Monday, April 25, 2016

Criminals manipulated Swift software – handelszeitung.ch

The spectacular hacker attack on the Central Bank of Bangladesh could provide an aftershock in the global financial world. After Reuters information succeeded the cyber criminals who looted $ 81 million from the central bank a few weeks ago, may penetrate into a software of the international payment system SWIFT. This is suggested by findings of security experts of the British arms company BAE Systems towards.

The experts told Reuters they had probably made a malicious program find that the hackers had used in their attack. Thus they had the Swift customers Software Alliance Access manipulated. So did the cyber thieves cover their tracks and delayed the discovery of rape. Swift is a linchpin of the international financial system. It is an international cooperative of 3,000 financial institutions based in Brussels. You should ensure that payments go safely and smoothly.



existence of the software confirms

A Swift spokeswoman confirmed the existence of a malicious program, intended to lead to customer software. She announced to submit even this Monday a software update that will turn off the malicious program. Furthermore, should a security warning to financial institutions go out. However, the spokeswoman stressed the malicious program had no effect on the data exchange platform of Swift, who made use of 11,000 banks and other institutions worldwide.

The affected software Alliance Access other hand is being used only by some institutions.

Unprecedented attack

Adrian Nish, who heads the danger Enlightenment ushers in BAE has never seen by his own admission a cleverly thought follows action by cybercriminals. BAE also wanted to inform the public in a blog on its own findings yet on Monday. This should include technical details are presented, the banks should help to prevent similar attacks.

The malicious software was indeed tailored to the Central Bank of Bangladesh, it said in the draft BAE announcement, has read the Reuters , But: “The general instruments, techniques and methods that were used in the attack, it could make the band possible strike again.”

The unprecedented cyber-attack on the Central Bank of Bangladesh in early February occurred. The unknown thieves caused fraudulent transactions total $ 951 million, but most of them were blocked. $ 81 million were directed to accounts in the Philippines and passed there at casinos. The largest part of this amount will continue to miss. As a consequence of the attack of the Fed Chairman had to resign.



traces blurred

The Bangladesh authorities go so far assumes that the hackers broke into the central bank computer and there access procured the Swift system. According to their view of the computer of the central bank showed serious safety deficiencies. However, the investigators Swift had a responsibility to, because the payment system operators have apparently not advised of the problems.

The experts at the BAE group, for the cyber security is a big business, came to a different conclusion. Accordingly, the vulnerability is in the Swift software that is located on the central computers. The malicious program named “Evtdiag.exe” have served to cover up the traces of hackers, by information on the fraudulent transfers were corrupted or lost. The desired objective was, the cyber robbery to conceal until the perpetrators have brought the stolen funds in security, explained Nish. As the transactions were instructed exactly, but remains unclear.

(Reuters / chb)

LikeTweet

No comments:

Post a Comment