Post Now
Image

Malware has infected several banks in Poland. Polish banks noticed some strange network activity and unauthorized files on some machines in their networks. After thorough investigation and coordination between various banks, they found that the origin of the infection is the KNF’s website, which is actually, the financial regulatory authority in Poland. Zaufana Trzecia Strona, a Polish news site, initially reported the attack. According to the news, security teams in various Polish banks noticed mysterious file downloads and traffic towards suspicious IPs in different foreign countries. The users who accessed the KNF website get infected with a malicious JavaScript file.This malicious file installs a remote access Trojan(RAT) on the victim machines. The motivation behind the attack is not still known. Banks reported that they do not have knowledge of any direct financial losses due to this attack. The investigation is still going on to identify the scope of loss and the real intention behind this massive attempt to disrupt Polish banking industry. Passive Total does confirm the observation and the finding related to external resources included in knf.gov.pl website since 2016-10- 07 till yesterday.   To unauthorized code was located in the following file:It looked like document.write("

");   You can find some hashes at the end of this article. Security experts investigated and collected further information regarding the malware. Some elements in the malware borrowed from other similar tools and crimeware strategies, but still, the attack technique or the code used in this attempt are entirely fresh. The malware uses commercial tools and multiple obfuscation techniques and has multiple stages. The malware relies on encryption, and at the moment of initial analysis, existing Antivirus solutions did not detect it.  The final payload functions like a regular RAT.   MD5, SHA1, SHA256 hashes of some samples: C1364BBF63B3617B25B58209E4529D8C 85D316590EDFB4212049C4490DB08C4B 1BFBC0C9E0D9CEB5C3F4F6CED6BCFEAE 496207DB444203A6A9C02A32AFF28D563999736C 4F0D7A33D23D53C0EB8B34D102CDD660FC5323A2 BEDCEAFA2109139C793CB158CEC9FA48F980FF2B FC8607C155617E09D540C5030EABAD9A9512F656F16B38682FD50B2007583E9B D4616F9706403A0D5A2F9A8726230A4693E4C95C58DF5C753CCC684F1D3542E2 CC6A731E9DAFF84BAE4214603E1C3BAD8D6735B0CBB2A0EC1635B36E6A38CB3A   For preventive actions, you may find below some IOCs: 125.214.195.17 196.29.166.218   Malicious URLs inserted in knf.gov.pl website given below:   Disclaimer:

Secure Reading (SR) has no confirmed sources for the information shared in the above news/articles. It relies on various unconfirmed inputs, social media claims, and websites for its content, and cannot guarantee the accuracy, timeliness, and genuineness of the same. If there is any error in the news, and once it is brought up to our attention with relevant evidence, SR is willing to make necessary corrections as applicable.