MAR-10257062-1.v2 - North Korean Remote Access Tool: FASTCASH for Windows

2020-08-26 • USCISA •

https://www.cisa.gov/news-events/analysis-reports/ar20-239c

Thumbnail for MAR-10257062-1.v2 - North Korean Remote Access Tool: FASTCASH for Windows

CISA, the FBI, and the Department of Defense identified FASTCASH for Windows as malware used by the North Korean government under the U.S. HIDDEN COBRA designation. The malware is injected into banking processes, hooks Windows network APIs, and parses ISO 8583 messages associated with ATM and point-of-sale transactions. It can identify configured account numbers, alter authorization responses, and approve fraudulent withdrawals beyond available balances. The report analyzes three samples and provides cryptographic indicators and behavioral details for detection.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 129b8825eaf61dcc2321aad7b846322… 2020-08-05 2024-10-13
YARA CISA_3P_10257062 2020-08-26 2020-08-26
YARA CISA_10257062_01 2020-08-26 2020-08-26
HASH 5cb7a352535b447609849e20aec18c8… 2020-08-26 2020-08-26
HASH 39cbad3b2aac6298537a85f0463453d… 2019-10-02 2020-08-26

Related Actors

Related Reports

« Back