TWO BYTES TO $951M

2016-04-25 • Bae Systems •

http://baesystemsai.blogspot.kr/2016/04/two-bytes-to-951m.html

Thumbnail for TWO BYTES TO $951M

BAE Systems analyzed custom malware linked to the Bangladesh Bank SWIFT heist, where attackers attempted to transfer $951 million and $81 million remained unaccounted for. The malware was built for an environment running SWIFT Alliance Access with an Oracle database, registered itself as a service, and parsed local SWIFT FIN messages to identify attacker-defined transaction strings. It could patch a SWIFT Alliance module in memory to bypass a conditional authorization check, then generate SQL statements to delete transaction records or manipulate balance-reporting data. The tooling also used an encrypted configuration file, local logging paths, and command-and-control callbacks tied to SWIFT login and logout events, showing detailed knowledge of the victim payment infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 4659dadbf5b07c8c3c36ae941f71b63… 2016-04-25 2020-03-09
HASH ae086350239380f56470c19d6a200f7… 2016-04-25 2020-03-09
HASH 5b7c970fee7ebe08d50665f278d47d0… 2016-04-25 2020-03-09
IPv4 196.202.103.174 2016-04-25 2016-08-25
HASH b07b37f0246bd436addbe5d702b1248… 2016-04-25 2016-05-27

Related Reports

« Back