Home » Business » Lazarus Heist: The intercontinental ATM theft that netted $14m in two hours
Business

Lazarus Heist: The intercontinental ATM theft that netted $14m in two hours

Imagine you are a low-wage worker in India who is offered a day as an extra in a Bollywood film. your role? Go to an ATM and withdraw some money.

In 2018, several men in the state of Maharashtra thought they would take on a small role in a movie — but in fact, they were tricked into being money mules, raising cash in an ambitious bank robbery.

The raid took place over a weekend in August 2018 and focused on Cosmos Co-operative Bank, which is headquartered in Pune.

On a quiet Saturday afternoon, staff at the bank’s headquarters suddenly received a series of alarming messages.

They came from card payment company Visa in the United States and warned that thousands of requests for large cash withdrawals could be pouring in from ATMs – from people who appear to be using Cosmos Bank cards.

But when the Cosmos team checked their own systems, they saw no abnormal transactions.

About half an hour later, they authorized Visa to be sure to stop all Cosmos bank card transactions. This delay would prove extremely costly.

The next day, Visa shared the full list of suspicious transactions with Cosmos headquarters: about 12,000 separate withdrawals from different ATMs around the world.

The bank had lost almost $14 million (£11.5 million).

Warning: This article contains spoilers for the Lazarus Heist podcast

It was a daring crime, notable for its large scale and meticulous dubbing. Criminals had looted ATMs in 28 different countries, including the US, UK, UAE and Russia. It all happened in just two hours and 13 minutes – an extraordinary global crime flash mob.

Eventually, investigators would trace its origins to a shadowy group of hackers who performed a series of previous jabs, seemingly at the behest of the North Korean state.

But before they knew the full picture, investigators from the Maharashtra Cybercrime Unit were stunned to see CCTV footage of dozens of men going to a row of ATMs, inserting bank cards and stuffing the bills into pockets.

“We were not aware of a money mule network like this,” says Insp General Brijesh Singh, who led the investigation.

One gang had a handler who monitored ATM transactions in real time on a laptop, Singh says. CCTV footage showed that whenever a money courier tried to keep some of the cash, the handler noticed and slapped him hard across the face.

Using CCTV footage and cell phone data from areas near the ATMs, Indian investigators arrested 18 suspects in the weeks following the raid. Most are now in prison awaiting trial.

Singh says these men were not hardened crooks. Among those arrested were a waiter, a driver and a shoemaker. Another had a degree in pharmacy.

“They were gentle people,” he says.

Despite this, he believes that at the time of the raid, even the men recruited as “extras” knew what they were really doing.

But did they know who they worked for?

Investigators believe the mysterious and isolated state of North Korea was behind the attack.

Hackers, North Korea and billions of dollars.

Listen to BBC World Service’s The Lazarus Heist with Jean Lee and Geoff White

North Korea is one of the world’s poorest nations, yet a significant portion of its limited resources goes into building nuclear weapons and ballistic missiles, activities banned by the UN Security Council. As a result, the UN has imposed onerous sanctions on the country that severely restrict trade.

Since coming to power 11 years ago, North Korean leader Kim Jong Un has led an unprecedented campaign of weapons testing, including four nuclear tests and several provocative offers to test-launch ICBMs.

US authorities believe the North Korean government is using a group of elite hackers to break into banks and financial institutions around the world and steal the money it needs to keep the economy afloat and fund the weapons program .

Nicknamed the Lazarus Group, the hackers are believed to be part of an entity run by North Korea’s powerful military intelligence agency, the Reconnaissance General Bureau.

Cyber ​​security experts named the hackers after the biblical figure Lazarus, who rose from the dead – because once their viruses get into computer networks, they are almost impossible to kill.

The group first gained international notoriety when then-US President Barack Obama accused North Korea of ​​hacking into Sony Pictures Entertainment’s computer network in 2014, which depicted the assassination of Kim Jong Un.

The Lazarus Group has since been accused of attempting to steal $1 billion (£815 million) from Bangladesh’s central bank in 2016 and launching the WannaCry cyberattack, which attempted to ransom money from victims around the world , including the NHS in the UK.

North Korea strongly denies the existence of the Lazarus Group and any claims of state-sponsored hacking.

But top law enforcement agencies say North Korea’s hacks are more advanced, bolder and more ambitious than ever.

For the Cosmos heist, the hackers used a technique known as “jackpotting” – so called because it’s like making the ATM pay out your money, like hitting the jackpot on a slot machine.

The bank’s systems were initially compromised in the classic way: through a phishing e-mail opened by an employee, which infected the computer network with malware. Once inside, the hackers manipulated a piece of software – called an ATM switch – that sends messages to a bank to authorize an ATM withdrawal.

This then gave the hackers the power to allow ATM withdrawals from their accomplices anywhere in the world. The only thing they couldn’t change was the maximum amount for each withdrawal, so they needed a lot of cards and a lot of people on site.

In preparation for the raid, they worked with accomplices to create “cloned” ATM cards – using real bank account details to create duplicate cards that can be used in ATMs.

The British security company BAE Systems immediately suspected that it was the Lazarus Group plant. It had been monitoring them for months and knew they were planning an attack on an Indian bank. It just didn’t know which one.

“It would have been too much of a coincidence to be another criminal operation,” says BAE security researcher Adrian Nish. The Lazarus Group is diverse and very ambitious, he says. “Most criminal groups would probably be happy enough to get away with a few million and stop at that.”

The logistics involved in the Cosmos Bank heist are mind boggling. How did the hackers find local accomplices in 28 countries, including many that North Korean citizens cannot legally visit?

US tech security investigators believe the Lazarus group has struck a key intermediary on the dark web, where entire forums dedicated to sharing hacking skills exist and where criminals often sell support services. In February 2018, a user calling himself Big Boss posted tips on how to carry out credit card fraud. He also said he has the equipment to create cloned ATM cards and has access to a group of money mules in the United States and Canada.

This was exactly the service Lazarus Group needed for their success at Cosmos Bank and they started working with Big Boss.

We asked Mike DeBolt, chief intelligence officer at Intel 471 – a tech security firm in the US – to find out more about this accomplice.

DeBolt’s team discovered that Big Boss had been active for at least 14 years and had a variety of aliases: G, Habibi, and Backwood. The security detectives managed to link him to all of these usernames because he was using the same email address on different forums.

“Basically, he’s lazy,” says DeBolt. “We see this quite often: actors change their alias on a forum but keep the same email address.”

In 2019, Big Boss was arrested in the US and revealed to be Ghaleb Alaumary, a 36-year-old Canadian. He pleaded guilty to laundering funds from alleged North Korean bank robberies and was sentenced to 11 years and eight months.

North Korea has never admitted involvement in the Cosmos Bank contract or any other hacking scheme. The BBC submitted allegations of involvement in the Cosmos attack to the North Korean embassy in London, but received no response.

However, when we contacted him earlier, Ambassador Choe Il replied that the allegations of North Korean state-sponsored hacking and money laundering were “a sham” and an attempt by the US to “smear our state’s image.”

In February 2021, the FBI, the US Secret Service and the Justice Department announced indictments against three suspected Lazarus Group hackers: Jon Chang Hyok, Kim Il and Park Jin Hyok, who they said work for North Korea’s military intelligence agency. They are now said to be back in Pyongyang.

US and South Korean authorities estimate that North Korea has up to 7,000 trained hackers. They are unlikely to all work within the country, where few people have permission to use the internet, making it difficult to hide users’ activities. Instead, they are often sent abroad.

Ryu Hyeon Woo, a former North Korean diplomat and one of the longest-serving people to leave the regime, provided an insight into how hackers work overseas.

In 2017, he worked at the North Korean embassy in Kuwait, helping to oversee the employment of around 10,000 North Koreans in the region. At that time, many worked on construction sites in the Gulf and, like all North Korean workers, had to hand over most of their wages to the regime.

He said his office received a daily call from a North Korean handler overseeing 19 hackers living and working in crowded neighborhoods in Dubai. “That’s really all they need: a computer connected to the internet,” he said.

North Korea denies sending hackers abroad, only IT staff with valid visas. But Mr. Ryu’s description fits the FBI’s claims about how these cyber entities operate from dormitories around the world.

In September 2017, the UN Security Council imposed its toughest sanctions on North Korea, limiting fuel imports, further restricting exports and requiring UN member states to send North Korean workers home by December 2019.

However, the hackers still seem to be active. They are now targeting cryptocurrency companies and are estimated to have stolen nearly $3.2 billion.

US authorities have described them as “the world’s leading bank robbers” who use “keyboards instead of guns”.

Add Comment

Click here to post a comment