Breaking News

Sigma Unveils 200mm f/2 DG OS Sports and 12mm F/1.4 DC lens SSSTC Launches World's First Industrial M.2 SSD Featuring KIOXIA’s 8th generation BiCS and PCIe 5.0 Interface Lexar presents new products at Gamescom 2025 Samsung Introduces Galaxy Buds3 FE Samsung Expands Super Big TV Lineup with 115-Inch Neo QLED 4K TV

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Multiple Banks Attacked by Hacker Group, Symantec Says

Multiple Banks Attacked by Hacker Group, Symantec Says

Enterprise & IT Oct 11,2016 0

Symantec has found evidence that a hacking group dubbed Odinaff has mounted attacks on SWIFT users, using malware to hide customers’ own records of SWIFT messages relating to fraudulent transactions. The research firm said that a group as infected 10 to 20 Symantec customers with malware that can be used to hide fraudulent transfer requests made over SWIFT, the messaging system that is a lynchpin of the global financial system.

SWIFT Chief Executive Gottfried Leibbrandt last month told customers about three hacks and warned that cyber attacks on banks are poised to rise.

The hacking tools used are designed to monitor customers’ local message logs for keywords relating to certain transactions. They will then move these logs out of customers' local SWIFT software environment. However, Symantec says it has no indication that SWIFT network was itself compromised.

These "suppressor" components are tiny executables written in C, which monitor certain folders for files that contain specific text strings. Among the strings seen by Symantec are references to dates and specific International Bank Account Numbers (IBANs).

Each executable appears to be tailored to for a target system. One of the files found along with the suppressor was a small disk wiper which overwrites the first 512 bytes of the hard drive. This area contains the Master Boot Record (MBR) which is required for the drive to be accessible without special tools. SYmnatec's researchers believe this tool is used to cover the attackers’ tracks when they abandon the system and/or to thwart investigations.

Symantec in May said it believed the a high-profile February attack on Bangladesh's central bank was carried out by a group known as Lazarus, which was also responsible for attacks on SWIFT customers in Southeast Asia as well as the 2014 hack of Sony Pictures Entertainment.

Symnatec said that the attacks involving Odinaff share some links to the Carbanak group, whose activities became public in late 2014. Carbanak also specializes in high value attacks against financial institutions and has been implicated in a string of attacks against banks in addition to point of sale (PoS) intrusions.

The discovery of Odinaff indicates that banks are at a growing risk of attack. Over the past number of years, cybercriminals have begun to display a deep understanding of the internal financial systems used by banks. They have learned that banks employ a diverse range of systems and have invested time in finding out how they work and how employees operate them. When coupled with the high level of technical expertise available to some groups, these groups now pose a significant threat to any organization they target.

Tags: Hacking
Previous Post
Western Digital Introduces WD Blue And WD Green SSDs
Next Post
Samsung Exynos 7 Dual 7270 Application Processor for Wearable Devices Offers LTE Connectivity, Compact Size

Related Posts

  • MSI has been hacked, be warned about where you download files

  • Hackers gain access to PS5 Debug Menu and show decrypted PS5 firmware files

  • HP Threat Research Shows Attackers Exploiting Zero‐Day Vulnerability Before Enterprises Can Patch

  • EA Gets hacked - 780GB of data and sourcecode stolen

  • European Supercomputers Researching Covid-19 Report Hacking Attacks

  • Microsoft Offers You $100,000 If You Can Hack the Linux-based Azure Sphere

  • Zoom Users' Data have Been on Sale on Dark Web: report

  • Indonesia's Tokopedia Inverstigates Alleged Data Leak of 91 Million Users

Latest News

Sigma Unveils 200mm f/2 DG OS Sports and 12mm F/1.4 DC lens
Cameras

Sigma Unveils 200mm f/2 DG OS Sports and 12mm F/1.4 DC lens

SSSTC Launches World's First Industrial M.2 SSD Featuring KIOXIA’s 8th generation BiCS and PCIe 5.0 Interface
Enterprise & IT

SSSTC Launches World's First Industrial M.2 SSD Featuring KIOXIA’s 8th generation BiCS and PCIe 5.0 Interface

Lexar presents new products at Gamescom 2025
PC components

Lexar presents new products at Gamescom 2025

Samsung Introduces Galaxy Buds3 FE
Smartphones

Samsung Introduces Galaxy Buds3 FE

Samsung Expands Super Big TV Lineup with 115-Inch Neo QLED 4K TV
Consumer Electronics

Samsung Expands Super Big TV Lineup with 115-Inch Neo QLED 4K TV

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Noctua NH-D15 G2

Noctua NH-D15 G2

Soundpeats Pop Clip

Soundpeats Pop Clip

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

be quiet! Pure Base 501

be quiet! Pure Base 501

Terramaster F8-SSD

Terramaster F8-SSD

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed