Researchers Uncover How Lazarus Hacking Group Stole Millions of Dollars From ATMs

Lazarus Hacking Group is known for launching highly Sophisticated Cyber attacks targeting various sectors such as entertainment, financial services, defense, technology, and virtual currency industries, academia, and electric utilities.

Their activities including the development of various malware that was used for one of the biggest Wannacry Ransomware attacks in 2017, Sony cyber Attack on 2014 and Bangladesh Bank attack where attackers theft $81 million.

Security researchers from Symantec uncover the important tool used by Lazarus Hacking Group to steal money from the ATMs.

According to Symantec’s research, to make the fraudulent withdrawals, Lazarus first breaches targeted banks’ networks and compromises the switch application servers handling ATM transactions.

Once the server compromised they deploy previously unknown malware (Trojan.Fastcash) which intercepts the fraudulent withdrawal requests and send fake responses to dispense cash from ATMs.

Lazarus Hacking GroupLazarus Hacking Group
Credits: Symantec

ISO 8583 is standard message format that details the exchange between the credit/debit card issuers and the devices where it used such as point-of-sale devices and automated teller machines.

Attackers inject malicious codes into a legitimate process on application servers running the AIX operating system, the inserted malicious script has the ability to construct the ISO 8583 messages.

According to Symantec analysis, the malware monitors incoming messages and intercepts the attacker generated fraudulent transaction requests to prevent them from reaching the switch application.

Then it transmits a fake response approving fraudulent withdrawal requests and the hacker group drops cash from the ATM.

“Symantec has found several different variants of (Trojan.Fastcash), each of which uses different response logic. The attackers appear to have built in a capability to selectively deny transactions based on their own blacklist of account numbers.”

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Cityworks Zero-Day Vulnerability Used by UAT-638 Hackers to Infect IIS Servers with Shell Malware

Cisco Talos has uncovered active exploitation of a zero-day remote-code-execution vulnerability, identified as CVE-2025-0994, in…

48 minutes ago

Researchers Warn of ‘Smiao Network’ Cyber Threat Against Taiwan’s Federal Staff

The Foundation for Defense of Democracies (FDD) and cybersecurity firm TeamT5 has exposed an intricate…

58 minutes ago

Vidar and StealC Malware Delivered Through Viral TikTok Videos by Hackers

A sophisticated social engineering campaign that leverages the viral power of TikTok to distribute dangerous…

1 hour ago

Halo Security Achieves SOC 2 Type 1 Compliance, Validating Security Controls for Its Attack Surface Management Platform

Halo Security, a leading provider of attack surface management and penetration testing services, today announced it has successfully…

1 hour ago

Hackers Deploy Weaponized npm Packages to Target React and Node.js JavaScript Frameworks

Socket's Threat Research Team, a series of malicious npm packages have been found lurking in…

1 hour ago

Malicious VS Code Extensions Target Windows Solidity Developers to Steal Login Credentials

Datadog Security Research has uncovered a targeted malware campaign aimed at Solidity developers on Windows…

1 hour ago