Group IB has uncovered a massive campaign impersonating the Central Bank of Russia, targeting various Russian financial institutions. The emails were “disguised” and resembled real emails sent by the Central Bank of Russia and FinCERT. Group IB experts found that the November 15 attackcould have been carried out by the hacker group Silence, while the October 23 attack was carried outby MoneyTaker. Group IB considers these two hacker groups to be the most dangerous in Russia.

November Attack: Silence
On the morning of November 15, Group IB detected a campaign that was sending mass emails to all banks in Russia from a fake email address that appeared to belong to the CBR (Central Bank of Russia). Apparently, the CBR has nothing to do with the campaign. The campaign used a bank address (or at least it appeared to be spoofed), but not the SSL certificate that it should also be using. The email that was sent had the subject line “Information from the Central Bank of the Russian Federation”, and asked recipients to check the decision of a regulatory body. The files that recipients had to open were inside a compressed zip file, which, when opened, downloaded Silence.Downloader, the tool used by the Silence hackers. What Group IB researchers noticed was that the structure of the emails was identical to the one used by the bank, which means that the hackers somehow had samples at their disposal that they could copy. According to the Group IB report, members of Silence must have been or are still employed by the bank as penetrator testers or reverse engineers.
October Attack: MoneyTaker
The message, which was sent on October 23, also from a fake FinCERT email address, contained 5 attachments, identical to CBR files. 3 of the 5 were empty doc files, while the other two downloaded the Meterpreter Stager. To carry out the attack, the hackers used their own SSL Certificate, while using the same server they had used in their previous attacks, from which it was concluded that MoneyTaker was behind the October attack.
Group IB’s automated intrusion detection system immediately detected the campaign and alerted other banks to the malicious activity. “The MoneyTaker and Silence hacker groups are the two most dangerous groups targeting financial institutions. From their previous attacks, we have seen that they target organizations in every possible way they can think of. For example, they may send spear phishing emails, rob a physical store of the organization, or scan the organization’s network for potential vulnerabilities. Once they have gained access to an internal system of the organization, they can easily carry out destructive attacks, make ATM withdrawals, gain access to internal systems and much more. However, from their history of attacks, we conclude that they prefer phishing attacks, which they pay great attention to making them look real.
Group IB is a partner of INTERPOL, EUROPOL, and is recommended by SWIFT and the OSCE.
