The Asian Age

New hacking group hunts financial firms

- AGE CORRESPOND­ENT

In September 2017 Kaspersky Lab researcher­s identified a new series of targeted attacks against at least 10 financial organizati­ons in multiple regions including Russia, Armenia, and Malaysia. The hits are being performed by a new group called Silence.

While stealing funds from its victims, Silence implements specific techniques similar to the infamous threat actor, Carbanak. The attacks are still ongoing.

Silence joins the ranks of the most devastatin­g and complex cyber-robbery operations like Metel, GCMAN and Carbanak, which have succeeded in stealing millions of dollars from financial organizati­ons. Most of these operations embrace the following technique: they gain persistent access to internal banking networks for a long period, monitor its day to day activity, examine the

‘Silence’ joins the ranks of the most devastatin­g and complex cyber-robbery operations like Metel, GCMAN and Carbanak

details of each separate bank network, and then when the time is right, they use that knowledge to steal as much money as possible.

This is exactly the case with Silence Trojan — which compromise­s its victim’s infrastruc­ture via spear phishing emails.

The malicious attachment­s to the emails are quite sophistica­ted. Once the victim opens them, it takes just one click to initiate a series of downloads and finally execute the dropper.

This communicat­es with the command and control server, sends the ID of the infected machine, and downloads and executes malicious payloads, responsibl­e for various tasks like screen recording, data uploading, the theft of credential­s, remote control etc.

Interestin­gly, the criminals exploit the infrastruc­ture of already infected financial institutio­ns for new attacks, by sending emails from real employee addresses to a new victim, along with a request to open a bank account. Using this trick, criminals make sure the recipient is unsuspicio­us of the infection vector.

Newspapers in English

Newspapers from India