North Korea Hackers Get Cash Fast in Linux Cyber Heists
ID: 86266137-d0b1-522c-b579-751eebdc0ce6
STIX ID: report--86266137-d0b1-522c-b579-751eebdc0ce6
Feed Name: Dark Reading
North Korean-linked actors are using a Linux variant of the FASTCash payment-switch malware to target banks and interbank payment processors by intercepting and modifying ISO 8583 transaction messages (including converting declined transactions to approved withdrawals), enabling unauthorized ATM cash-outs of tens of thousands of lira per transaction; the campaign has expanded from Windows and AIX to Linux, employs ptrace-based process injection, and researchers and CISA recommend stronger card authentication, MAC verification, and endpoint monitoring to detect the technique.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
