Showing posts with label Carbanak Banking Malware. Show all posts
Showing posts with label Carbanak Banking Malware. Show all posts

Tuesday, 26 May 2015

Server Digital Bank Robbery Points To Russian Secret Service


Researchers from the Japanese anti-virus company Trend Micro were strange to look at when a server that was used in a bank robbery comprehensive digital suddenly pointed to an IP address of the Russian secret service FSB. Late last and early this year warned security for a group of attackers, called "Anunak "or" Carbanak "who knew to break through malware with banks and tens of millions of euros booty made.

The malware was driven by the gang used several domain names, as Command & Control (C & C) server functioned. Since the revelations infrastructure Carbanak monitored. Last week was the IP address of one of the C & C domains suddenly turned and pointed to an IP address of the FSB, let analyst Maxim Goncharov know. He does not think the FSB of adjustment and is therefore suspect that it is a joke of the domain owner, though a blunder also not excluded.

Tuesday, 17 February 2015

Banks Hacked And Robbed By Missing Word Updates


About a hundred banks and financial institutions for a period of two years by cyber criminals hacked and robbed because security updates for Microsoft Word had not been installed. According to a published today report of the Russian antivirus company Kaspersky Lab, the gang of cyber criminals gave the name Carnabak. This is the same gang that late last year by the Dutch Fox-IT and the Russian Group-IB was unmasked .

This weekend was the New York Times all with a message about the gang. It stated that Dutch banks had been targeted.Something later by both the Dutch banks as Kaspersky Lab was denied. In an old version of the report, which include Computer Emergency Reponse Teams (CERTs) was dispersed, the Netherlands was mentioned. However, it was in fact a false positive.

Although the New York Times Kaspersky had received a report that newer Netherlands ceased, it still used the information from the old report, says Jornt van der Wiel, analyst at Kaspersky Lab. Another detail that was highlighted in the media is wrong to use recording software. The gang has monitored no security cameras inside the attacked banks, but made ​​via software images from the desktop. This gave insight into the methods and processes within the banks.

It now appeared online report also shows how the attackers went to work. Bank employees who sent emails with Word documents, and in some cases, RAR files containing CPL files. However, there were mainly used Word documents, Van der Wiel. The documents were abuse of leaks in 2012, 2013 and 2014 all were patched by Microsoft. Patches that were missing on the attacked systems. There was in this operation no zero-day vulnerabilities. The advice given to both consumers and businesses, namely installing security updates timely, was not followed by the banks.

Once bank employees with a vulnerable version of Microsoft Office documents of the attackers opened there was malware installed on the system. In some cases, were also used RAR files there, including a CPL file. CPL (Control Panel) files are used for configuration Protect. The programs in the Control Panel as 'System', 'Printers' and 'Programs and Features', all CPL files. They are also used as malware. Furthermore, Kaspersky Lab says that there may be traces of classic drive-by download attacks are detected, in which bank staff when visiting a Web site became infected, but this is not confirmed yet.

Once the attackers had access to the system was installed additional software, such as the Ammyy Remote Administration Tool. Probably the attackers used this tool because it is on a whitelist in many environments. Ammyy gives administrators namely remote access to the computer. Then the attackers tried to steal the credentials of the system. For this, there were internal emails from the infected computers again sent infected Word files. In this way, could be infected, other systems on the network.

Eventually the attackers access to the transaction systems and made the money to other accounts or left-recording infected ATMs. Researchers have one shot where there is to see how someone at night with a bag goes to the ATM of a bank. At exactly 3:00 am spitting automatics the notes from that stopped and taken into the bag by the man.

The damage from the surgery is difficult to determine. Although in the media amounts of $ 1 billion mentioned, this amount is not confirmed. Kaspersky used a calculation method whereby a damage of $ 10 million per bank is used, although this amount is not stolen at all banks. Thus in the report but one victim mentioned that lost $ 10 million and a second bank where 7.3 million dollars were diverted.

Yet Kaspersky multiplied the amount of $ 10 million with 30 affected banks. In addition, there might also be some 30 banks that did not report and the police should also know of some 30 affected banks. For these banks, most of which are located in Russia, $ 10 million was used, eventually yielding an unconfirmed amount of around $ 900 million. The actual damage is probably about $ 300 million or maybe even much lower, Van der Wiel notes. Kaspersky also involves a battle report to hand.

What is certain is that the criminals to strike because the banks did not follow the basic rules for safe Internet, namely the installation of security updates, and do not open unsolicited attachments. Two of the hijacked Russian banks were due to the poor security of their banking license be lost. According to Kaspersky, the attackers are still active.

Monday, 16 February 2015

Gang That Stole Millions From Banks Last Year Already Unmasked


The gang of cyber criminals that this weekend the news was because they enable a billion dollars in banks around the world had been stolen last year by Dutch and Russian security unmasked . From when the published analysis showed that the attacks could have been prevented if the banks had installed security updates for Microsoft Word and employees had opened no exe files that were sent via email.

The Russian anti-virus firm Kaspersky Lab will later today make a report out on the Carnabak gang. The gang was last year in a report by the Delft Fox-IT and Russian Group-IB called "Anunak". The attack that the researchers of the two security companies which took begun infecting the computer of an employee. For example, documents were used in Word installed malware via known vulnerabilities.

If the system of the banks had installed the updates for these vulnerabilities, which since 2012 and 2013 are available, it would fail the attack. Also sent the attackers email attachments with exe files. In case this step was successful was then tried to steal the password of a user with administrator privileges. The next step consisted of getting access to a server.



Through the server password of the domain administrator was compromised. Hereafter all active domain accounts were taken over and monitor the attackers email traffic. The next step in the attack consisted of the compromise of the operator workstations of the bank system. In these systems, recording software was installed to record the process of the workers.Finally, there were changes made in the firewall configuration. Or the gang has adapted the method later applied or other tactics will only become clear once the report of Kaspersky online. but according to Fox-IT Carnabak and Anunak same group.

The examination of the two security companies further revealed that the criminals had access to ATMs and could infect remote malware to record at later times "free" money. The group had access to 50 Russian banks, five payment and sixteen companies. The damage amounted to 14 million dollars, according to the researchers. The attacks were at the time of publication are still going on in the december.

In an update , Fox-IT suggests that a different amount has named Kaspersky because it listed only the direct losses of Russian banks that could be verified. There was also in the report do not include damage caused by intellectual property theft and damage caused by downtime and repairs. Furthermore, Kaspersky Lab reports that banks in Europe and the US have become the target, while not appearing in the research of Fox-IT and Group-IB.

After publication of the report in December, the gang would have scaled back their activities. "The exact reason for this break is unclear, but he was already going for our report," said the researchers. At this time, the group would be not very active."But they can at any time to start again. Another possibility is that they have already started and we have no reports or evidence of their new activities."

Sunday, 15 February 2015

Cyber ​​Criminals Steal Millions From Banks Worldwide



A group of cyber criminals worldwide millions of dollars from more than 100 banks in 30 countries stolen.Most of the affected banks are located in Russia and the US, followed by banks in Germany, Ukraine and China. Dutch banks would not have been a target in contrast to previous reports.

This was discovered by the Russian anti-virus firm Kaspersky Lab on Monday a report on the operation will publish the cybercriminals, but part of all details with the New York Times reported. The Russian virus fighter came the criminals on the track when an ATM in Kiev randomly money bills issued without there was an ATM card in the machine plugged. Research showed that cyber criminals had infiltrated the internal banking network.


By sending infected e-mails, for example, a news item that appeared from a colleague who became infected by staff opened the bank computers. Through these computers knew the attackers to gain access to the systems that used the bank staff for daily transactions and accounting. Through the installed malware was then included the process of the bank employees.

This information used the criminals to pose as bank staff, where there are millions of banks in Russia, Japan, Switzerland and the United States was transferred to accounts in other countries. To include also the money the criminals ruled the ATMs of the bank, so that the expenses banknotes at a certain time. In addition, the money was transferred through online banking systems.

However, the largest amounts were stolen by hacking the accounting systems of the banks and temporarily change the account. For example, a bill of $ 1,000 to $ 10,000 raised, and $ 9,000 was transferred to another bank. The original account holder noticed nothing of this and the bank fraud after discovering some time. Many banks accounts were found to check every 10 hours. Within this time window, the criminals were able to change the accounts and transfer the money.


In total, were attacked according to Kaspersky Lab over a period of nearly two years, more than 100 banks in 30 countries.Which banks will want the anti-virus company can not say. Researchers from the virus fighter would have seen evidence that the gang $ 300 million has been captured and possibly even triple this. This estimate, however, would be impossible to prove because the criminals a limit of $ 10 million per transaction wielded.

Some banks, however, were repeatedly struck. The New York Times reports that most transactions were modest, probably in order not to let the warning systems of the banks go. "If going to the tactics and methods used by the cybercriminals to go unnoticed, this is probably the most sophisticated cyber attack that has taken place so far," said Chris Doggett of Kaspersky Lab.

Kaspersky Lab know that no Dutch bank or banks are affected there as previously reported, on which the article was adapted. In addition, would also no banks in Belgium and Luxembourg have been targeted. In the article by the New York Times, however, still always stated that money from one or more Dutch banks has been stolen. A survey of Kaspersky Lab shows that after Russia and the US banks in Germany, the Ukraine and China are most affected.

According to the virus fighter used the attackers emails with the attached "Carnabak-malware" and emails were also used with exploits. Or were these exploits of unknown leak or leaks which use an update was available is not yet published. However, the attackers would at banks have infected hundreds of computers to find the computer system, which then accesses the transaction systems were obtained.

Kaspersky Lab has also announced that the New York Times, the cooperation between the anti-virus company and the Dutch National High Tech Crime Unit (NHTCU) may have misinterpreted. The Russian virus fighter has information about the case is sent to the NHTCU. Further, the report will tomorrow during Kaspersky Security Analyst Summit (SAS) are presented, together with Peter Zinn of the NHTCU.

Possibly, the US newspaper based on this that Dutch banks have become victims. However, the Netherlands is in the report that tomorrow does not appear in the list of affected countries. Furthermore, Kaspersky Lab that it has no evidence that Dutch financial institutions have fallen victim.