Menu
Bangladesh Bank attackers used custom malware that hijacked SWIFT software

Bangladesh Bank attackers used custom malware that hijacked SWIFT software

The malware deleted transaction records from the database and printed out altered SWIFT confirmation messages, researchers say

The hackers who stole US $81 million from Bangladesh's central bank likely used custom malware designed to interfere with the SWIFT transaction software used by many financial institutions.

The attackers attempted to transfer $951 million out of Bangladesh Bank's account at the Federal Reserve Bank of New York in February, but most of the transfers were blocked before completion. The attackers did manage to send $81 million to accounts in the Philippines, and that money is still missing.

Researchers from BAE Systems have recently come across several malware components that they believe are part of a custom attack toolkit that was likely used in the heist.

The samples were uploaded to online malware repositories by someone in Bangladesh and they are designed to monitor, delete and alter transaction records in the database used by the SWIFT client software.

Brussels-based SWIFT, or the Society for Worldwide Interbank Financial Telecommunication, is a cooperative society owned by thousands of financial institutions that runs the world's largest secure financial messaging network.

One of the malware components bypasses a validation check in a library that's part of SWIFT's Alliance software suite, which stores transaction records in an Oracle Database, the BAE researchers said in a blog post Monday.

The rogue program then monitors SWIFT Financial Application messages for strings defined in an encrypted configuration file. When it detects a matching one, it identifies the corresponding database entry and deletes it.

The malware also monitors for login and logout events in the application and notifies command-and-control servers when they are detected.

Finally, the program can manipulate confirmation SWIFT messages, which are automatically printed out on paper by the bank's systems. Altering database records is not enough to hide fraudulent transactions because these printed confirmation messages could give an attack away, the BAE researchers said.

There are still many unknowns about the well-planned Bangladesh Bank heist, such as who was behind it, how they got into the bank's network in the first place, and how they initiated the rogue transfers. However, the existence of this custom malware toolkit should serve as a warning to other financial institutions.

"This malware was written bespoke for attacking a specific victim infrastructure, but the general tools, techniques and procedures used in the attack may allow the gang to strike again," the BAE researchers said. "All financial institutions who run SWIFT Alliance Access and similar systems should be seriously reviewing their security now to make sure they too are not exposed."

SWIFT is aware of the malware's existence. However, the program doesn't impact SWIFT's network or core messaging services, the organization said in an emailed statement.

"We understand that the malware is designed to hide the traces of fraudulent payments from customers’ local database applications and can only be installed on users’ local systems by attackers that have successfully identified and exploited weaknesses in their local security," SWIFT said.

"We have developed a facility to assist customers in enhancing their security and to spot inconsistencies in their local database records," the organization added. "However, the key defence against such attack scenarios remains for users to implement appropriate security measures in their local environments to safeguard their systems -- in particular those used to access SWIFT -- against such potential security threats."

According to investigators, one factor that contributed to the success of the attack against Bangladesh's central bank was the lack of proper segmentation between the bank's SWIFT systems and the rest of its network. The SWIFT-connected computers were linked to the network via cheap switches with no management capability and lacking a firewall, Reuters reported Friday.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Brand Post

What to expect from your IT Distributor

Whether you’re just starting out or you’ve been around since before the dot com rollercoaster, choosing the right distribution partner can be a pivotal factor in your success. This definitive guide outlines the traits that every IT partner needs to look for in their IT Distributor.

Featured

Slideshows

Channel gathers to celebrate the Reseller News Innovation Awards 2020 winners

Channel gathers to celebrate the Reseller News Innovation Awards 2020 winners

More than 500 channel leaders gathered in Auckland on 21 October at the ​Reseller News Innovation Awards ​2020 to celebrate the achievements of the New Zealand technology industry's top partners, start-ups, vendors, distributors and individuals.

Channel gathers to celebrate the Reseller News Innovation Awards 2020 winners
Meet the winners of the 2020 Reseller News Innovation Awards

Meet the winners of the 2020 Reseller News Innovation Awards

Reseller News honoured the standout players of the New Zealand channel in front of more than 500 technology leaders in Auckland on 21 October, recognising the achievements of top partners, start-ups, vendors, distributors and individuals.

Meet the winners of the 2020 Reseller News Innovation Awards
Meet the Reseller News 30 Under 30 Tech Awards 2020 winners

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners

This year’s Reseller News 30 Under 30 Tech Awards were held as an integral part of the first entirely virtual Emerging Leaders​ forum, an annual event dedicated to identifying, educating and showcasing the New Zealand technology market’s rising stars. The 30 Under 30 Tech Awards 2020 recognised the outstanding achievements and business excellence of 30 talented individuals​, across both young leaders and those just starting out. In this slideshow, Reseller News honours this year's winners and captures their thoughts about how their ideas of leadership have changed over time.​

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners
Show Comments