In less than two years, this group has conducted over 20 successful attacks on financial institutions and legal firms in the USA, UK and Russia. The group has primarily been targeting card processing systems, including the AWS CBR (Russian Interbank System) and purportedly SWIFT (US). Given the wide usage of STAR in LATAM, financial institutions in LATAM could have particular exposure to a potential interest from the MoneyTaker group.
Executive Summary
MoneyTaker is a threat actor targeting financial institutions and legal firms in the USA, UK, Russia, and potentially LATAM, with a focus on card processing systems such as AWS CBR and SWIFT. Over 20 successful attacks in two years indicate a high operational tempo and significant capability to exploit financial infrastructure vulnerabilities.
Goals & Targeting
MoneyTaker’s targeting of financial institutions and legal firms suggests a primary motivation of financial gain, data exfiltration, or disruption of critical infrastructure. The focus on card processing systems such as SWIFT and AWS CBR indicates an interest in exploiting high-value financial data flows, potentially for monetary theft or to destabilize financial systems. Legal firms may be targeted for sensitive client data or to facilitate fraud. The inclusion of Russia and LATAM as potential targets highlights a strategic interest in regions with significant financial transaction volumes and potentially weaker cybersecurity postures.
Enhanced Description
MoneyTaker has executed over 20 successful attacks within two years, primarily targeting financial institutions and legal firms in the USA, UK, and Russia, with potential interest in LATAM due to the prevalence of STAR systems. The group’s focus on card processing infrastructures, including the Russian Interbank System (AWS CBR) and SWIFT in the US, highlights a strategic intent to exploit critical financial pathways. While specific technical methods remain undocumented, the group’s success suggests a combination of targeted spear-phishing, network infiltration, and exploitation of vulnerabilities in financial systems. The potential exposure of LATAM institutions underscores the need for global threat awareness, particularly in regions reliant on card processing technologies.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
MoneyTaker’s campaigns exhibit a high operational tempo, with over 20 successful attacks in two years, primarily targeting financial institutions in the USA, UK, and Russia. The group’s campaigns likely involve spear-phishing, exploitation of card processing infrastructures, and lateral movement within compromised networks. Notable operations include alleged intrusions into SWIFT systems in the US and the Russian Interbank System (AWS CBR), with potential interest in LATAM institutions using STAR systems. Campaigns appear to prioritize stealth and persistence to avoid detection.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in MoneyTaker’s targeting of financial institutions and legal firms is high, supported by multiple reported attacks. However, specific technical capabilities, tools, and MITRE technique details are inferred based on sector and system targeting, as explicit evidence remains limited. Gaps exist in confirmed tool use, sophistication levels, and full campaign timelines, necessitating further intelligence collection for precise attribution.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics