HomeinetFourth bank hacked by SWIFT hackers

Fourth bank hacked by SWIFT hackers

A fourth bank, this time in the Philippines, was attacked by hackers who target the SWIFT interbank transfer system.

Security researchers at Symantec report that it is the same group that carried out the infamous $81 million robbery at the central bank of Bangladesh last February, as well as another attack in the Philippines in 2015.hackers SWIFT

The same hacker group has also been accused of stealing $12 million from the Equatorial Bank Banco del Austro SA, which they again managed to breach the SWIFT system. The suspicions appear to be justified, as in all the aforementioned hacks, the same malware was used, a fact that indicates that behind this is the same group, according to Symantec.

Symantec has identified three malware that were used in limited targeted attacks against the financial sector in Southeast Asia: Backdoor.Fimlis, Backdoor.Fimlis.B and Backdoor.Contopee.

It is not yet clear what the motives behind these attacks are, however, there is a common code base in Trojan.Banswift (which was used in the Bangladesh bank attack to manipulate the SWIFT system) and in the variants of Backdoor.Contopee.

All of the above malware also use a common practice. They delete the malicious code to cover up the bank attacks and, more generally, their traces. This particular practice matches the one used in the Sony Pictures attacks, according to researchers at Symnatec.

Symantec believes that malicious code is shared among malware and the fact that Backdoor.Contopee was used in limited targeted attacks against financial institutions in the region means that these tools can be attributed to the same hacking group.

The Backdoor.Contopee has been used in the past by attackers associated with a group known as Lazarus. The Lazarus group has been linked to a series of attacks in 2009, which focused largely on targets in the USA and South Korea. The group was linked to Backdoor.Destover, a particularly destructive Trojan that even caused the FBI to issue a warning after its use in an attack against Sony Pictures Entertainment. The FBI then concluded that the North Korean government was responsible for this attack.

How deep is the rabbit hole?

There are indications that attacks on SWIFT (Society for Worldwide Interbank Financial Telecom) started as early as October 2015, with the bank in the Philippines being the first victim, two months before the discovery of the failed attack on Tien Phong Bank in Vietnam.

Some of the tools used against the Bank of the Philippines have many similarities in the code to the malware used by Lazarus, the group behind the Sony Pictures breach. The US government has repeatedly accused North Korea of the hack on Sony Pictures in November 2014.

Symantec's findings point once again to North Korea.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS