Security News > 2022 > March > Hackers Target Bank Networks with new Rootkit to Steal Money from ATM Machines

Hackers Target Bank Networks with new Rootkit to Steal Money from ATM Machines
2022-03-20 22:48

A financially motivated threat actor has been observed deploying a previously unknown rootkit targeting Oracle Solaris systems with the goal of compromising Automatic Teller Machine switching networks and carrying out unauthorized cash withdrawals at different banks using fraudulent cards.

The intrusions staged by the actor involve "a high degree of OPSEC and leverage both public and private malware, utilities, and scripts to remove evidence and hinder response efforts," Mandiant researchers said in a new report published this week.

Also put to use are two backdoors known as SLAPSTICK and TINYSHELL, both attributed to UNC1945 and are used to gain persistent remote access to mission-critical systems as well as shell execution and file transfers via rlogin, telnet, or SSH. "In line with the group's familiarity with Unix and Linux based systems, UNC2891 often named and configured their TINYSHELL backdoors with values that masqueraded as legitimate services that might be overlooked by investigators, such as systemd, name service cache daemon, and the Linux at daemon," the researchers pointed out.

WINGHOOK - A keylogger for Linux and Unix based operating systems that captures the data in an encoded format.

WINGCRACK - A utility that's used to parse the encoded content generated by WINGHOOK. WIPERIGHT - An ELF utility that erases log entries pertaining to a specific user on Linux and Unix based systems.

MIGLOGCLEANER - An ELF utility that wipes logs or remove certain strings from logs on Linux and Unix based systems.


News URL

https://thehackernews.com/2022/03/hackers-target-bank-networks-with-new.html