Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors FASTCash

Description

Treasury has identified a sophisticated cyber-enabled ATM cash out campaign we are calling FASTCash. FASTCash has been active since late 2016 targeting banks in Africa and Asia to remotely compromise payment switch application servers within banks to facilitate fraudulent transactions, primarily involving ATMs, to steal cash equivalent to tens of millions of dollars. FBI has attributed malware used in this campaign to the North Korean government. We expect FASTCash to continue targeting retail payment systems vulnerable to remote exploitation.

AI Analysis

· 1 week ago

Executive Summary

FASTCash is a sophisticated cyber-enabled ATM cash-out campaign identified by the Treasury and FBI as linked to North Korean state-sponsored actors. This campaign has targeted banks in Africa and Asia since late 2016, compromising payment switch application servers to steal tens of millions of dollars through fraudulent transactions.

Goals & Targeting

FASTCash's primary goal appears to be the theft of significant financial resources through fraudulent transactions, with a focus on targeting banking systems in Africa and Asia. The campaign exploits vulnerabilities in payment switch servers, enabling unauthorized access and manipulation of ATM networks. The choice of sectors and regions likely reflects opportunities for high-value targets with weaker cybersecurity defenses. Victims have included banks and financial institutions vulnerable to remote exploitation, making them attractive for large-scale fraud.

Enhanced Description

FASTCash represents a significant cyber threat to financial institutions, particularly those operating in regions with inadequate cybersecurity measures. The campaign leverages advanced techniques to compromise payment systems, enabling the theft of large sums via ATM networks. It is notable for its state-sponsored origins, with the FBI attributing the malware used in these attacks to North Korea. FASTCash demonstrates a high level of technical sophistication, with operators targeting vulnerable retail payment systems and exploiting remote access capabilities to execute their attacks. The long operational timeframe (since late 2016) and continued activity suggest a well-resourced and persistent threat actor focused on financial gain.

Key Capabilities

  • Remote compromise of payment switch application servers
  • Execution of fraudulent transactions through compromised systems
  • Persistence in target networks for prolonged periods
  • Use of malware linked to North Korean state-sponsored actors
  • Targeting vulnerable retail payment systems

MITRE ATT&CK Tactics

Initial Access
Execution
Post-Compromise Activity

ATT&CK Techniques

T1059
T1078
T1204

Software / Tooling

Mirai variant malware (linked to North Korean actors)
Custom-built financial fraud tools

Campaigns & Victims

FASTCash has demonstrated a persistent and evolving approach to targeting financial systems. The campaign's longevity since late 2016 indicates a well-planned operational strategy, with operators likely refining their techniques over time. Targeting of banks in Africa and Asia suggests an understanding of regional cybersecurity gaps. Notable operations include high-profile ATM cash-outs, which indicate both technical proficiency and an ability to exploit systemic vulnerabilities in payment infrastructure.

IOC Patterns

  • Unusual spikes in ATM transaction volumes
  • Network traffic anomalies within payment systems
  • Presence of custom malware linked to North Korean APT groups

Recommended Actions

  • Implement robust security measures for retail payment systems and ATM networks
  • Monitor for unusual patterns in financial transaction logs
  • Conduct regular penetration testing on payment switch servers
  • Adopt MITRE ATT&CK-based detection mechanisms to identify potential compromises
  • Enhance network segmentation to limit lateral movement by attackers

Suggested Tags

APT
North Korea
Banking Sector
Financial Fraud

Confidence Assessment

High confidence in the attribution of FASTCash to North Korean actors based on FBI findings and malware links. The operational timeline and targeting patterns are well-documented, though specific technical details of TTPs remain limited.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

1

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Financial Targeting
Government Targeting
APT
North Korea
Banking Sector
Financial Fraud

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.