Info security body finds no evidence of infection at Swiss banks as a result of “Sharpshooter” campaign

Maria Nikolova

Switzerland’s Reporting and Analysis Centre for Information Assurance is in touch with a number of banks but no evidence of infection has been found.

Switzerland’s Reporting and Analysis Centre for Information Assurance (MELANI) has earlier today posted its 29th semi-annual report which addresses the most important cyberincidents of the first half of 2019 both in Switzerland and abroad.

MELANI noted the Lazarus attacks targeting Swiss banks. In March 2019, security software company McAfee published a follow-up to its December 2018 report on the Sharpshooter campaign. Last year, the campaign targeted 87 companies from all over the world, but mainly in the US. The companies concerned were from the defence, energy, nuclear and financial sectors.

In its second report, McAfee confirmed their initial suspicion that the Lazarus group was behind the attacks. The group is well known for having attacked systems at various banks and is considered by many experts to be connected to the North Korean regime.

In its first report on the matter, McAfee described attempted attacks against Swiss financial institutions.

Today, MELANI said it is in contact with a number of banks, as mentioned in the preceding semi-annual report.

“Then as now, no evidence of infection has been found at the potential target companies in Switzerland”, says MELANI.

Let’s recall that, in December 2018, security firm McAfee released a report on a newly discovered APT campaign against defence, energy, nuclear, and financial companies. The campaign called “Sharpshooter” began on October 25, 2018 with the sending of infected documents to individuals from 87 organisations around the world, mainly in the USA. According to the report, Swiss companies in the financial sector were also hit by the campaign.

Social engineering was used to get the recipients to open the infected documents. The letter was disguised as a letter of application and contained a link to a document on Dropbox which allegedly contained the application dossier. This method is particularly insidious because HR departments often receive unsolicited applications and usually open such documents.

The infection occurred via a macro contained in the Word document. Such macros are now blocked in many companies, or are activated only after confirmation of a corresponding warning message. If the macro is executed despite all warnings, the malware will smuggle Sharpshooter into the working memory of Word. The malware then installs a modular backdoor called “Rising Sun”. The functions of this component include collecting and sending information about documents, user names, network configuration, and system settings. The malware can also reload other functions.

The malware communicates via a command and control server controlled by the attackers.

In analysing the campaign, McAfee found evidence of connections to the “Lazarus” group: “Rising Sun” contains code and configuration data from the “Duuzer” family. Duuzer was also used in the hacker attack on Sony, which is associated with the Lazarus group.

Read this next

Chainwire

Bandit Network’s Points SDK and Brave Ads Power Astar zkEVM’s Quest Platform “Yoki Origins”

“Yoki Origins,” supported by Bandit Network and Brave Ads, introduces a gamified and rewarding experience for Astar zkEVM users, marking a significant milestone in Web3 adoption.

Digital Assets

Crypto ETFs to debut in Hong Kong next week

Hong Kong has authorized six cryptocurrency-based spot ETFs set to launch on April 30, according to Bloomberg.

blockdag

BlockDAG Among The Best New Crypto To Invest In Post 8 Billion Coins Sales; More On Bitcoin Cash Futures’ Launch & Solana Positive Predictions

Explore Solana’s ATH predictions to see whether it can rise after a $17B dip? BlockDAG sells 8 billion coins in presale as Bitcoin Cash Futures launch.

Fundamental Analysis, Market News, Tech and Fundamental

Global FX Market Summary:USD, FED, German IFO ,Gold April 24 ,2024

Mixed US economic data and Fed rate hike uncertainty are causing volatility in the EUR/USD pair, while the Eurozone and gold prices add another layer of complexity.

Market News, Tech and Fundamental, Technical Analysis

EURCHF Technical Analysis Report 24 April, 2024

EURCHF currency pair can be expected to rise further toward the next major resistance level 0.9840, which stopped the pervious waves C and B, as can be seen below.

Digital Assets

Binance’s CZ could stay in prison until 2027, wife begs for mercy

Changpeng “CZ” Zhao, the founder and former CEO of Binance, has apologized for his decisions and accepted “full responsibility” in a letter to U.S. District Judge Richard A. Jones.

Digital Assets

Monex Group expands crypto business with 3iQ takeover

Monex Group has completed the acquisition of a majority stake in 3iQ Digital Holdings, Inc., a Canadian digital asset investment fund manager, as part of its strategy to expand its crypto business.

Education, Fintech, Inside View

How to Get Into Fintech: Best Tips to Succeed

The Fintech sector is experiencing significant growth, with fresh opportunities emerging rapidly.  Innovations such as machine learning and cryptocurrency are revolutionising finance, leading to a need for trained experts.

Digital Assets

FalconX launches Prime Connect on Deribit

“We are pleased to launch Prime Connect with Deribit and look forward to providing our full suite of prime services which allow institutions to confidently scale their digital assets portfolios while trading on exchanges.”

<