The story of the February cyberattack on the Bank of Bangladesh that sought $1 billion — and achieved $81 million — keeps looking more and more like a Hollywood caper movie.

The first account of the attack said it was detected by a misspelling, which prompted an employee of the victimized SWIFT banking network to look into it. Further stories came out insinuating that the Bangladesh network was actually undone by insecure and cheap routers.

Brussels-based SWIFT is central to interbank functioning; it is the financial nerve system of the world. So what really happened when it came under attack?

More Sophisticated Than First Believed

A new story has evolved, one far more menacing than bad routers. Security researchers at BAE Systems found tools lurking in malware repositories. They think the tools are connected to the attacks, stating, “The custom malware was submitted by a user in Bangladesh and contains sophisticated functionality for interacting with local SWIFT Alliance Access software running in the victim infrastructure.”

The tools seem to have been designed as part of an overall attack toolkit for SWIFT. The tools discovered were used to cover the attackers’ tracks while they sent payment instructions. By hiding their tracks, the attackers would have made detection harder, thus giving more time for money laundering to take place.

“The tools are highly configurable and, given the correct access, could feasibly be used for similar attacks in the future,” BAE Systems noted in its blog. “The tool was custom-made for this job and shows a significant level of knowledge of SWIFT Alliance Access software as well as good malware coding skills.”

The malware creator knew exactly how the SWIFT software functioned and what to do in order to bypass it. This was no random job: It was a targeted operation done using good intelligence.

SWIFT Banking Network Responds

SWIFT posted a response to all of this. “Contrary to reports that suggest otherwise, this malware has no impact on SWIFT’s network or core messaging services,” the network claimed.

“We have developed a facility to assist customers in enhancing their security and to spot inconsistencies in their local database records, however, the key defense against such attack scenarios remains for users to implement appropriate security measures in their local environments to safeguard their systems.”

The SWIFT banking network is shining the spotlight on the member banks, but it still has a serious problem: Someone knows just how to play the system. This exploit didn’t work all the way, but the next one might. The stakes are huge and call for the strongest possible response.

More from

The Evolution of Antivirus Software to Face Modern Threats

Over the years, endpoint security has evolved from primitive antivirus software to more sophisticated next-generation platforms employing advanced technology and better endpoint detection and response.  Because of the increased threat that modern cyberattacks pose, experts are exploring more elegant ways of keeping data safe from threats.Signature-Based Antivirus SoftwareSignature-based detection is the use of footprints to identify malware. All programs, applications, software and files have a digital footprint. Buried within their code, these digital footprints or signatures are unique to the respective…

How Do Threat Hunters Keep Organizations Safe?

Neil Wyler started his job amid an ongoing cyberattack. As a threat hunter, he helped his client discover that millions of records had been stolen over four months. Even though his client used sophisticated tools, its threat-hunting technology did not detect the attack because the transactions looked normal. But with Wyler’s expertise, he was able to realize that data was leaving the environment as well as entering the system. His efforts saved the company from suffering even more damage and…

The White House on Quantum Encryption and IoT Labels

A recent White House Fact Sheet outlined the current and future U.S. cybersecurity priorities. While most of the topics covered were in line with expectations, others drew more attention. The emphasis on critical infrastructure protection is clearly a top national priority. However, the plan is to create a labeling system for IoT devices, identifying the ones with the highest cybersecurity standards. Few expected that news. The topic of quantum-resistant encryption reveals that such concerns may become a reality sooner than…

Contain Breaches and Gain Visibility With Microsegmentation

Organizations must grapple with challenges from various market forces. Digital transformation, cloud adoption, hybrid work environments and geopolitical and economic challenges all have a part to play. These forces have especially manifested in more significant security threats to expanding IT attack surfaces. Breach containment is essential, and zero trust security principles can be applied to curtail attacks across IT environments, minimizing business disruption proactively. Microsegmentation has emerged as a viable solution through its continuous visualization of workload and device communications…