Showing posts with label Natasha Deteran. Show all posts
Showing posts with label Natasha Deteran. Show all posts

Tuesday, April 26, 2016

SWIFT network says aware of multiple cyber fraud incidents


SWIFT, the global financial network that banks use to transfer billions of dollars every day, warned its customers on Monday that it was aware of "a number of recent cyber incidents" where attackers had sent fraudulent messages over its system.

The disclosure came as law enforcement authorities in Bangladesh and elsewhere investigated the February cyber theft of $81 million from the Bangladesh central bank account at the New York Federal Reserve Bank. SWIFT has acknowledged that the scheme involved altering SWIFT software on Bangladesh Bank's computers to hide evidence of fraudulent transfers.

Monday's statement from SWIFT marked the first acknowledgement that the Bangladesh Bank attack was not an isolated incident but one of several recent criminal schemes that aimed to take advantage of the global messaging platform used by some 11,000 financial institutions.

"SWIFT is aware of a number of recent cyber incidents in which malicious insiders or external attackers have managed to submit SWIFT messages from financial institutions' back-offices, PCs or workstations connected to their local interface to the SWIFT network," the group warned customers on Monday in a notice seen by Reuters.

The warning, which SWIFT issued in a confidential alert sent over its network, did not name any victims or disclose the value of any losses from the previously undisclosed attacks. SWIFT confirmed to Reuters the authenticity of the notice.

SWIFT, or the Society for Worldwide Interbank Financial Telecommunication, is a cooperative owned by 3,000 financial institutions.

Also on Monday, SWIFT released a security update to the software that banks use to access its network to thwart malware that security researchers with British defense contractor BAE Systems said was probably used by hackers in the Bangladesh Bank heist.

BAE's evidence suggested that hackers manipulated SWIFT's Alliance Access server software, which banks use to interface with SWIFT's messaging platform, to cover their tracks.

BAE said it could not explain how the fraudulent orders were created and pushed through the system.

But SWIFT provided some evidence about how that happened in its note to customers, saying that in most cases the modus operandi was similar.

It said the attackers obtained valid credentials for operators authorized to create and approve SWIFT messages, then submitted fraudulent messages by impersonating those people.

FireEye, the internet security company whose Mandiant unit was hired by Bangladesh Bank to help investigate the heist, said the same group behind that hack had probably attacked other financial targets.

"FireEye has observed activity in other financial services organizations that is likely by the same threat actor behind the cyber attack on the Bank of Bangladesh," Vivek Chudgar, Mandiant's senior director for the Asia Pacific said in a statement emailed to Reuters.

FireEye declined to go into detail.

Rakesh Asthana, the World Informatix Cyber Security CEO, who is overseeing Bangladesh Bank's probe into the hack, declined to discuss the other attacks that SWIFT referred to.

But he urged banks to conduct independent security assessments to make sure their networks are secure and prevent future attacks.

“SWIFT builds on security practices established by the customer itself and therefore it is imperative that in the wake of this attack, customers using SWIFT Alliance Access must strengthen their cyber security posture,” Asthana said

FOLLOWING THE MONEY

Cyber security experts said more attacks could surface as SWIFT's banking clients look to see if their SWIFT access has been compromised.

Shane Shook, a banking security consultant who investigates large financial crime, said hackers were turning to SWIFT and other private financial messaging platforms because such attacks can generate more revenue than going after consumers or small businesses.

"These hacks specifically target financial institutions because smaller efforts result in much larger thefts," he said. "It's much more efficient than stealing from consumers."

Justin Harvey, chief security officer with Fidelis Cybersecurity, said hackers followed the money and would be drawn into such schemes in hopes of emulating a big heist like the one on Bangladesh Bank.

"After the Bangladesh Bank heist became public, every other attacker out there is looking to see if they can do the same," he said.

SWIFT spokeswoman Natasha Deteran told Reuters that the commonality in these cases was that internal or external attackers compromised the banks’ own environments to obtain valid operator credentials.

"Customers should do their utmost to protect against this," she said in an email to Reuters.

SWIFT told customers that the security update must be installed by May 12.

"We have made the Alliance interface software update mandatory as it is designed to help banks identify situations in which attackers have attempted to hide their traces - whether these actions have been executed manually or through malware," she said.

source: www.abs-cbnnews.com

Monday, April 25, 2016

Bangladesh Bank hackers compromised SWIFT software


The attackers who stole $81 million from the Bangladesh central bank probably hacked into software from the SWIFT financial platform that is at the heart of the global financial system, said security researchers at British defense contractor BAE Systems.

SWIFT, a cooperative owned by 3,000 financial institutions, confirmed to Reuters that it was aware of malware targeting its client software. Its spokeswoman Natasha Deteran said SWIFT would release on Monday a software update to thwart the malware, along with a special warning for financial institutions to scrutinize their security procedures.

The new developments now coming to light in the unprecedented cyber-heist suggest that an essential lynchpin of the global financial system could be more vulnerable than previously understood to hacking attacks, due to the vulnerabilities that enabled attackers to modify SWIFT's client software.

Deteran told Reuters on Sunday that it was issuing the software update "to assist customers in enhancing their security and to spot inconsistencies in their local database records."

The software update and warning from Brussels-based SWIFT, or the Society for Worldwide Interbank Financial Telecommunication, come after researchers at BAE, which has a large cyber-security business, told Reuters they believe they discovered malware that the Bangladesh Bank attackers used to manipulate SWIFT client software known as Alliance Access.

BAE said it planned to go public on Monday with a blog post about its findings concerning the malware, which the thieves used to cover their tracks and delay discovery of the heist.

The cyber criminals tried to make fraudulent transfers totaling $951 million from the Bangladesh central bank's account at the Federal Reserve Bank of New York in February.

Most of the payments were blocked, but $81 million was routed to accounts in the Philippines and diverted to casinos there. Most of those funds remain missing.



Investigators probing the heist had previously said the still-unidentified hackers had broken into Bangladesh Bank computers and taken control of credentials that were used to log into the SWIFT system. But the BAE research shows that the SWIFT software on the bank computers was probably compromised in order to erase records of illicit transfers.

Deteran reiterated on Sunday that "the malware has no impact on SWIFT's network or core messaging services."

The SWIFT messaging platform is used by 11,000 banks and other institutions around the world, though only some use the Alliance Access software, Deteran said.

SWIFT may release additional updates as it learns more about the attack in Bangladesh and other potential threats, Deteran said.

SWIFT is also reiterating a warning to banks that they should review internal security.

"While we keep all our interface products under continual review and recommend that other vendors do the same, the key defense against such attack scenarios is that users implement appropriate security measures in their local environments to safeguard their systems," Deteran said.

Adrian Nish, BAE's head of threat intelligence, said he had never seen such an elaborate scheme from criminal hackers.

"I can't think of a case where we have seen a criminal go to the level of effort to customize it for the environment they were operating in," he said. "I guess it was the realization that the potential payoff made that effort worthwhile."

A Bangladesh Bank spokesman declined comment on BAE's findings.

A senior official with the Bangladesh Police's Criminal Investigation Department said that investigators had not found the specific malware described by BAE, but that forensics experts had not finished their probe.

Bangladesh police investigators said last week that the bank's computer security measures were seriously deficient, lacking even basic precautions like firewalls and relying on used, $10 switches in its local networks.

Still, police investigators told Reuters in an interview that both the bank and SWIFT should take the blame for the problems.

"It was their responsibility to point it out but we haven't found any evidence that they advised before the heist," said Mohammad Shah Alam, head of the Forensic Training Institute of the Bangladesh police's criminal investigation department, referring to SWIFT.

THWARTING FUTURE ATTACKS

The BAE alert to be published on Monday includes some technical indicators that the firm said it hopes banks could use to thwart similar attacks. Those indicators include the IP address of a server in Egypt the attackers used to monitor use of the SWIFT system by Bangladesh Bank staff.

The malware, named evtdiag.exe, was designed to hide the hacker's tracks by changing information on a SWIFT database at Bangladesh Bank that tracks information about transfer requests, according to BAE.

BAE said that evtdiag.exe was likely part of a broader attack toolkit that was installed after the attackers obtained administrator credentials.

It is still not clear exactly how the hackers ordered the money transfers.

Nish said that BAE found evtdiag.exe on a malware repository and had not directly analyzed the infected servers. Such repositories collect millions of new samples a day from researchers, businesses, government agencies and members of the public who upload files to see if they are recognized as malicious and help thwart future attacks.

Nish said he was highly confident the malware was used in the attack because it was compiled close to the date of the heist, contained detailed information about the bank's operations and was uploaded from Bangladesh.

While that malware was specifically written to attack Bangladesh Bank, "the general tools, techniques and procedures used in the attack may allow the gang to strike again," according to a draft of the warning that BAE shared with Reuters.

The malware was designed to make a slight change to code of the Access Alliance software installed at Bangladesh Bank, giving attackers the ability to modify a database that logged the bank's activity over the SWIFT network, Nish said.

Once it had established a foothold, the malware could delete records of outgoing transfer requests altogether from the database and also intercept incoming messages confirming transfers ordered by the hackers, Nish said.

It was able to then manipulate account balances on logs to prevent the heist from being discovered until after the funds had been laundered.

It also manipulated a printer that produced hard copies of transfer requests so that the bank would not identify the attack through those printouts, he said.

source: www.abs-cbnnews.com