The Mysterious Case of the Ukrainian Bagsu

No ratings

Presented at CopenhagenCyberCrime 2019 by

Bagsu is a Trojan banker that has been around for approx. 4 years without getting much attention from the security industry. That is about to change now. So strap on your seatbelts as we are heading for an unexpected ride into a fairly organized and long time running criminal operation distributing the Bagsu malware - but also many other and more complex malware families - sharing the same infrastructure and MO.The name Bagsu is a generic naming scheme as the code is more or less based on the leaked ZeuS source code. It is therefore not something new as such, but the criminals behind this operation prefer to keep a low profile and fly under the radar. So far - unfortunately - with great success.Apart from targeting Windows, we have also found several previously undocumented Android malware samples that have been deployed in the wild since 2014.Lately we have observed how the author and brain behind this operation has switched to a Crime as a Service setup and just the begining of 2019 we can document losses of several million euros stolen from enterprises globally but mostly in Germany.This presentation will look into the binary code, its distribution methods, geographical targets, infrastructure, and finally - as always when it comes to research from CSIS - the potential identity of the person/individuals behind it.