Wednesday, January 13, 2021

Case Study - Cyberattack on Cosmos Bank

 Impact:

·         US$13.5 million stolen from Cosmos Bank between August 10-13, 2018.

·         Cosmos Bank was forced to close its ATM operations and suspend online and mobile banking facilities.

Scope: 

·         Malware infection via social engineering

·         ATM switch compromise

·         SWIFT environment compromise.

Compromise Path

·         Initial infiltration (patient-zero compromise):  Based on the attribution, likely spear phishing and/or remote administration/third-party interface.

o   Attribution:  August 29, 2018: According to the latest report from the Maharashtra Special Investigation Team performing the investigation of the attack, they have not yet been able to link the attacks to the Lazarus or Cobalt hacking groups, noting that the Cosmos bank attackers “wiped out all tracks, leaving no evidence; it’s well-planned.” . The latter is consistent with the behavior of major hacking groups, including Lazarus group, that are known to use tools that wipe out all tracks and evidence. To illustrate, according to the TrendMicro report on Lazarus Group operations from earlier this year, Lazarus Group use wiper tools that remove Prefetch, event logs, MFT records and other evidence from the compromised systems

·         lateral movement August 10-11, 2018, the bank’s internal and ATM infrastructure was compromised. The exploit involved multiple targeted malware infections followed by leveraging a set of malicious ISO8583 libraries and process code injections to stand up a malicious ATM/POS switch (malicious-Central or MC) in parallel with the existing Central and then selectively breaking the connection between the Central and the backend/Core Banking System (CBS).

·         Compromise: After making adjustments to the target account balances to enable withdrawals, MC was then likely used in fake off-us, on-us, foreign-to-EFT, standing-in, etc. activity that enabled the malicious threat actor to authorize specific primary account number (PANs) transactions to implement ATM withdrawals for over US$11.5 million in 2849 domestic (Rupay) and 12,000 international (Visa) transactions using 450 cloned (non-EMV) debit cards in 28 countries.

·         Using MC, attackers were likely able to send fake Transaction Reply (TRE)/ISO8583 x210 messages in response to Transaction Request (TRQ) messages from cardholders and terminals. As a result, the required ISO 8583 messages (e.g. x200), were never forwarded to the backend/CBS from the ATM/POS switching solution that was compromised, which enabled the malicious withdrawals and impacted the fraud detection capabilities on the banking backend.

·         Exploit: On August 13th, 2018 the malicious threat actor continued the attack against Cosmos Bank likely by moving laterally and using the Cosmos bank’s SWIFT SAA environment LSO/RSO compromise/authentication to send three malicious MT103 to ALM Trading Limited at Hang Seng Bank in Hong Kong amounting to around US$2 million.

Vectors Used

·         Phishing to bring malware onto comprised MC

·         Malware attack: The core banking system (CBS) of the bank receives debit card payment requests via a ‘switching system’. During the malware attack, a proxy switch was created, and all the fraudulent payment approvals were passed by the proxy switching system

·         ATM cash-out: The cyber criminals typically create fraudulent copies of legitimate cards by sending stolen card data to co-conspirators who imprint the data on reusable magnetic strip cards, such as gift cards purchased at retail stores. At a pre-determined time, the co-conspirators withdraw account funds from ATMs using these cards. When depositors withdraw money at ATMs, a request is transferred to the respective bank’s CBS. If the account has enough balance, the CBS will allow the transaction. In the case of Cosmos Bank, the malware created a proxy system that bypassed the CBS. While cloning the cards and using a ‘parallel’ or proxy switch system, the hackers were able to approve the requests – withdrawing over INR 80.5 crore in approximately 15,000 transactions.

·          

Possible Sections of the Act impacted

The bank registered an FIR at the Chatushringi police station in Pune. A case was registered under Indian Penal Code (IPC) sections 379 (theft), 420 (cheating),120 (B) (conspiracy) and 34 and sections 43,65,66 (C) and 66 (D) of the Information Technology Act Section 43A (Compensation for failure to protect data) of the Information Technology Act, 2000

·         Section 66 (Computer-related offences) of the Information Technology Act, 2000

·       Section 408 (criminal breach of trust by clerk or servant), Indian Penal Code, 1860

No comments:

Post a Comment

The Priority Gap: When Patchability Does Not Equal Protection

Vulnerability management often fails at the point where security mandates collide with IT operations, creating a Priority Gap between vulne...