Treasury has identified a sophisticated cyber-enabled ATM cash out campaign we are calling FASTCash. FASTCash has been active since late 2016 targeting banks in Africa and Asia to remotely compromise payment switch application servers within banks to facilitate fraudulent transactions, primarily involving ATMs, to steal cash equivalent to tens of millions of dollars. FBI has attributed malware used in this campaign to the North Korean government. We expect FASTCash to continue targeting retail payment systems vulnerable to remote exploitation.
Executive Summary
FASTCash is a sophisticated cyber-enabled ATM cash-out campaign identified by the Treasury and FBI as linked to North Korean state-sponsored actors. This campaign has targeted banks in Africa and Asia since late 2016, compromising payment switch application servers to steal tens of millions of dollars through fraudulent transactions.
Goals & Targeting
FASTCash's primary goal appears to be the theft of significant financial resources through fraudulent transactions, with a focus on targeting banking systems in Africa and Asia. The campaign exploits vulnerabilities in payment switch servers, enabling unauthorized access and manipulation of ATM networks. The choice of sectors and regions likely reflects opportunities for high-value targets with weaker cybersecurity defenses. Victims have included banks and financial institutions vulnerable to remote exploitation, making them attractive for large-scale fraud.
Enhanced Description
FASTCash represents a significant cyber threat to financial institutions, particularly those operating in regions with inadequate cybersecurity measures. The campaign leverages advanced techniques to compromise payment systems, enabling the theft of large sums via ATM networks. It is notable for its state-sponsored origins, with the FBI attributing the malware used in these attacks to North Korea. FASTCash demonstrates a high level of technical sophistication, with operators targeting vulnerable retail payment systems and exploiting remote access capabilities to execute their attacks. The long operational timeframe (since late 2016) and continued activity suggest a well-resourced and persistent threat actor focused on financial gain.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
FASTCash has demonstrated a persistent and evolving approach to targeting financial systems. The campaign's longevity since late 2016 indicates a well-planned operational strategy, with operators likely refining their techniques over time. Targeting of banks in Africa and Asia suggests an understanding of regional cybersecurity gaps. Notable operations include high-profile ATM cash-outs, which indicate both technical proficiency and an ability to exploit systemic vulnerabilities in payment infrastructure.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the attribution of FASTCash to North Korean actors based on FBI findings and malware links. The operational timeline and targeting patterns are well-documented, though specific technical details of TTPs remain limited.
No techniques linked yet.
No tools linked yet.
FASTCash
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
0
IOCs
0
Observed Data
0
Tactics