Impact:
·
US$13.5 million stolen from Cosmos Bank between August 10-13,
2018.
·
Cosmos Bank was forced to close its ATM operations and suspend
online and mobile banking facilities.
Scope:
·
Malware infection via social engineering
·
ATM switch compromise
·
SWIFT environment compromise.
Compromise Path
·
Initial infiltration (patient-zero compromise):
Based on the attribution, likely spear phishing and/or remote
administration/third-party interface.
o
Attribution: August 29, 2018: According to the latest
report from the Maharashtra Special Investigation Team performing the
investigation of the attack, they have not yet been able to link the attacks to
the Lazarus or Cobalt hacking groups, noting that the Cosmos bank attackers
“wiped out all tracks, leaving no evidence; it’s well-planned.” . The latter is
consistent with the behavior of major hacking groups, including Lazarus group,
that are known to use tools that wipe out all tracks and evidence. To illustrate,
according to the TrendMicro report on Lazarus Group operations from earlier
this year, Lazarus Group use wiper tools that remove Prefetch, event logs, MFT
records and other evidence from the compromised systems
·
lateral movement August 10-11, 2018, the bank’s internal and ATM infrastructure was
compromised. The exploit involved multiple targeted malware infections followed
by leveraging a set of malicious ISO8583 libraries and process code injections
to stand up a malicious ATM/POS switch (malicious-Central or MC) in parallel
with the existing Central and then selectively breaking the connection between
the Central and the backend/Core Banking System (CBS).
·
Compromise: After making adjustments to the target account balances to enable
withdrawals, MC was then likely used in fake off-us, on-us, foreign-to-EFT,
standing-in, etc. activity that enabled the malicious threat actor to authorize
specific primary account number (PANs) transactions to implement ATM
withdrawals for over US$11.5 million in 2849 domestic (Rupay) and 12,000
international (Visa) transactions using 450 cloned (non-EMV) debit cards in 28
countries.
·
Using MC, attackers were likely able to
send fake Transaction Reply (TRE)/ISO8583 x210 messages in response to
Transaction Request (TRQ) messages from cardholders and terminals. As a result,
the required ISO 8583 messages (e.g. x200), were never forwarded to the
backend/CBS from the ATM/POS switching solution that was compromised, which
enabled the malicious withdrawals and impacted the fraud detection capabilities
on the banking backend.
·
Exploit: On August 13th, 2018 the malicious threat actor
continued the attack against Cosmos Bank likely by moving laterally and using
the Cosmos bank’s SWIFT SAA environment LSO/RSO compromise/authentication to
send three malicious MT103 to ALM Trading Limited at Hang Seng Bank in Hong
Kong amounting to around US$2 million.
Vectors Used
·
Phishing to bring malware onto
comprised MC
·
Malware attack: The core
banking system (CBS) of the bank receives debit card payment requests via
a ‘switching system’. During the malware attack, a proxy switch was created,
and all the fraudulent payment approvals were passed by the proxy switching
system
·
ATM cash-out: The
cyber criminals typically create fraudulent copies of legitimate cards by
sending stolen card data to co-conspirators who imprint the data on reusable
magnetic strip cards, such as gift cards purchased at retail stores. At a
pre-determined time, the co-conspirators withdraw account funds from ATMs using
these cards. When depositors withdraw money at ATMs, a request is transferred
to the respective bank’s CBS. If the account has enough balance, the CBS will
allow the transaction. In the case of Cosmos Bank, the malware created a proxy
system that bypassed the CBS. While cloning the cards and using a
‘parallel’ or proxy switch system, the hackers were able to approve the
requests – withdrawing over INR 80.5 crore in approximately 15,000
transactions.
·
Possible
Sections of the Act impacted
The bank registered
an FIR at the Chatushringi police station in Pune. A case was
registered under Indian Penal Code (IPC) sections 379 (theft), 420 (cheating),120
(B) (conspiracy) and 34 and sections 43,65,66 (C) and 66 (D) of the Information
Technology Act Section 43A (Compensation for failure to protect data) of the
Information Technology Act, 2000
·
Section 66 (Computer-related offences) of the Information
Technology Act, 2000
·
Section 408 (criminal breach of trust by clerk or servant),
Indian Penal Code, 1860
No comments:
Post a Comment