95000… | 2018-10-02 | 2018-10-02 |
| HASH | f3e521996c85c0cdb2bfb3a0fd91eb0… | 2018-08-28 | 2018-10-02 |
| HASH | ab88f12f0a30b4601dc26dbae57646e… | 2018-08-28 | 2018-10-02 |
| IPv4 | 75.99.63.27 | 2018-08-28 | 2018-10-02 |
Related Actors
Related Reports
Shares tags: FASTCash, HiddenCobra • Same author: USCISA • Published within a week
Shares tags: FASTCash, HiddenCobra • Same author: USCISA
Shares tag: HiddenCobra • Published within a week
Shares tag: HiddenCobra • Same author: USCISA
Shares tag: HiddenCobra • Same author: USCISA
Shares tag: HiddenCobra • Same author: USCISA