lazarusholic

Everyday is lazarus.dayβ

Taiwan Bank Heist and the Role of Pseudo Ransomware

2017-10-12, Mcafee
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/taiwan-bank-heist-role-pseudo-ransomware/
#ATM #Finance #FEIB

Contents

Widespread reports claim the Far Eastern International Bank in Taiwan has become a victim of hacking. The attacks demonstrate the global nature of cybercrime, with the cybercriminals attempting to wire US$60 million to destinations such as Sri Lanka, Cambodia, and the United States. Recent reports from Sri Lanka say that two individuals have been arrested for suspected money laundering after a tip-off from the Bank of Ceylon, which reported a suspicious transfer of $1.2 million from the Far Eastern International Bank.
On Saturday October 7, Far Eastern International Bank reported that it had recovered most of the money and that overall losses could reach $500,000.
How did the attack happen?
Based on the initial intelligence we have received, the first direct interaction with the victim began with spear phishing attacks that contained “backdoor” attachments.
Figures 1 and 2 provide some examples of the attachments.
Figure 1: Spear phishing attachment.
Figure 2: Spear phishing attachment.
When the victim …