Russian APT28 hacking crew plans bank attacks – A security firm is warning that a group of Russian hackers known for targeting the military, government and news organizations is now preparing to attack banks in the US and elsewhere.
The group's preparations include writing new malware, registering domain names similar to those of intended targets, and installing command-and-control servers, which were discovered by analysts at security firm Root9B.
The group has been active since at least 2007 and is known by various names including APT28 and Pawn Storm. Several security vendors believe it is based in Russia and has possible links to the country's intelligence agencies.
The group's main malware tool is a backdoor program called Sednit or Sofacy, which it sends to victims via spear-phishing emails or via drive-by downloads promoted by compatible websites.
Root9B analysts stumbled upon a phishing domain in late April. Whenthey dugdeeper, they discovered new Sofacy malware samples and servers and domains that had been set up by the group for an upcoming operation.
Based on the information gathered so far, Root9B believes that the group's planned targets include Commercial Bank International, Bank of America, TD Canada Trust, the United Nations Children's Fund (UNICEF), United Bank for Africa, Regions Bank, and possibly Commerzbank.
The company has alerted organizations, as well as international and US authorities. It is unclear whether the attacks have yet begun, but Root9B analysts believe that when they do, they will likely involve spear-phishing.


