BuhTrap is a financially motivated threat actor targeting Russian and Ukrainian banks using network worms.
Analyst brief
BuhTrap is a group targeting the financial sector, primarily banks in Russia and Ukraine. They use a network worm to infect entire bank infrastructures, significantly complicating the removal of malicious functions. Key TTPs involve spreading via network worm and manipulating banking transactions. Defenders should focus on network segmentation, anomaly detection, and restricting unauthorized access to banking systems.
BuhTrap
unknown
Buhtrap has been active since 2014, however their first attacks against financial institutions were only detected in August 2015. Earlier, the group had only focused on targeting banking clients. At the moment, the group is known to target Russian and Ukrainian banks.
From August 2015 to February 2016 Buhtrap managed to conduct 13 successful attacks against Russian banks for a total amount of 1.8 billion rubles ($25.7 mln). The number of successful attacks against Ukrainian banks has not been identified.
Buhtrap is the first hacker group using a network worm to infect the overall bank infrastructure that significantly increases the difficulty of removing all malicious functions from the network. As a result, banks have to shut down the whole infrastructure which provokes delay in servicing customers and additional losses.
Malicious programs intentionally scan for machines with an automated Bank-Customer system of the Central Bank of Russia (further referred to as BCS CBR). We have not identified incidents of attacks involving online money transfer systems, ATM machines or payment gates which are known to be of interest for other criminal groups.
What specific method does the BuhTrap group use to infect a bank's infrastructure?+
BuhTrap uses a network worm to infect the entire bank infrastructure.
Which financial sector was targeted in BuhTrap's first known successful attacks?+
The first known successful attacks were conducted against Russian banks, resulting in 13 successful attacks and 1.8 billion rubles ($25.7 million) stolen.