New wave of cyberattacks against global banks linked to Lazarus cybercrime group

1486992913 wall street

wall-street.jpg

Almost 20 US banks have been specifically targeted by Lazarus hackers.


Image: iStock

An aggressive campaign of malware attacks against dozens of banks across the globe has been linked to the notorious cybercriminal group known as Lazarus.

The hacking gang, active since 2009, has been involved in a number of aggressive cyberattacks against financial institutions, including the theft of $81m from the Bangladesh Bank’s US Federal Reserve.

ADVERTISEMENT

Now the group continues to be a thorn in the side of organisations across the globe as banks in 31 countries have been targeted in a new wave of attacks by Lazarus that began in October last year.

This latest wave of attacks came to light when a Polish bank discovered previously unknown malware on its network and shared indicators of compromise with other institutions, a number of which also found they’d fallen victim to the malware.

The source of the attack is suspected to have been the website of the Polish financial regulator, which was compromised by hackers who used a watering hole attack to redirect visitors to an exploit kit. This exploit kit infected specific targets with malware that’s instructed to only infect visitors from around 150 different IP addresses.

While these are mostly banks, a small number of telecommunications and internet firms have also been targeted by this malware scheme, which takes aim at 104 organisations in 31 countries. Banks in Poland and the United States are most targeted by Lazarus in this attack, which also hit a number of banks in Central and South America.

434-fig1-top-countries-targeted.png

Top countries targeted by Lazarus attackers since October 2016.


Image: Symantec

The malware used in the latest attacks was previously unidentified, but researchers at Symantec have analysed the malicious software and have discovered that the code shares common traits with the Lazarus group.

Identified as Ratankba, the malware contacts a command-and-control hub before downloading HackTool, a virus that shares distinctive characteristics associated with Lazarus. In addition to targeting banks, the Lazarus gang has also been linked to a Trojan attack on Sony Pictures Entertainment’s internal network.

Naturally, acting as large depositories of both money and financial data, banks are a lucrative target for hackers and therefore constantly face persistent and sophisticated cyberattacks, with institutions across the globe continually having their defences tested.

Read more on cybercrime

(via PCMag)

ADVERTISEMENT

ADVERTISEMENT
Just in:
Galaxy Macau’s Sakura Cultural Festival Kicked off in Splendor // Lee Chong Wei Shows Up On Chinese Hot cultural Talk Show “SHEDE Wisdom Talents”, Talking About “Crossing The Hill” // DIFC Courts Cement Role as Top English Dispute Resolution Choice // NetApp’s 2024 Cloud Complexity Report Reveals AI Disrupt or Die Era Unfolding Globally // World Intellectual Property Day: OPPO Maintains Top 10 Global IP Ranking for Fifth Consecutive Year // Crypto Market Poised for Boom as Baby Boomers Embrace Bitcoin ETFs // Forward Fashion’s Artelli Presents: Nobuyoshi Araki’s “Paradise” Starting from April 27th, at K11 MUSEA // Oman Seeks Growth Through Strategic Economic Alliances // World Football Federation Secures Sponsorship From Saudi Oil Giant // Telecom Giant Du Eyes Crypto Integration for FinTech Platform // Downpours in Oman and UAE Likely Amplified by Warming Planet // UAE President, Spanish Prime Minister Hold Phone Talks // Etihad Airways Announces Paris Service with A380 // Supreme Court dismisses pleas for 100% VVPAT verification // TPBank and Backbase Clinch ‘Best Omni-Channel Digital CX Solution’ at the Digital CX Awards 2024 // Andertoons by Mark Anderson for Fri, 26 Apr 2024 // Emirates to Embrace Electric Seaglider Travel // PolyU forms global partnership with ZEISS Vision Care to expand impact and accelerate market penetration of patented myopia control technology // GE Jun, Chairman and CEO of TOJOY, Delivers an Inspiring Speech: “Leaping Ahead Again” // Abu Dhabi Unveils Online Portal to Strengthen Healthcare Workforce //