FIN8 Targets US Bank With New ‘Sardonic’ Backdoor
#1
Information 
Quote:The financially motivated FIN8 cybergang used a brand-new backdoor – dubbed Sardonic by the Bitdender researchers who first spotted it – in attempted (but unsuccessful) breaches of networks belonging to two unidentified U.S. financial organizations.
 
It’s a nimble newcomer, researchers wrote: “The Sardonic backdoor is extremely potent and has a wide range of capabilities that help the threat actor leverage new malware on the fly without updating components,” according to Bitdefender’s report.
 
FIN8 has typically gone after financial services and payment-card data from point-of-sale (PoS) systems, particularly those of retailers, restaurants and the hotel industry. It’s been active since at least January 2016, but it periodically pops in and out of dormancy in order to fine-tune tactics, techniques and procedures (TTPs) and thereby evade detection and ramp up its success rate.
 
True to form, in March, Bitdefender spotted FIN8 re-emerging after a period of relative quiet with a new version of the BadHatch backdoor to compromise companies in the chemical, insurance, retail and technology industries. Sardonic is an updated version of BadHatch that’s apparently still under development, Bitdefender said.
 
It’s a refinement of BadHatch in that it can be automatically boosted with new functionality without the malware needing to be redeployed: A way to make it more agile, Bitdefender said.
Bogdan Botezatu, director of threat research for Bitdefender, told BankInfoSecurity that the security firm has seen FIN8 carrying out two attacks over the past few months, what he called “unusually high activity for a threat actor that used to take long breaks between attacks.”

Read more: FIN8 Targets US Bank With New ‘Sardonic’ Backdoor
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Cloudflare CEO warns AI bots could outnu...
The internet you use...schreckdeividas — 11:03
ScreenToGif 2.43.1
ScreenToGif 2.43.1...harlan4096 — 08:55
uBOLite 2026.322.1735 (already available...
uBOLite 2026.322.1...harlan4096 — 08:54
Microsoft outs Windows 11 KB5085516 to f...
This month, Micros...harlan4096 — 08:53
AV-Test - Awards 2025: celebrating the v...
V-TEST Awards 2025...harlan4096 — 08:50

[-]
Birthdays
Today's Birthdays
avatar (43)artmaGoork
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (46)qaqapeti

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>