Thursday, February 27, 2025
HomeComputer SecurityAfrican Financial Institutions Targeted by Hackers With Multiple Malware and Living off...

African Financial Institutions Targeted by Hackers With Multiple Malware and Living off the Land Tactics

Published on

SIEM as a Service

Follow Us on Google News

Attackers targeted west African financial institutions with generic malware and with living off the land tools. The attack appears to be from the mid of 2017 and the recent one was on December 2018.

The hacker group behind the attacks still remain unknown and the attacks targeted organizations in Cameroon, Congo (DR), Ghana, Equatorial Guinea, and Ivory Coast. The attack uses generic malware and use living off the land tactics.

Living off the land tactics is the use of operating system features or legitimate network administration tools to compromise victims’ networks.

Multiple Attack Vectors On
Financial Institutions

Security researchers from Symantec observed four distinct attack campaigns that affected multiple financial institutions in Africa.

NanoCore & PsExec

Attackers used weaponized word documents that referred to be from West African bank, with this campaign attackers infected victims through NanoCore malware and then it was executed using Microsoft Sysinternals tool PsExec on infected computers.

Mimikatz, Cobalt Strike & UltraVNC

The second type of attack uses Mimikatz(Hacking tool), Cobalt Strike(malware) & UltraVNC(remote administration tool).

According to the Symantec report, the attack appears to be started in late 2017 and the attackers use PowerShell scripts to infect victims, uses Mimikatz for credential stuffing and UltraVNC for remote administration. Attackers used Cobalt Strike malware for backdooring on the computer and to establish the connection with C&C server for downloading additional payloads.

financial institutions

Remote Manipulator System RAT, Mimikatz & RDP

The Third type of attack uses Remote Manipulator System RAT(backdoor), Mimikatz(Hacking tool) & RDP(Remote Desktop Protocol).

This type of attack targets organization in Ivory Coast, attackers used Remote Manipulator System RAT along with Mimikatz tool to steal the credentials and the stolen credentials allows attackers to establish a remote desktop connection.

Imminent Monitor RAT

The fourth type of attack uses info stealer Imminent Monitor RAT that steals the information from the compromised computer and downloads additional malware. The attack originated in December 2018 and targets organizations in Ivory Coast.

A growing number of attackers in recent years are adopting “living off the land” tactics—namely the use of operating system features or network administration tools to compromise victims networks, reads Symantec report.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

ATM Jackpotting – Attacker Can Compromise the ATM and Spit the Cash out – Attack now Hit U.S ATM’s

Free Android App that helps you to Detect Credit Card Skimmers at Fuel Pump

ATMJackpot – New ATM Malware Steal Your Money From ATM using ATM Jackpotting Technique

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has...

Squidoor: Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2

A newly identified malware, dubbed "Squidoor," has emerged as a sophisticated threat targeting government,...

Unpatched Vulnerabilities Attract Cybercriminals as EDR Visibility Remains Limited

Cyber adversaries have evolved into highly organized and professional entities, mirroring the operational efficiency...

Threat Actors Attack Job Seekers of Fortune 500 Companies to Steal Personal Details

In Q3 2024, Cofense Intelligence uncovered a targeted spear-phishing campaign aimed at employees working...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has...

Squidoor: Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2

A newly identified malware, dubbed "Squidoor," has emerged as a sophisticated threat targeting government,...

Unpatched Vulnerabilities Attract Cybercriminals as EDR Visibility Remains Limited

Cyber adversaries have evolved into highly organized and professional entities, mirroring the operational efficiency...