Cybercriminals Seized Control of Brazilian Bank for 5 Hours

  /     /     /  
Publicated : 22/11/2024   Category : security


Cybercriminals Seized Control of Brazilian Bank for 5 Hours


Sophisticated heist compromised major banks entire DNS infrastructure.



KASPERSKY SECURITY SUMMIT 2017 – St. Maarten – Cybercriminals for five hours one day last fall took over the online operations of a major bank and intercepted all of its online banking, mobile, point-of-sale, ATM, and investment transactions in an intricate attack that employed valid SSL digital certificates and Google Cloud to support the phony bank infrastructure.
The attackers compromised 36 of the banks domains, including its internal email and FTP servers, and captured electronic transactions during a five-hour period on Oct. 22, 2016. Researchers estimate that hundreds of thousands or possibly millions of the banks customers across 300 cities worldwide, including in the US, may have been victimized during the hijack window when customers accessing the banks online services were hit with malware posing as a Trusteer banking security plug-in application. The malware harvested login credentials, email contact lists, and email and FTP credentials, and disabled anti-malware software on the victims machine to avoid detection.
Dmitry Bestuzhev, director of Kaspersky Labs research and analysis team in Latin America, says the attackers were able to pull off the heist by compromising the banks Domain Name Service (DNS) provider Registro.br and gained administrative control of the banks DNS account. The attackers also obtained valid digital certificates for their poser banks servers via Lets Encrypt, a legitimate HTTPS certificate provider, to dupe customers who, when they logged into their online accounts, were redirected to the phony systems. Meanwhile, the bank, which has $25 billion in assets, 5 million customers worldwide, and 500 branches in Brazil, Argentina, the US, and the Cayman Islands, was locked out of its own network and systems during the attack.
As far as we know, this type of attack has never happened before on such a big scale, Bestuzhev says. Kaspersky Lab did not disclose the name of the victim bank.
The operation actually began at least five months prior to the actual hijack on Saturday, Oct. 22. Bestuzhev says its unclear just how the attackers were able to compromise the DNS provider, but notes that Registro.br in January of this year patched a cross-site request forgery flaw on its website. Maybe they [the attackers] exploited the vulnerability on that website and got control. Or … We found several phishing emails targeting employees of that registrar, so they could have spear-phished them, he says. We dont know how exactly they originally compromised the DNS provider, he says.
The bank didnt deploy the two-factor authentication option offered by Registro.br, which left the financial institution vulnerable to an authentication-type attack as well as authentication-type flaws such as CSRF, Fabio Assolini, a Kaspersky Lab researcher said here today during a presentation about the bank hijack discovered by Kaspersky.
More Banks at Risk
The attackers also dropped on banking customer machines malware that targets a specific list of other banks in Brazil, the UK, Japan, Portugal, Italy, China, Argentina, the Cayman Islands, and the US, apparently in hopes of nabbing their accounts there as well. There were eight components of the malware, including the one that disabled or removed anti-malware software, all written in JAR and able to run on Windows and Mac systems. Once executed, the malware detection rate was very low, he says. Even if they failed at removing anti-virus, they were able to partially disable it.
A phishing campaign targeting specific bank clients also was set in motion in order to steal payment card information, and during the five-hour heist, the bank was unable to access its email system and alert its customers. The hijackers had complete control of the bank, Bestuzhev says.
The attackers routed stolen credentials and other information to a server in Canada, likely a disposable hosting setup, he says.
Bestuzhev says theres no way to defend against this type of targeted attack against infrastructure. Its the fragility of the Internet, he says. Most banks in Latin America rely on a third-party DNS provider for their infrastructure, and at least half of the top 20 largest banks in the world use DNS providers for some or all of their DNS infrastructure, he notes.
The bank ultimately regained control of its DNS infrastructure, but the victim machines could remain infected with the malware. The malware is persistent, Bestuzhev says. It stays on the computers and can keep causing damage to the victim.
Kaspersky Lab doesnt identify hacker groups, but believes the attackers were a sophisticated Brazilian cybercrime group.
They spent five months just waiting. This is not someone who is a newbie, Bestuzhev says.
Kaspersky Lab identified the malware used in the attack as Trojan-Downloader.Java.Agent; Trojan.BAT.Starter; not-a-virus:RiskTool.Win32.Deleter; and Trojan-Spy.Win32.Agent.
Related content:
Mandiant: Financial Cybercriminals Looking More Like Nation-States
The Interconnected Nature of International Cybercrime
 

Last News

▸ DHS-funded SWAMP scans code for bugs. ◂
Discovered: 23/12/2024
Category: security

▸ Debunking Machine Learning in Security. ◂
Discovered: 23/12/2024
Category: security

▸ Researchers create BlackForest to gather, link threat data. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Cybercriminals Seized Control of Brazilian Bank for 5 Hours