Cyber Crime

Crooks used a KilllDisk wiper in an attack against Banco de Chile as diversion for a SWIFT hack

Crooks attempted to hack the SWIFT system at the Banco de Chile and used a disk-wiping malware as a diversion strategy.

The intent of the attackers was to sabotage hundreds of computers at the Banco de Chile while they were attempting to breach the real target, the bank’s SWIFT money transferring system.

Causing a broad outage, the attackers aimed at distracting the internal IT staff while carrying our the cyberheist.

The attempted attack took place on May 24, as result, many systems at several of its branches were inoperable.

“May 24, 2018, Banco de Chile reports that today it detected the presence of a fault that affected our normal attention in branches, telephone banking and some specific services.” reads the security advisory published by the company,

“This generated the activation of our contingency protocol designed to maintain the continuity of the services, and in no case was the security of the products and transactions of our clients affected.” 

Initial investigation conducted by the bank revealed that the bank systems were infected by a malware.

“After an exhaustive investigation, it was determined that the origin of the detected fault was a virus, presumably from international networks, which directly affected Banco de Chile’s work stations, such as an inn in the offices and terminals of our executives and cashier personnel, among others, causing difficulties in branch service and telephone banking.” reads the announcement published by the bank on May 28.

Analyzing the images posted online by bank employees, it is possible to verify that the infected machine where hit by a malware that wiped their hard drives’ Master Boot Records (MBRs).

Bleeping Computer reported a screenshot of private IM conversations posted on a Chilean forum. According to a member of the forum, the wiper destroyed over 9,000 computers and over 500 servers.

According to experts from Arkavia Networks, the malware that infected the systems at the Banco de Chile was a KillDisk sample tracked as KillMBR by Trend Micro.

A couple of days ago, experts at Trend Micro reported the discovery of a new sample of KillDisk in Latin America, the malware infected the systems of a bank.

Trend Micro did not reveal the name of the bank, but likely it was the Chilean bank.

According to the experts, the hacker failed the attack because the real goal was obtaining the access to SWIFT network.

“Last May, we uncovered a master boot record (MBR)-wiping malware in the same region. One of the affected organizations was a bank whose systems were rendered inoperable for several days, thereby disrupting operations for almost a week and limiting services to customers.” reads the analysis published by Trend Micro.

“Our analysis indicates that the attack was used only as a distraction — the end goal was to access the systems connected to the bank’s local SWIFT network.”

The malware researchers determined that the malicious code was a strain of the dreaded Killdisk due to on the error message displayed by the affected systems.

The malware discovered by Trend Micro wipes all physical hard disks on the infected system, it retrieves the handle of the hard disk and overwrites the first sector of the disk (512 bytes) with “0x00”, then forces the machine to shut down.

Trend Micro team associated the sample of the KillDisk recently discovered with the operations of a crime gang that a few weeks ago attempted to steal over $110 million from the Mexican bank Bancomext.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs –Banco de Chile, wiper)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Fintech firm Figure disclosed data breach after employee phishing attack

Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…

20 hours ago

U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…

21 hours ago

Suspected Russian hackers deploy CANFAIL malware against Ukraine

A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…

1 day ago

New threat actor UAT-9921 deploys VoidLink against enterprise sectors

A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…

2 days ago

Attackers exploit BeyondTrust CVE-2026-1731 within hours of PoC release

Attackers quickly targeted BeyondTrust flaw CVE-2026-1731 after a PoC was released, enabling unauthenticated remote code…

2 days ago

Google: state-backed hackers exploit Gemini AI for cyber recon and attacks

Google says nation-state actors used Gemini AI for reconnaissance and attack support in cyber operations.…

2 days ago

This website uses cookies.