SWIFT attackers’ malware linked to more financial attacks
ID: 7708ed13-109b-4a26-9fef-8c616a718c6b
STIX ID: report--7708ed13-109b-4a26-9fef-8c616a718c6b
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2018-08-10
Last Modified Date: 2018-08-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec reports that a group responsible for the $81M Bangladesh central bank theft and other SWIFT-related frauds deployed malware (Backdoor.Fimlis, Backdoor.Fimlis.B, Backdoor.Contopee and Trojan.Banswift) against banks in Southeast Asia and Ecuador; code similarities — including a distinctive multi-iteration file-wiping routine and shared control bytes — link these tools to each other and to malware historically attributed to the Lazarus threat group, indicating a wider, ongoing financially motivated campaign targeting banks and payment systems.
