Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Bank Hackers Linked to Wider Campaign: Researchers

The hackers behind the $81 million heist from the Bangladesh central bank have likely been involved in a series of attacks on the financial system, a US security firm has concluded.

The hackers behind the $81 million heist from the Bangladesh central bank have likely been involved in a series of attacks on the financial system, a US security firm has concluded.

Researchers at the security firm Symantec also found that the malware used in the bank hacks shares code with that used in the massive 2014 cyberattack against Sony Pictures.

Symantec said a bank in the Philippines has been attacked by the group that hit the Bangladesh central bank and attempted a heist from the Tien Phong Bank in Vietnam.

Malware used by the group was also deployed in targeted attacks against a bank in the Philippines. In addition to this, some of the tools used share code similarities with malware used in historic attacks linked to a threat group known as Lazarus,” Symantec researchers said in a blog post Thursday.

Hear About SWIFT Attacks at the CISO Forum on June 1

“The attacks can be traced back as far as October 2015, two months prior to the discovery of the failed attack in Vietnam, which was hitherto the earliest known incident.”

Advertisement. Scroll to continue reading.

News of the Bangladesh incident sparked a warning from the global financial interbank platform SWIFT, which earlier this month warned of a wide-ranging campaign.

SWIFT said this month that hackers exploited vulnerabilities at two unnamed banks to gain access to their fund transfer systems, which then give instructions to the SWIFT network.

Symantec said the malware found has been tied to the group known as Lazarus, blamed for the Sony attack which according to US officials had been ordered by North Korea.

“The discovery of more attacks provides further evidence that the group involved is conducting a wide campaign against financial targets in the region,” Symantec said.

“While awareness of the threat posed by the group has now been raised, its initial success may prompt other attack groups to launch similar attacks. Banks and other financial institutions should remain vigilant.”

Written By

AFP 2023

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.