https://arstechnica.com/security/2024/10/north-korean-hackers-use-newly-discovered-linux-malware-to-raid-atms/ Skip to content Ars Technica home Sections Forum Subscribe * AI * Biz & IT * Cars * Culture * Gaming * Health * Policy * Science * Security * Space * Tech * Feature * Reviews * Store * AI * Biz & IT * Cars * Culture * Gaming * Health * Policy * Science * Security * Space * Tech Forum Subscribe Theme * Light * Dark * System Search dialog... Search for: [ ] Search Sign In Sign in dialog... Sign in THAT WAS FAST North Korean hackers use newly discovered Linux malware to raid ATMs Once, FASTCash ran only on Unix. Then came Windows. Now it can target Linux, too. Dan Goodin - Oct 15, 2024 5:16 pm [north-korea-hacking] Credit: Getty Images 11 In the beginning, North Korean hackers compromised the banking infrastructure running AIX, IBM's proprietary version of Unix. Next, they hacked infrastructure running Windows. Now, the state-backed bank robbers have expanded their repertoire to include Linux. The malware, tracked under the name FASTCash, is a remote access tool that gets installed on payment switches inside compromised networks that handle payment card transactions. The US Cybersecurity and Infrastructure Security Agency first warned of FASTCash in 2018 in an advisory that said the malware was infecting AIX-powered switches inside retail payment networks. In 2020, the agency updated its guidance to report FASTCash was now infecting switches running Windows as well. Besides embracing Windows, FASTCash had also expanded its net to include not just switches for retail payments but those handled by regional interbank payment processors as well. Tampering with transaction messages on the fly Over the weekend, a researcher reported finding two samples of FASTCash for switches running on Linux. One sample is compiled for Ubuntu Linux 20.04 and was likely developed sometime after April 21, 2022. The other sample was likely not used. As of the time this post went live, only four anti-malware engines detected each sample. The number of detections as of Sunday was zero. The Linux version was uploaded to VirusTotal in June 2023. "Discovery of the Linux variant further emphasizes the need for adequate detection capabilities which are often lacking in Linux server environments," a researcher using the moniker haxrob wrote. The purpose of FASTCash is to compromise a key switch inside the complex networks that broker payment transactions among merchants and their banks on the one hand and, on the other, the payment card issuers who must approve a transaction. The particular switches targeted are deployed inside the interbank network that connects. The diagram below illustrates how transactions occur between the card issuers, listed as the issuing domain, and the merchant and merchant bank listed as the acquiring domain. [authorization-request-overview] Credit: haxrob Credit: haxrob The malware resides in the userspace portion of the interbank switch connecting the issuing domain and the acquiring domain. When a compromised card is used to make a fraudulent translation, FASTCash tampers with the messages the switch receives from issuers before relaying it back to the merchant bank. As a result, issuer messages denying the transaction are changed to approvals. The following diagram illustrates how FASTCash works: [fastcash-overview] Credit: haxrob Credit: haxrob The switches chosen for targeting run misconfigured implementations of ISO 8583, a messaging standard for financial transactions. The misconfigurations prevent message authentication mechanisms, such as those used by field 64 as defined in the specification, from working. As a result, the tampered messages created by FASTCash aren't detected as fraudulent. "FASTCash malware targets systems that ISO8583 messages at a specific intermediate host where security mechanisms that ensure the integrity of the messages are missing, and hence can be tampered," haxrob wrote. "If the messages were integrity protected, a field such as DE64 would likely include a MAC (message authentication code). As the standard does not define the algorithm, the MAC algorithm is implementation specific." The researcher went on to explain: FASTCash malware modifies transaction messages in a point in the network where tampering will not cause upstream or downstream systems to reject the message. A feasible position of interception would be where the ATM/PoS messages are converted from one format to another (For example, the interface between a proprietary protocol and some other form of an ISO8583 message) or when some other modification to the message is done by a process running in the switch. CISA said that BeagleBoyz--one of the names the North Korean hackers are tracked under--is a subset of HiddenCobra, an umbrella group backed by the government of that country. Since 2015, BeagleBoyz has attempted to steal nearly $2 billion. The malicious group, CISA said, has also "manipulated and, at times, rendered inoperable, critical computer systems at banks and other financial institutions." The haxrob report provides cryptographic hashes for tracking the two samples of the newly discovered Linux version and hashes for several newly discovered samples of FASTCash for Windows. Photo of Dan Goodin Dan Goodin Senior Security Editor Dan Goodin Senior Security Editor Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at @dangoodin on Mastodon. Contact him on Signal at DanArs.82. 11 View Comments Comments Forum view Loading Loading comments... Prev story Next story Most Read 1. Listing image for first story in Most Read: Routine dental X-rays are not backed by evidence--experts want it to stop 1. Routine dental X-rays are not backed by evidence--experts want it to stop 2. 2. Apple study exposes deep cracks in LLMs' "reasoning" capabilities 3. 3. Invisible text that AI chatbots understand and humans can't? Yep, it's a thing. 4. 4. Expert witness used Copilot to make up fake damages, irking judge 5. 5. NASA launches mission to explore the frozen frontier of Jupiter's moon Europa Customize Ars Technica has been separating the signal from the noise for over 25 years. With our unique combination of technical savvy and wide-ranging interest in the technological arts and sciences, Ars is the trusted source in a sea of information. After all, you don't need to know everything, only what's important. More from Ars * About Us * Staff Directory * Newsletters * Ars Videos * General FAQ * RSS Feeds Contact * Contact us * Advertise with us * Reprints Do Not Sell My Personal Information (c) 2024 Conde Nast. All rights reserved. Use of and/or registration on any portion of this site constitutes acceptance of our User Agreement and Privacy Policy and Cookie Statement and Ars Technica Addendum and Your California Privacy Rights. Ars Technica may earn compensation on sales from links on this site. Read our affiliate link policy. The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of Conde Nast. Ad Choices