Cyber Crime

Crooks used a KilllDisk wiper in an attack against Banco de Chile as diversion for a SWIFT hack

Crooks attempted to hack the SWIFT system at the Banco de Chile and used a disk-wiping malware as a diversion strategy.

The intent of the attackers was to sabotage hundreds of computers at the Banco de Chile while they were attempting to breach the real target, the bank’s SWIFT money transferring system.

Causing a broad outage, the attackers aimed at distracting the internal IT staff while carrying our the cyberheist.

The attempted attack took place on May 24, as result, many systems at several of its branches were inoperable.

“May 24, 2018, Banco de Chile reports that today it detected the presence of a fault that affected our normal attention in branches, telephone banking and some specific services.” reads the security advisory published by the company,

“This generated the activation of our contingency protocol designed to maintain the continuity of the services, and in no case was the security of the products and transactions of our clients affected.” 

Initial investigation conducted by the bank revealed that the bank systems were infected by a malware.

“After an exhaustive investigation, it was determined that the origin of the detected fault was a virus, presumably from international networks, which directly affected Banco de Chile’s work stations, such as an inn in the offices and terminals of our executives and cashier personnel, among others, causing difficulties in branch service and telephone banking.” reads the announcement published by the bank on May 28.

Analyzing the images posted online by bank employees, it is possible to verify that the infected machine where hit by a malware that wiped their hard drives’ Master Boot Records (MBRs).

Bleeping Computer reported a screenshot of private IM conversations posted on a Chilean forum. According to a member of the forum, the wiper destroyed over 9,000 computers and over 500 servers.

According to experts from Arkavia Networks, the malware that infected the systems at the Banco de Chile was a KillDisk sample tracked as KillMBR by Trend Micro.

A couple of days ago, experts at Trend Micro reported the discovery of a new sample of KillDisk in Latin America, the malware infected the systems of a bank.

Trend Micro did not reveal the name of the bank, but likely it was the Chilean bank.

According to the experts, the hacker failed the attack because the real goal was obtaining the access to SWIFT network.

“Last May, we uncovered a master boot record (MBR)-wiping malware in the same region. One of the affected organizations was a bank whose systems were rendered inoperable for several days, thereby disrupting operations for almost a week and limiting services to customers.” reads the analysis published by Trend Micro.

“Our analysis indicates that the attack was used only as a distraction — the end goal was to access the systems connected to the bank’s local SWIFT network.”

The malware researchers determined that the malicious code was a strain of the dreaded Killdisk due to on the error message displayed by the affected systems.

The malware discovered by Trend Micro wipes all physical hard disks on the infected system, it retrieves the handle of the hard disk and overwrites the first sector of the disk (512 bytes) with “0x00”, then forces the machine to shut down.

Trend Micro team associated the sample of the KillDisk recently discovered with the operations of a crime gang that a few weeks ago attempted to steal over $110 million from the Mexican bank Bancomext.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs –Banco de Chile, wiper)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Google fixed critical Chrome vulnerability CVE-2024-4058

Google addressed a critical Chrome vulnerability, tracked as CVE-2024-4058, that resides in the ANGLE graphics…

3 hours ago

Nation-state actors exploited two zero-days in ASA and FTD firewalls to breach government networks

Nation-state actor UAT4356 has been exploiting two zero-days in ASA and FTD firewalls since November…

15 hours ago

Hackers hijacked the eScan Antivirus update mechanism in malware campaign

A malware campaign has been exploiting the updating mechanism of the eScan antivirus to distribute…

22 hours ago

US offers a $10 million reward for information on four Iranian nationals

The Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned four Iranian nationals for their…

1 day ago

The street lights in Leicester City cannot be turned off due to a cyber attack

A cyber attack on Leicester City Council resulted in certain street lights remaining illuminated all…

1 day ago

North Korea-linked APT groups target South Korean defense contractors

The National Police Agency in South Korea warns that North Korea-linked threat actors are targeting…

2 days ago

This website uses cookies.