HaoBao Malware Hitting Banks Scans for Bitcoin Activity

Robinson+Cole Data Privacy + Security Insider
Contact

Lazarus, the well-known hacking group responsible for the WannaCry ransomware attack from last year, as well as the attack on the Bangladesh Central Bank and Sony, is now targeting global financial firms and Bitcoin adopters with a phishing campaign dubbed “HaoBao.”

The phishing campaign was discovered by McAfee Labs in mid-January. The way it works is that Lazarus distributes a Dropbox link in an email that looks like a job advertisement for executive level bank jobs. When the user opens the link, malware is implanted into the user’s system.

Lazarus attackers pose as job recruiters that send targeted spear-phishing emails to bank employees and executives with the link to a job opportunity. When the user opens the link, they are then requested to enable Visual Basic macros, that then allow the attackers to implant the malware. When the malware is enabled, the attackers are able to scan the user’s data to determine whether there is any Bitcoin activity and allow the attacker access for long-term data gathering.

It is believed that the malware is specifically looking to assist with stealing Bitcoin and other cryptocurrencies, but the malware can also gather the details of the user’s computer, including username and the processes running on the computer which can be used in future attacks.

The lure of a job opportunity is powerful ammunition to dupe unsuspecting bank employees to disregard usual security processes. Alerting employees to new scams such as HaoBao will continue to increase awareness and vigilance among our work force.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide