SWIFT, the organization that is supposed to provide banks with a secure network for sending and receiving information for financial transactions, issued a warning about a malware attack against another bank. They believe its customers are facing “a highly tailored campaign that specifically targets banks' payment points.”
In the previous case, in the robbery of the central bank of Bangladesh, the attackers were able to obtain valid administrator credentials, which allowed them to submit fake SWIFT messages, and to hide the evidence to cover the tracks of the fake messages.
“In this new case we saw that malicious software was used to target the PDF reader application used by the client to read the payment confirmation PDFs”, the company says.
“Once installed on an infected local machine, the PDF reader Trojan creates an icon and a description file that match those of the legitimate software. When a PDF file containing SWIFT confirmation messages is opened, the Trojan begins to modify the PDF, removing any trace that shows it has been tampered with.”
The company reports that the malicious software cannot create new or modify outgoing messages, and does not affect the SWIFT network, the interface software, or the provided messaging services.
“In both cases, the attackers exploit the vulnerable points that exist in the environments of the initiation of banks' capital transfers”, before the messages are sent via SWIFT,” they emphasized.
“Attackers clearly demonstrate a deep and specialized knowledge of special operational controls within the context of targeted attacks on banks. Knowledge that may have been acquired from malicious insiders (and naturally meaning some from within, aka bank staff) or previous cyber attacks, or a combination of both”
SWIFT did not identify the victim of the latest attack nor did it state whether the attack was ultimately successful.
Sergei Shevchenko and Adrian Nish, two BAE Systems analyzing the malware, revealed that the affected financial institution is a commercial bank in Vietnam.
With their analysis of the malicious software used in both attacks, they discovered that:
- The malicious software was custom-made in both cases.
- Both had the functions “file-wipe-out” and “file-delete”, which were the same or only minimally modified.
- The malware displays the same unique characteristics, such as mutex names, encryption keys, and other tools from a larger set of tools described in US-CERT advisory TA14-353A, the same advisory that described the 2014 attack on Sony Entertainment.
- It contains some of the same errors, and presents elements that were developed in the same environment.
“The overlaps between these samples provide strong connections for the same encoder that is behind the recent hypotheses with the bank robbery and a more widely known campaign that goes back almost a decade.”
“It is possible that this specific delete function of the deletion files exists as shared code, which many developers share who are looking to achieve similar results. However, we have seen that this code is not publicly available or is not included in any other software when searching through tens of millions of files. ”
In the meantime, SWIFT has called on its customers to review the controls in their payment environments, across all messages, their payments and the eBanking channels they use, and if they have suffered an attack, to share the information they have with SWIFT and the authorities.
