Online:
Visits:
Stories:
Profile image
By American Kabuki
Contributor profile | More stories
Story Views

Now:
Last Hour:
Last 24 Hours:
Total:

Hackers Who Got Caught by a Typo Were Trying to Take Over the World

Sunday, May 1, 2016 23:34
% of readers think this story is Fact. Add your two cents.

(Before It's News)

Musings On The Finite Statist Machine

B4INREMOTE-aHR0cHM6Ly8zLmJwLmJsb2dzcG90LmNvbS8taGRSNFFleGVydE0vVnlieTFjWUFzSUkvQUFBQUFBQUFWRGsvNnlxc1lZWXJBRWt2ODNoUjNaUThzbWc5YTkwVlFmODdRQ0xjQi9zNjQwL0NIRUFQLVJPVVRFUi5KUEc=

 

Hackers Who Got Caught by a Typo Were Trying to Take Over the World (Updated)

http://gizmodo.com/bangladesh-bank-hackers-created-malware-to-target-the-g-1772834299

The hackers behind a large-scale Bangladesh bank hack went further than simply stealing money. Now it turns out that they created malware that could compromise the internationally used SWIFT payment system.

BAE Systems researchers tell Reuters that the hackers who took the central bank of Bangladesh for a ride compromized the SWIFT system using malware. SWIFT has confirmed to Reuters that it’s “aware of malware targeting its client software.” The organization plans to issue an update for its software some time today to protect the payment systems from attack.

The malware, called evtdiag.exe, allowed the hackers to change records on SWIFT databases in order to hide what they were up to. The criminals could delete records of transfer requests, intercept messages about payments and manipulate the displayed account balances to cover their tracks.

The software was apparently specifically written to attack the Bangladesh bank, but the theory could, according to the researchers, be applied elsewhere. Adrian Nish from BAE Systems told Reuters that it was one of the most elaborate malware hacks he’d ever come across.
 

An $80M Bank Hack Has Been Blamed on $10 Routers

Sometimes it pays to spend. The central bank of Bangladesh has found that out the hard way, as police are blaming its loss of $80m during a hack on crappy $10 routers.

You might remember that a team of hackers tried to steal vast quantities from the bank earlier this year. Their attempts were brought to a halt because they managed to misspell “foundation” as “fandation”—a typo that was noticed by Deutsche Bank, ultimately bringing the heist to an abrupt end. The criminals did, however, manage to make off with $80 million before they were found out.

Now, Reuters reports that the Forensic Training Institute of the Bangladesh police’s criminal investigation department has carried out an investigation into what went wrong. The team found that the bank was using second-hand $10 network switches without a firewall to link its computers. Perhaps no surprise then, that it proved incredibly easy to hack. Sadly those computers were connected to the SWIFT global payment system, which meant the hackers were able to gain access to the credentials required to make high-value transfers straight into their own accounts. Perhaps just as amusing—sorry, alarming—is the fact that the lack of sophisticated hardware is also apparently making it harder to trace the origin of the hacks. While the police has found 20 people who received payments as part of the heist, it admits it’s yet to find the hackers themselves.

A good reminder, if ever there was one, that sometimes you really do get what you pay for.
A Basic Spelling Error Cost These Hackers Nearly $1 Billion 

Most spelling mistakes are innocent, fleeting, and only mildly embarrassing. Then there are the… 

The Bangladesh bank hack until now seemed like a farcically amusing comedy of errors. First, the hackers were brought to a halt because they managed to misspell “foundation” as “fandation”—a typo that was noticed by Deutsche Bank, ultimately bringing the heist to an abrupt end. The criminals did, however, manage to make off with $80 million before they were found out.

Then, just last week, a forensic analysis of the hacks found that the bank had been using second-hand $10 network switches without a firewall to link its computers. Those computers were connected to the SWIFT global payment system, which meant the hackers were able to gain access to the credentials required to make high-value transfers straight into their own accounts.

Reuters claims that the attackers actually targeted a very specific piece of SWIFT software known as Alliance Access. So while the SWIFT system is used by thousands of banks and financial institutions, not all of them are affected by the malware.

Read more »



Source: http://americankabuki.blogspot.com/2016/05/gizmodo-hackers-who-got-caught-by-typo.html

Report abuse

Comments

Your Comments
Question   Razz  Sad   Evil  Exclaim  Smile  Redface  Biggrin  Surprised  Eek   Confused   Cool  LOL   Mad   Twisted  Rolleyes   Wink  Idea  Arrow  Neutral  Cry   Mr. Green

Top Stories
Recent Stories

Register

Newsletter

Email this story
Email this story

If you really want to ban this commenter, please write down the reason:

If you really want to disable all recommended stories, click on OK button. After that, you will be redirect to your options page.