Bitcoin Forum
May 04, 2024, 07:22:01 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [Warning] AllaKore RAT Targets Mexican Banks and Cryptocurrency Platforms  (Read 85 times)
Jating (OP)
Hero Member
*****
Offline Offline

Activity: 2912
Merit: 808


View Profile
January 30, 2024, 10:32:20 AM
Merited by DdmrDdmr (4), hugeblack (2), Yaunfitda (1)
 #1

There is a group of cyber actors that targeted Mexican banking apps and crypto trading exchange and has been active in the wild right now. Not sure why Mexico and Latin-American countries, (Lat-Am), but they are financially motivated and targeting companies, gross revenues over $100M. They uses to lure their victims with the IDSE software update document:

Code:
guia_de_soluciones_idse.pdf
and

Code:
 IMSS payment system SIPARE

The infection process initiates with a ZIP file, which is disseminated through either phishing or a drive-by compromise. Inside this ZIP file is an MSI installer that deploys a .NET downloader. This downloader is responsible for verifying the victim's geographical location in Mexico.



And once you extract and executed this files you will be instructed to:



1.- EXTRACT THE CONTENT OF THE INSTALARPLUGINSIPARE.ZIP FILE
2.- RUN THE FILE CALLED "INSTALARPLUGIN"
3.- WHEN YOU FINISH THE INSTALLATION YOU WILL BE ABLE TO LOG IN NORMALLY

It checks ipinfo[.]io for a geolocation in Mexico, if MX is not in the response string then the downloader aborts itself.



This is just a warning to our Mexican members or those who are in Latin-American. I know that there are a lot of respected members here and maybe they can share this.

https://blogs.blackberry.com/en/2024/01/mexican-banks-and-cryptocurrency-platforms-targeted-with-allakore-rat
1714850522
Hero Member
*
Offline Offline

Posts: 1714850522

View Profile Personal Message (Offline)

Ignore
1714850522
Reply with quote  #2

1714850522
Report to moderator
Bitcoin addresses contain a checksum, so it is very unlikely that mistyping an address will cause you to lose money.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
Yaunfitda
Hero Member
*****
Offline Offline

Activity: 2842
Merit: 575



View Profile
January 30, 2024, 12:13:26 PM
Merited by Jating (1)
 #2

I'm not Mexican, but this is scary indeed as this criminals are targeting big companies not just banks as per the report. Obviously, this groups are financially motivated and most likely they have success and that's why they continue to evolved and you might be right that they will go and target other Latin Americans with just a few modifications of the code itself. So the best weapons against this kind of attacks is to just really ignored those kind of message, specially with attachment that seems to be legitimate as it could really be one of those coming from this criminal groups.

███████████████████████████████
███████████████████████████████
███▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀███████████
█████████████▀▀        ▀▀██████
██████▀▀▀▀▀▀              ▀████
██████████▀     ▄▄██▄▄     ▀███
██████████      ██████      ███
██████████▄     ▀▀██▀▀     ▄███
██████▄▄▄▄▄▄              ▄████
█████████████▄▄        ▄▄██████
███▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████████
███████████████████████████████
███████████████████████████████
.
|
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▄██████▀████░███▄██▄
███░████████▀██░████░███
███░████░█▄████▀░████░███
███░████░███▄████████░███
▀██▄▀███░█████▄█████▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
SSC NAPOLI
OFFICIAL EUROPEAN
BETTING PARTNER
|.ROLLBOTS.|
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄██▀▀▀▀▀▀▀▀▀▀▀▀▀▀█████▄
▄█████████▀████████▀████▄
██████▄▄▄█████▄▄█████████
█████████████████████████
██████▀▀▀█████▀▀█████████
▀█████████▄████████▄████▀
▀██▄▄▄▄▄▄▄▄▄▄▄▄▄▄█████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀
ROLLBIT COIN
TRADE RLB NOW!
|...PLAY NOW...
Bitcoin_Arena
Copper Member
Legendary
*
Offline Offline

Activity: 2030
Merit: 1787


฿itcoin for all, All for ฿itcoin.


View Profile
January 30, 2024, 11:43:22 PM
Merited by Jating (1)
 #3

I don't know about IDSE software but is it like some random pop up that asks for update or the victim out of their curiosity just downloads the malware from some non-reputable source?
As usual, Microsoft/Windows seems to be the soft target for hackers.

If anyone is to deal with financial apps and money, operating systems like Linux should be top priority for them. The problem is traditional banking services don't even know what the hell Linux is, and they have no support when it comes to apps.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
lovesmayfamilis
Legendary
*
Offline Offline

Activity: 2086
Merit: 4284


✿♥‿♥✿


View Profile
January 31, 2024, 11:37:26 AM
 #4

One can also say that many corporate networks still use Windows 7, not trying to replace them with Linux but not updating them to the latest release.
Administrators must be attentive since the e-system IDS is precisely aimed at the timely detection of intrusions.
AllaKore RAT has been causing harm for more than two years; as they say, it was previously used in India. But at this time, attacks have become more targeted, and they are looking for companies with a fairly large income level, which once again confirms the idea that it is necessary to monitor strictly what system the server is installed on and is it easy to access.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
Fiatless
Hero Member
*****
Online Online

Activity: 546
Merit: 519



View Profile
February 01, 2024, 08:51:19 AM
 #5

This is just a warning to our Mexican members or those who are in Latin-American. I know that there are a lot of respected members here and maybe they can share this.
Although it was reported by the article OP quoted that these attackers are mostly interested in big organisations that are worth over USD 100M, it is still a wake-up call for everyone and not just people who reside in Mexico and Latin America. Most of these attackers have a wide-range network that operates globally and they can also target individuals and smaller organisations in the future.

It is scary that such an attack has lasted for over two years now and there seems to be no ending to these attacks. Big organisations need to invest more funds in cybersecurity because attacks will cost them more losses. The only reason why these attacks are still reoccurring is because these organisations have not sought the services of renowned cybersecurity companies. Maybe they could get a good cybersecurity expert from this forum Cheesy.       

.
SPIN

       ▄▄▄██████████▄▄▄
     ▄███████████████████▄
   ▄██████████▀▀███████████▄
   ██████████    ███████████
 ▄██████████      ▀█████████▄
▄██████████        ▀█████████▄
█████████▀▀   ▄▄    ▀▀▀███████
█████████▄▄  ████▄▄███████████
███████▀  ▀▀███▀      ▀███████
▀█████▀          ▄█▄   ▀█████▀
 ▀███▀   ▄▄▄  ▄█████▄   ▀███▀
   ██████████████████▄▄▄███
   ▀██████████████████████▀
     ▀▀████████████████▀▀
        ▀▀▀█████████▀▀▀
.
RIUM
.
███
███
███
███
███
███
███
███
███
███
███
███
SAFE GAMES
WITH WITHDRAWALS
       ▄▀▀▀▀▀▀▄▄▄▄
 ▄▀▀▀▀▀▀▀▀▀▀▀▀▄  ▀▀▄
█    ▄         █   ▀▌
█   █ █        █    ▌
█      ▄█▄     █   ▐
█     ▄███▄    █   ▌
█    ███████   █  ▐
█    ▀▀ █ ▀▀   █  ▌
█     ▄███▄    █ ▐
█              █▐▌
█        █ █   █▌
 ▀▄▄▄▄▄▄▄▄█▄▄▄▀
       ▄▀▀▀▀▀▀▄▄▄▄
 ▄▀▀▀▀▀▀▀▀▀▀▀▀▄  ▀▀▄
█    ▄         █   ▀▌
█   █ █        █    ▌
█      ▄█▄     █   ▐
█     ▄███▄    █   ▌
█    ███████   █  ▐
█    ▀▀ █ ▀▀   █  ▌
█     ▄███▄    █ ▐
█              █▐▌
█        █ █   █▌
 ▀▄▄▄▄▄▄▄▄█▄▄▄▀
.
███
███
███
███
███
███
███
███
███
███
███
███
.
.SIGN UP.
ImThour
Copper Member
Legendary
*
Offline Offline

Activity: 1400
Merit: 1512


Bitcoin Bottom was at $15.4k


View Profile
February 01, 2024, 01:46:04 PM
 #6

Seems like a pretty intelligent group of hackers. I mean if they are not able to make millions out of it, it will all be waste. For the users who are affected by this, It's pretty sad and I am sure you might be able to get some help if it was your Bank however in Crypto, once it's gone, you can never recover it. That's how it is. Once a transaction is made and it receives confirmation, it's not reversible. Stay safe!
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!