TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

F5 Labs

Malware Targeting Bank Accounts Has a Swapping Pattern

2016-09-01 · Read original ↗

ATT&CK techniques detected

1 predictions
T1539Steal Web Session Cookie
58%
"ibans in question were reported to the appropriate financial institutions. the account was investigated, confirmed malicious, and was subsequently shut down. since we originally detected this web injection in may 2016, we have seen it change. once valuable forms are identified, i…"

Summary

F5 Labs analysts discovered a target pattern in the IBAN number formats as well as weekly changes to the script injection content. In May 2016, the F5 Security Operations Center (SOC) detected a generic form grabber and IBAN (International Bank...