TWO BYTES TO $951M
2016-04-25 • Bae Systems •
http://baesystemsai.blogspot.kr/2016/04/two-bytes-to-951m.html
BAE Systems analyzed custom malware linked to the Bangladesh Bank SWIFT heist, where attackers attempted to transfer $951 million and $81 million remained unaccounted for. The malware was built for an environment running SWIFT Alliance Access with an Oracle database, registered itself as a service, and parsed local SWIFT FIN messages to identify attacker-defined transaction strings. It could patch a SWIFT Alliance module in memory to bypass a conditional authorization check, then generate SQL statements to delete transaction records or manipulate balance-reporting data. The tooling also used an encrypted configuration file, local logging paths, and command-and-control callbacks tied to SWIFT login and logout events, showing detailed knowledge of the victim payment infrastructure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 4659dadbf5b07c8c3c36ae941f71b63… | 2016-04-25 | 2020-03-09 |
| HASH | ae086350239380f56470c19d6a200f7… | 2016-04-25 | 2020-03-09 |
| HASH | 5b7c970fee7ebe08d50665f278d47d0… | 2016-04-25 | 2020-03-09 |
| IPv4 | 196.202.103.174 | 2016-04-25 | 2016-08-25 |
| HASH | b07b37f0246bd436addbe5d702b1248… | 2016-04-25 | 2016-05-27 |