logo

SWIFT attackers’ malware linked to more financial attacks

ID: 7708ed13-109b-4a26-9fef-8c616a718c6b

STIX ID: report--7708ed13-109b-4a26-9fef-8c616a718c6b

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2018-08-10

Last Modified Date: 2018-08-10

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec reports that a group responsible for the $81M Bangladesh central bank theft and other SWIFT-related frauds deployed malware (Backdoor.Fimlis, Backdoor.Fimlis.B, Backdoor.Contopee and Trojan.Banswift) against banks in Southeast Asia and Ecuador; code similarities — including a distinctive multi-iteration file-wiping routine and shared control bytes — link these tools to each other and to malware historically attributed to the Lazarus threat group, indicating a wider, ongoing financially motivated campaign targeting banks and payment systems.