logo

North Korea Hackers Get Cash Fast in Linux Cyber Heists

ID: 86266137-d0b1-522c-b579-751eebdc0ce6

STIX ID: report--86266137-d0b1-522c-b579-751eebdc0ce6

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-10-15

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

North Korean-linked actors are using a Linux variant of the FASTCash payment-switch malware to target banks and interbank payment processors by intercepting and modifying ISO 8583 transaction messages (including converting declined transactions to approved withdrawals), enabling unauthorized ATM cash-outs of tens of thousands of lira per transaction; the campaign has expanded from Windows and AIX to Linux, employs ptrace-based process injection, and researchers and CISA recommend stronger card authentication, MAC verification, and endpoint monitoring to detect the technique.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.