Full Report
One malware campaign, 11,000 compromised devices, two banks with very different outcomes. At the bank with fused defence, fraud succeeded on just 0.027% of compromised devices; nine times less than the market average. Regulators are taking notice too.
Analysis Summary
# Incident Report: Comparative Analysis of a Global Banking Malware Campaign
## Executive Summary
A large-scale malware campaign targeted over 11,000 compromised devices across multiple financial jurisdictions. The incident highlights a stark disparity in outcomes based on defensive architecture: a bank utilizing "fused defense" (integrated cyber and fraud teams) limited successful fraud to 0.027% of compromised devices, performing nine times better than the market average.
## Incident Details
- **Discovery Date:** Campaign analysis spanning mid-2024 to 2026 regulatory milestones
- **Incident Date:** Ongoing/Multi-year campaign
- **Affected Organization:** Two unnamed banks (for comparative study)
- **Sector:** Banking and Financial Services
- **Geography:** Global (Impact noted in UK, Singapore, Australia, UAE, Saudi Arabia, EU, and USA)
## Timeline of Events
### Initial Access
- **Date/Time:** Variable per device
- **Vector:** Malware infection of customer end-user devices
- **Details:** The campaign targeted 11,000+ devices globally to facilitate unauthorized financial transactions.
### Lateral Movement
- **Details:** Focus was not on traditional network lateral movement, but rather the transition from device compromise to session hijacking and account takeover within banking applications.
### Data Exfiltration/Impact
- **Impact:** Attempted unauthorized fund transfers and Authorized Push Payment (APP) fraud.
- **Success Rate:** High variability; "Bank A" (standard defense) saw typical market loss rates, while "Bank B" (fused defense) saw only a 0.027% success rate.
### Detection & Response
- **Discovery:** Detected via behavior-based fraud monitoring and real-time threat intelligence.
- **Response:** Fused defense banks utilized real-time blocking and automated risk-based monitoring across both sending and receiving sides of transactions.
## Attack Methodology
- **Initial Access:** Malware infection on customer devices.
- **Persistence:** Maintenance of access to mobile/web banking sessions.
- **Defense Evasion:** Use of legitimate customer devices to bypass geographic and device-based whitelisting.
- **Credential Access:** Harvesting of banking credentials and session tokens via malware.
- **Impact:** Financial theft via fraudulent payments (ACH, APP scams).
## Impact Assessment
- **Financial:** Significant potential losses; market average fraud success is 9x higher than fused-defense benchmarks.
- **Data Breach:** Compromise of 11,000+ sets of user device/banking credentials.
- **Operational:** Increased pressure on fraud and SOC teams to align workflows.
- **Reputational/Regulatory:** Significant exposure to new global liability frameworks (e.g., Australia’s AUD 50M penalties, UK mandatory reimbursement).
## Indicators of Compromise
- **Behavioral indicators:** Discrepancies between technical device signals (malware presence) and transaction patterns.
- **Network indicators:** Transactions originating from devices with known malware signatures (defanged for report: `malware-signature-alpha[.]local`).
## Response Actions
- **Containment:** Real-time detection and blocking of suspicious activity.
- **Eradication:** Identification of compromised customer devices to prompt password resets and device cleaning.
- **Recovery:** Implementation of mandatory reimbursement and shared responsibility frameworks as per local regulations.
## Lessons Learned
- **Siloed Defense is Ineffective:** Separating "Cyber" (technical breach) from "Fraud" (monetary loss) leads to a 9x higher success rate for attackers.
- **Regulatory Shift:** Regulators (SAMA, EU PSD3, US Nacha) are moving toward holding banks liable for "failure to prevent," necessitating real-time prevention.
- **Fusion Model:** Integrating technical signals with transactional analysis is the only way to reach the 0.027% success benchmark.
## Recommendations
- **Adopt Cyber-Fraud Fusion:** Unify SOC and Fraud department workflows into a single architecture.
- **Real-Time Monitoring:** Implement risk-based monitoring on both the sending and receiving sides of every payment (e.g., ACH/APP).
- **Intelligence Sharing:** Actively participate in cross-institutional intelligence sharing as mandated by new frameworks like Singapore’s SRF.
- **Gap Analysis:** Map current regulatory exposure against the "three levers": liability regimes, real-time mandates, and sharing requirements.