There seems to be a new variant of the North Korean malware #FASTCASH that hacks ATMs. The interesting quirk is that the only currency it steals is... Turkish Lira? This makes more sense when you consider that:
1) Over the last 1.5 or so years most big crypto exchanges have been making moves towards Turkey (opening offices, sponsoring local events, etc.)
2) DPRK loves stealing crypto but cashing out is still a challenge for them
While this malware just looks like it engages in outright theft I have a strong hunch that laundering stolen crypto is a factor here.
thread: https://x.com/haxrob/status/1845307197913432282
[UPDATE] IOCs here: https://otx.alienvault.com/pulse/670ead49449b8caec5e64437
#NorthKorea #DPRK #cybersecurity #ATMJackpotting #infosec #Turkey #Turkiye #Istanbul #crypto #cryptocurrency #malware #TurkishLira #currency #ATM #ATMs #scams #theft