Second Bank Hit By 'Sophisticated' Malware Attack, Says Swift (theguardian.com) 32
An anonymous reader cites an article on The Guardian: Swift, the global financial messaging network that banks use to move billions of dollars every day, warned of a second malware attack similar to the one that led to February's $81 million cyberheist at the Bangladesh central bank. The second case targeted a commercial bank, Swift spokeswoman Natasha de Teran said, without naming it. It was not immediately clear how much money, if any, was stolen in the second attack. Swift said in a statement that the attackers exhibited a "deep and sophisticated knowledge of specific operational controls" at targeted banks and may have been aided by "malicious insiders or cyber attacks, or a combination of both." The organization, a Belgian co-operative owned by member banks, said that forensic experts believe the second case showed that the Bangladesh heist was not a single occurrence, "but part of a wider and highly adaptive campaign targeting banks."
"Sophisticated" Malware Attack (Score:5, Funny)
And by "Sophisticated Malware Attack" they mean "a photo of a cute kitten or puppy".
A.K.A. "cute-kitten-must-see.jpg.this-is-a-very-dangerous-virus-do-not-open-this-file-you-idiot.exe"
Re: (Score:3)
http://1.bp.blogspot.com/-bP6k... [blogspot.com]
Re: (Score:2)
Re: (Score:2)
Pretty much.
Unless the attack can be summarized as "used a previously unknown 0-day exploit" then what they're really saying is "got past our defenses".
"Sophisticated" merely means "knows more than than our person responsible for defenses".
And I'm sure that many of you have seen some rather ... unintelligent ... security decisions made.
Let's go cashless... (Score:1)
Re: (Score:3)
Re: (Score:1)
Re: (Score:1)
I call bullshit on the "wider campaign"... (Score:4, Interesting)
What happens here is far simpler: One group got away with an amazing payout and had a real chance of making it even larger. This lead to some people re-focusing their attempts, because who knew before that security at some banks using Swift was this pathetic. And no, all these claims of "advanced" and "sophisticated" really only serve to daemonize the attackers, so the affected banks and Swift have can avoid admitting how massively they have screwed up.
The whole thing is not a surprise at all. Experts have observed "cheaper than possible" security to be used all around the finance industry in the aftermath of 2008, because management that does not get it is making the decisions and is trying to save money on security (and reliability and people as well) in order to make IT more "profitable". That almost universally costs a lot later.
We are now at the point where "later" is reached. This will get worse for at least 5...10 years until all the bad decisions of the last few years have been fixed.
Re: (Score:2)
all these claims of "advanced" and "sophisticated" really only serve to daemonize the attackers
I confess I've never heard of this technique, but it sounds like a lot of work. I've just been using the daemon() function.
Re: (Score:2)
Actual experts call them "morons that keep at it and eventually get lucky due to bigger morons on the other side".
"Sophisticated"? Or... (Score:1)
Did this (unnamed) bank have a $10 router as well, because someone thought it would be enough, and why spend money on security that isn't thick walls and guards with guns and truncheons?
Poor Apple... (Score:2)
Saudi Wahhabi Terrorist ring (Score:1)
It's obvious.
Duh.
Re: (Score:2)
Seriously, those Wasabis leave a bad taste in my mouth.
Re: (Score:3)
Interesting mix of racism and paranoia.
Re: (Score:2)
The real issue is that ppl are ignoring facts because they are afraid of being called racists by ppl like you.br. As a person that has worked with Target and Home Depot, I can tell you that things are NOT what they appear.
Re: (Score:2)
Considering that I am married to an India, not very likely.,
I've heard of having multiple wives, but that is ridiculous!
Re: I will bet that they outsourced to India (Score:2)
Nobody to blame but themselves (Score:2)
Seriously, attacks on bank network security started when they first had bank networks. There is no legitimate excuse for not have impenetrable systems by now. Before anyone says it, yes there is such a thing as bug free software because NASA makes it and their budget is miniscule in comparison to banks!
This is what happens when IT is OUTSOURCED! (Score:4, Informative)
quoting Willie Sutton: (Score:2)
"because that's where the money is"
Re: (Score:2)
Fascinating link. Thanks!