The report reviews cyber threats targeting financial institutions, covering malware distribution, phishing, database leaks, credential sales on forums, and ransomware incidents affecting banks and related companies. It highlights specific cases including firewall admin credential sales by an IAB on BreachForums, a claimed mortgage data breach by FulcrumSec, and ransomware victim disclosures by Qilin. #Qilin #FulcrumSec
Keypoints
- The report catalogs malware and phishing campaigns specifically targeting the financial sector and provides a Top 10 list of major financial-sector malware.
- An Initial Access Broker (miyako) is selling firewall and network administrator credentials for Chinese financial institutions on BreachForums, enabling possible RCE and shell access.
- FulcrumSec claims a large-scale data breach of W***s.com mortgage broker, allegedly exposing ~19,000 mortgage application documents and sensitive PII (SSNs, driver’s licenses, bank details).
- Ransomware groups CL0P, DragonForce, and Qilin have publicly listed multiple financial-sector victims on dedicated leak sites, with Qilin’s victim post later inaccessible/disabled.
- The sale of admin-level perimeter device credentials is assessed as high risk due to potential full network takeover, data theft, ransomware deployment, and supply-chain propagation.
- The report includes industry leakage statistics (accounts leaked via Telegram) and malware distribution statistics targeting the financial sector to quantify exposure and trends.
MITRE Techniques
- [T1078 ] Valid Accounts – Sale of administrator credentials for firewall and network admin panels enabling legitimate credential use for access. [‘access credentials for firewall and network administrator panels of Chinese financial institutions are being sold on the cybercrime forum BreachForums.’]
- [T1190 ] Exploit Public-Facing Application – Remote code execution and shell access on Linux-based firewall devices enabling network takeover via vulnerable perimeter systems. [‘enabling direct control over the internal network, including root-level remote code execution (RCE) and shell access on Linux-based firewall devices.’]
- [T1486 ] Data Encrypted for Impact – Ransomware groups compromising financial companies and publishing victims on leak sites as part of impact and extortion operations. [‘Ransomware groups such as CL0P, DragonForce, and Qilin have compromised numerous financial-related companies and publicly exposed victims on their dedicated leak sites (DLS).’]
Indicators of Compromise
- [File Hash (MD5) ] ransomware/victim data samples – 02e33ac182acde8ce5c04fb2da933181, 1f8715d769b879769fa4c65a2c9a9467, and 3 more hashes
- [Domain (redacted) ] affected companies referenced in leaks – w***s.com (claimed mortgage broker breach by FulcrumSec), t***e.com (listed as a Qilin ransomware victim)
- [Forums/Leak Sites ] sources of sales/posts – BreachForums (sale of firewall/admin credentials), DarkForums (posting and sale of W***s.com data)
Read more: https://asec.ahnlab.com/en/92903/