INDEPENDENT NEWS

How the Lazarus Group is Emptying Millions from ATMs

Published: Fri 9 Nov 2018 11:02 AM
FASTCash: How the Lazarus Group is Emptying Millions from ATMs
Last month, the US government issued an alert that Lazarus has been conducting “FASTCash” attacks against ATMs from banks in Asia and Africa. Symantec researchers have since uncovered the key component used by Lazarus to fraudulently empty ATMs of cash.
Known initially for its espionage operations and high-profile attack against Sony Pictures, Symantec’s research shows increasing financial motivation behind the Lazarus group’s attacks, including the targeting of the Bangladesh Central Bank and the group’s WannaCry ransomware operation. This recent wave of FASTCash attacks demonstrates that financially motivated attacks are not simply a passing interest for Lazarus, but one of its core activities.
To make fraudulent withdrawals, Lazarus first breaches the banks’ networks and compromises the switch application servers handling ATM transactions.Once these servers are compromised, previously unknown malware (Trojan.Fastcash) is deployed, which intercepts fraudulent cash withdrawal requests and sends fake approval responses, in turn allowing the attackers to steal cash from ATMs.

Next in Business, Science, and Tech

Gaffer Tape And Glue Delivering New Zealand’s Mission Critical Services
By: John Mazenier
Ivan Skinner Award Winner Inspired By Real-life Earthquake Experience
By: Earthquake Commission
Consultation Opens On A Digital Currency For New Zealand
By: Reserve Bank
Ship Anchors May Cause Extensive And Long-lasting Damage To The Seafloor, According To New NIWA Research
By: NIWA
A Step Forward For Simpler Trade Between New Zealand And Singapore
By: New Zealand Customs Service
68% Say Make Banks Offer Fraud Protection
By: Horizon Research Limited
View as: DESKTOP | MOBILE © Scoop Media