drIBAN Fraud Operations Target Corporate Banking Customers

Threat actors have extensively used a sophisticated web injection kit called drIBAN to orchestrate malicious attacks against corporate banking institutions and their customers.

According to the new Recommendation drIBAN was first discovered in 2019 by Clafy security researchers. drIBAN uses JavaScript code tailored to target different entities within the corporate banking sector.

Operating as part of a Man-in-the-Browser (MITB) attack, web injects allow cybercriminals to bypass the TLS protocol and manipulate the content of legitimate web pages in real time.

Clafy’s head of threat intelligence and incident response Federico Valentini and malware analyst Alessandro Strino explained that drIBAN’s functionality resides in the ATS (Automatic Transfer System) engine.

This allows attackers to receive money transfers from compromised victim machines without the need for credentials or two-factor authentication (2FA) codes that banks commonly use during the login and payment authorization phases. increase.

In particular, drIBAN can perform large-scale ATS attacks. It operates by falsifying legitimate bank transfers made by users, changing payees, and diverting funds to illicit bank accounts controlled by malicious actors or their affiliates.

ATS Attack Details: Novel Banking Trojan PixPirate Targets Brazil

Valentini and Strino also said that drIBAN has evolved over the years, employing evasion tactics that thwart detection and analysis.

The researchers added that they observed polymorphic techniques in June 2021. With this approach, identifiable characteristics such as certain variable names changed frequently, making it difficult to track malicious payloads.

In addition to its technical capabilities, drIBAN also introduces extortion capabilities. Over the past year, Clafy has identified multiple extortion messages embedded within her web injection payload.

These messages, written in broken English, suggested an attempt to negotiate with the targeted banking institution to prevent attacks on corporate customers.

To combat these evolving threats, Clafy emphasized the need for effective cooperation between the private sector, financial institutions, computer emergency response teams (CERTs), law enforcement and other stakeholders. .

“Proactive precautions, such as sharing threat intelligence and implementing robust security measures, are essential to protecting corporate bank accounts and mitigating the impact of sophisticated APT campaigns,” the company said.

“By promoting cooperation and implementing a unified defense strategy, we will strengthen our resilience against these malicious activities, Integrity in the European banking sector. ”

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *