2、研究人员认为攻击台湾和欧洲ATM系同一团伙
标题:Cybersecurity Expert Links Taiwan And Europe ATM Hacks
作者信息:1/6/2017 10:10 AM By Dark Reading Staff
//BEGIN
Group-IB says both attacks were likely carried out by Cobalt group using malware "ATM spitter."
Cybersecurity firm Group-IB has linked the July Taiwan ATM cyber heist to the ATM hacking spree in Europe last year, claiming the two were carried out by the same hacking group, dubbed Cobalt. Reuters reports that Group-IB’s conclusion is based on the fact that the hack technique used in both incidents match.
通过对2起发生在不同地域的针对ATM银行取款机的盗取行动的技术分析,安全团队得出了结论:台湾第一银行的幕后黑手和去年欧洲的ATM取款机的盗取者应该属于同一组织。同时给该组织命名为Cobalt。
//END
A group of 22 foreign nationals are alleged to be behind the First Commercial Bank ATM hack in Taiwan, of which three Eastern Europeans are in custody. Most of the stolen money was recovered and Taiwan authorities believe the bank network was breached at a London branch.
According to a Group-IB report, the hackers used malware “ATM spitter” in the Taiwan attack as well as in similar hacks carried out in Britain, Russia, Poland, Spain, Bulgaria, and many other European countries, Reuters adds.
台湾第一银行的ATM盗取案件涉及到22个来自不同国家的犯罪团伙,其中有3人来自东欧国家,这些人正在被拘留。大多数的赃款被追回,不过中国台湾当局确认这些银行网络的泄露地点位于英国伦敦的分支机构。
这些攻击行为发生在除了中国台湾地区外的世界的多个国家和地区,其中包括:亚美尼亚、白俄罗斯、保加利亚、爱沙尼亚、格鲁吉亚、哈沙克斯坦、摩尔多瓦、荷兰、波兰、罗马尼亚、俄罗斯和西班牙等。
点评:归因还是有难度的:包括技术层面和非技术因素。 |