Showing posts with label bank. Show all posts
Showing posts with label bank. Show all posts

Sunday, 23 September 2018

A Nation State Robbing Banks: 80 Million and a Spelling Error (Night's Black Agents)

This post is inspired in part by Kento Bento's video about the biggest bank heist in modern history:


You may remember me mentioning this bank heist before, back in 2016 when not all the facts were in.

A couple quick points before I dive into Lazarus. Night's Black Agents Directors and agents wondering if Human Terrain is useful, wonder no more. Think about how cleverly this whole thing had to be coordinated: the thieves knew if they hit this particular bank on this particular day, and then transferred the stolen money to a bank in the Philippines, they'd be in the clear. Bangladesh, being Muslim majority, had its weekend on Friday and Saturday. The hack starts Friday. They come in on Sunday to sort out their problems, but they can't talk to their colleagues in New York because, on Sunday, their Christian colleagues are all off for the day. Monday works, but the bank in the Philippines, where the money is sent, is celebrating Chinese New Year, so it can't be contacted. That was fiendishly clever timing on someone's part.

Two, you may remember me mentioning a missing IT expert in the previous post. That expert, Tanveer Hassan Zoha, did turn up eventually. Detectives found him wandering near the airport and took him home, six days after he went missing. The IT expert claimed he could discover the identity of some of the culprits, and went with special police to the Bangladesh bank to have a look at the bank's records. Two days after that he was abducted from an auto rickshaw, and his family claimed the police were no help finding him. As far as I can determine his abductors were not caught. If he ever issued a public statement about his abduction, he didn't make it in an English language publication, as far as I know.

Bangladesh Airport connects to Hong Kong via Cathay Dragon, and Hong Kong is only a ferry ride away from Macau. That's where the alleged thieves went - it was a stopping point on their journey to North Korea, according to Kento Bento.

Which brings me to Lazarus Group, an entity that has been committing cybercrime since the early 2000s. Its earliest known attacks targeted South Korea, and it's alleged that the group has links to the North Korean government. This is difficult to prove, and might be a fake-out to throw blame on a believable straw man. That said, if anyone's going to think it's a good idea to back a group of crooks on a cybercrime spree, it's the dictator who may have poisoned his half-brother at an airport shopping concourse.

Lazarus has hit banks before, but banks aren't its only focus. It likes to hit South Korean targets, and allegedly was responsible for the Sony hack in 2014. The group demanded Sony withdraw its film The Interview, a comedy about an attempt on Kim Jong-un's life.


The Interview had so-so reviews and according to IMDB lost a ton of money - budget $44 million, worldwide gross something in the region of $12 million. Sony pulled the film from theatres in December 2014, allowing only a limited independent cinema release, and that after President Obama criticized Sony for giving in to terrorist threats.

Cybercrime experts Kaspersky Labs analyzed the Bangladesh hack, and give Kaspersky praise because it has nailed down the perfect hacking mini-scenario for Night's Black Agents Directors.

Initial Compromise. A single system inside the bank is breached with remotely accessible vulnerable code, perhaps through a webserver or a watering hole on a seemingly trustworthy website. The premise is simple: find a site you know the target visits, like a Chinese takeaway. The security on that site is bound to be less robust than the target's IT. Break it, infect it, wait for your target to visit - and the mouse takes the cheese. Snap!

Foothold Established. The group establishes persistent backdoors so they can come and go as they like.

Internal Reconnaissance.  The groups spends days, weeks, learning the network and identifying useful resources, like a backup server with vital information or an email server that can let the hackers into anything connected to that server. With the Bangladesh hack, Lazarus was particularly interested in SWIFT authentication, so it went after any server that might contain SWIFT authorization codes as well as IT admin systems.

Deliver and Steal. The great hack begins. Presumably followed by a scene Kaspersky does not mention, tentatively titled RUN AWAY!

This is the perfect breakdown for scenes in a game. What's more, they don't have to be about Digital Intrusion and nothing else. Human Terrain, Surveillance, Infiltration, Electronic Surveillance, potentially Flattery, Bureaucracy - all these will be useful, particularly in the early stages of the hack.

I see this as a potential Thrilling Digital Intrusion contest, starting with the initial compromise and moving through to final execution. The technothriller dialogue opportunities, particularly in the Initial Compromise or Internal Reconnaissance, are fascinating. It's a reminder that a Thrilling Contest doesn't have to be over in a few minutes. This one takes months - though at the table on the day the whole thing might take an hour's game time at most.

As for North Korea, well … it'd make a hell of a Node.

Enjoy!

Sunday, 17 September 2017

Ripped from the Headlines: Fishtanks, Yachts, Bankers and Cuba

Ever wonder what it takes to hack into a casino? Or whether those wealthy tourists disembarking from that yacht are all they seem to be? Wonder no more! Searching for something new for your Night's Black Agents game, or looking for a special new toy for the opposition to play with? Read on!

Recently someone cracked a North American casino - name and location carefully withheld, according to the Washington Post - by way of its fish tank. The tank's systems were connected in order to monitor temperature, food, cleanliness; after all, it had to look its best. Since it was connected, hackers got into the casino's systems and stole 10GB of data, sending it all to a device in Finland, and from there God, and possibly the NSA, alone knows where. Nobody's saying what the data was. Best guess is guest information, credit cards, that sort of thing.

I've discussed this topic before, but it bears repeating. If your players are wondering how best to hack into a facility, the easiest route is via the weak point that is the Internet of Things.


Every single thing in that facility is connected to something. The fish tank needs food. Vending machines need to tell home base when they are empty. Lights and cameras need to sense activity. Projectors connect, as do thermostats, HVAC, plumbing, lavatories. Complex equipment, like tractors, may have multiple processes, some of which may have been modified by the owner, some of which may be set by the manufacturer to only accept its brand of maintenance. Every single thing needs to be managed, and that means it is vulnerable.

The facility owner may not even have full control over its systems. Recently there's been a ton of internet hate directed at the entrepreneurs behind the Bodega vending machine, because apparently they have no idea how marketing works and thought saying they wanted to destroy corner store bodegas would be a good idea. However my first thought wasn't 'oh no, my bodega,' because my nearest bodega is a few thousand miles away and I can't swim that far. No, my first thought was, 'here's a device that's technically managed by an outside agency, but you can bet your sweet bippy it'll be connected to the host's network.' Probably for no good reason either, but that's never stopped anyone in the history of anything. Which means that if the Bodega has a system vulnerability, then its host has a system vulnerability - and the same applies to every single outside agency device you care to name. The device might even have malware built right in.

In fact, there's a genius idea right there. Say your characters notice that the vending machine is supplied and maintained by XYZ Corp. Oh, no, it broke. Darn shame. Oh look, here's a new one - wow, that's fast service. Is anyone going to check and see whether the soda machine delivered actually is from XYZ Corp? Are they hell - so long as it supplies frosty beverages, the host's never going to question it. XYZ Corp will, so you need a workaround there, but apart from that you've an actual Trojan horse wheeled in and installed, dispensing all kinds of goodness, sweetness and light. Plus malware. Yummy. In Night's Black Agents terms, it's a job for the Wire Rat rather than the Hacker - but think of the benefits!

The next one's from this Guardian article about people smuggling. Many hundreds of thousands are fleeing Syria, some with much more money than the rest. For those with the cash, there's a better quality of service. Professionals, entrepreneurs and other wealthy migrants who couldn't get out by other means were paying a Turkish crime syndicate hundreds of thousands at a time to get them and their families out, on cruises best described as luxury desperation.

According to one Italian prosecutor, some smugglers were behaving like travel agencies, offering first, second and third-class accommodation. "It depends how much money you can pay."

We often talk about people smuggling in terms of desperation, hardship, and despair. The route to Italy has been described as the most lethal. Yet at the same time the rich buy their way out of that problem, and make the same crossing in Port Out, Starboard Home style.

As gamification, consider: this is the perfect route for an abandoned Conspiracy asset, Esoterrorist or other well-heeled undesirable to make their way out of a hot zone to somewhere more appealing. Dracula himself once used much the same tactic to get to Whitby, although he definitely travelled closer to third class than first. Finding an abandoned luxury yacht afloat in the Mediterranean is a good hook for a scenario, and this one has an added bonus: the crime syndicate that financed the cruise will be just as interested as the characters in finding out what went wrong, which makes them perfect second-string antagonists for the scenario.

An old one from Monaco: HSBC's banker to the rich and famous was arrested and charged over allegations that he siphoned close to $10 million from his clients' accounts. The banker, Stephen Troth, fought back by claiming his employers were the ones to blame, not him. That didn't work, and he was later arrested again in Monaco for kiting cheques. Before all this happened, Troth worked with Edmond J Safra, a banker who was burnt to death in an arson attack. The fire was set by Safra's bodyguard and nurse Ted Maher, who wanted to impress his boss by rescuing him from a blazing inferno, but only got the inferno bit right. Troth was part of Safra's old banking operation, and when HSBC took that over Troth went to work for HSBC.

Ordinarily I wouldn't delve too deeply in yet another banking scandal, were it not for the fact that it happened in Monaco, the microstate that's home to the rich and eccentric. All sorts of people can claim Monaco as their home, so long as they pay a hefty fee. Moreover, as you can see from the above truth defies fiction; if I'd tried to write that plot I'd be laughed out of every publishers from here to Hong Kong. It's got everything: the rich, lunatics, mysterious arson attacks, a disgraced money man claiming his trial is a cover-up for high level corruption, plus all the lavish trappings of wealth in the ritziest microstate in the world.

I've argued before that when designing supernatural threats the Keeper ought to make liberal use of history and folklore. People have been dreaming this sort of thing up for millennia; it's a cinch there's gold in there for Keepers, if only they sift for it. The case of Stephen Troth goes to show that the same applies to less supernatural plotlines. With just the information above I could come up with two or three Night's Black Agents plots without having to do much work; the same goes for you, Director.

Finally, news from Cuba: Canadian and American diplomats posted to Cuba are falling ill, and report a bewildering variety of symptoms, from speech loss and headaches to balancing problems and nervous system damage. Initial reports suggest some kind of sonic weapon is to blame, but nobody's sure what that weapon is - or even if such a weapon is feasible. Infrasound is supposed to have unusual effect on the human body, causing fatigue, panic attacks and, in extreme cases, hallucination. However an effect at this level is more akin to some kind of mad scientist's death ray than anything known to be in development.

The reports came in before Hurricane Irma, which caused considerable damage to Cuba. It would be interesting to know if the effect continues post-Irma.

Frankly, it's tempting to call this a psychosomatic illness. Even if you assume that such a weapon is possible, it's incredible to think the Cubans developed one - and what would be the purpose? A few diplomats sent home ill? Even if you call it a test run, perhaps conducted by the Russians rather than Cuba, there's less high-profile targets you could be testing it on. Nobody would give a damn if this was happening, say, in the Ukraine, except the Ukrainians, and frankly if the West isn't going to pay attention to actual missiles then it wouldn't blink at whatever this sound gun is - assuming it exists at all.

Israel's supposed to have something called The Scream and there have been attempts to make less-than-lethal sonic devices, but the known examples of those toys are very, very obvious when they go off. It wouldn't just be a few diplomats complaining of headaches; half Havana would hear it. Or, as with the Active Denial System, a device that acts on nerve receptors, it's large enough to be seen by pretty much anyone. However this whatever-it-may-be is portable and small enough to avoid immediate detection.

Psychosomatic effects can spread. Sick building syndrome is a bane of facility maintenance people and building surveyors alike as there's no agreed cause, yet, when it starts, an entire building's population may be affected - or at least say they are. Often there is no real cause, no mold or HVAC malfunction you can point to. People just get ill, and as soon as one person says they're suffering it's a sure bet half a dozen others will too - whether they actually are, or not. SBS can be caused by poor work/life balance and stress, factors that don't involve the building in any way, but once people get it into their heads that the building's at fault, nothing will persuade them otherwise. In many ways it's similar to hauntings; all it takes is one or two people spreading the tale, and before you know it everyone's chattering about cold spots and poltergeists.

Edit 12 October: I see I'm not the only one who thinks the whole thing might be psychosomatic.

That's it for this week. Enjoy!

Sunday, 20 March 2016

80 Million and a Spelling Error: Hacking (Night's Black Agents)

When I was just starting out as a low level employee for a financial institution I shall not name, a senior staff member was caught with his fingers in the electronic till. He rigged the system so that, every so often, dormant accounts or trust funds would deposit a trifling amount of money in his personal account. It was never much more than a few dollars, even cents, at a time, but spread over many accounts and over a long period of time those small sums added up to one big payout. He was caught when he went to lunch one day and forgot to lock his machine. Someone came into his office to drop something off, noticed the suspicious activity on his monitor, and passed it on to the higher-ups. It became a police matter very soon after that.

I was reminded of him when I read about the $80 million heist carried out electronically via the Bangladesh Bank. His scheme wasn't original, but it paid off big time, and he would have gotten clean away had he not made a very simple mistake, the kind of error we all make every day. Not quite cautious enough, not quite careful or suspicious enough, and it's game over. It's stories like these that have me paying cash rather than electronic POS whenever I can.

If you haven't already read this one: sophisticated criminals ripped off the central bank of Bangladesh, breaching its systems and then sending requests for money transfer to the US Fed, where Bangladesh Bank had billions stored. Several transfers took place, only for the whole thing to come crashing to a halt when someone misspelled the word Foundation as Fandation on one of the request forms. If that request had gone through the gang - and given the level of preparation it probably was a gang - would have made off with at least a billion, and probably more, since there's no reason to think they would have stopped until Bangladesh's accounts were empty. An IT expert who publicly voiced suspicion that apathetic bank officials had, at the very least, contributed to the caper through their negligence has gone missing. The bank's governor resigned; apparently his employees failed to tell him what had happened, and he only found out about the heist when it hit the papers. Though the bank has said it expects to recover some of the money it seems likely that the bandits will make a clean getaway. Most of it went to casinos in the Philippines, presumably so it could be efficiently laundered, and as a consequence the Philippines may once again be blacklisted by the Money Laundering Task Force. This is all the more important for the Philippines because there are elections coming in May; this kind of news is the last thing the ruling Liberal party needs. At least $30 million in cash ended up in the hands of an ethnic Chinese in Manila, but as for the rest, it could be anywhere.

So what does this story tell us about what it takes to be a hacker in Night's Black Agents?

To begin with, as discussed in last week's post on black baggers, you have to know a lot about human nature and how organizations work. Whoever did this had to know how Bangladesh Bank operated. They probably studied the habits of bank employees for some time before making a move, both in the real world and via keylogger virus or similar on their work machines. They knew when to strike, and how, for maximum impact.

This has been the case since time immemorial, which in computer terms goes back all the way to last week Tuesday. I have on my bookshelf Secrets of a Super Hacker by someone writing under the pseudonym Knightmare. It's hopelessly out of date from a technical perspective - if ever I want to know how to cut up an 8 inch floppy, Knightmare has me covered - but its lessons on interpersonal interaction and information finding are still very relevant. One chapter's devoted to social engineering, another to reverse social engineering, and he spends a remarkable amount of time discussing the joys of dumpster diving and how information found in the trash can help you pillage companies' accounts.

Speaking of, I wonder what Bangladesh Bank did with its trash. Even today banks generate so much paper, reams of physical data. You'd like to think it was all shredded, pulped or otherwise rendered unreadable. But maybe not; after all, Kapersky Labs has a very beautiful interactive map that claims Bangladesh is, at time of writing, the 41st most attacked country in the world. These things don't happen by chance. That same map says Russia is #1 - not an award to be proud of, hope those nuclear silos are doing just fine - Vietnam is #3, the US is #2, and most of Europe seems to be hovering in the 10s and 20s. Apart from Norway, Sweden and Finland, which are #133, #87 and #149. Come on, guys, Finland's not that bad. I know some great Finns. Don't be shy. Bear in mind this is real time data, so by the time you read this everything will have changed, with the possible exception of the top 2.

Incidentally, Kapersky, I notice Bermuda doesn't even feature on the map. Way to hurt my feelings, fellas.

So we're looking at Bureaucracy, Human Terrain, and probably Reassurance to reflect social engineering, and Urban Survival for those dumpster diving expeditions. The hacker is an urban animal; no hiking through the piney woods and living off fresh caught fish or beef jerky for this bunch. A decent Infiltration pool might also be helpful, for breaking into installations and making off with the contents of the shredder. With enough dedication almost anything can be pieced back together. It isn't about whether it can be done, but rather if it's worth the effort. Research is a must, as is Traffic Analysis. Depending on whether or not the hacker makes a dishonest crust by, say, fleecing banks in Bangladesh, or catching those who do, points in Streetwise or Criminology might be in order.

While the hacker is probably the least athletically inclined of all the Night's Black Agents types, it would be a very foolish player who didn't put some points in self defense. However pools in Mechanics and Surveillance are more likely. You're the one who watches, not the one who goes in with a cosh and a black bag.

With all that in mind, consider this example:

Kayo

One sentence: Former Nollywood actor and con artist shooting for the big leagues.

Investigative: Accounting 1, Bureaucracy 1, Bullshit Detector 3, Cryptography 1, Data Recovery 2, Electronic Surveillance 2, Human Terrain 2, High Society 1, Research 1, Traffic Analysis 1, Reassurance 2, Languages 2, Streetwise 1, Urban Survival 1

General: Athletics 8, Cover 10, Digital Intrusion 15, Disguise 6, Health 8, Infiltration 10, Mechanics 4, Network 15, Shooting 8 (base 14, with special weapons training), Stability 7, Surveillance 5, Sense Trouble 1.

MOS: Digital Intrusion (silly not to, really).

Cherries: Athletics (Parkour), Digital Intrusion (cracker's cryptid), Infiltration (open sesame), with special weapons training in the AK47. I picture this as an actor's conceit, for when Kayo decides to relive his glory days in Mafia Soldiers or the like.

As has become traditional, let's end this with a scenario seed:

A not for profit has announced a competition, the Shreddathon Challenge, to see who can be the first to piece together five sets of shredded documents, with $50,000 going to the winner. One team, the Hatfall Brigade, was coming very close to this goal with its specially designed computer program, but just as the final pieces were coming together three of the five programmers were brutally murdered, and the program was stolen. Shortly afterward the hacking community discovers that the not for profit hosting the challenge only ever existed in cyberspace; its backers have disappeared. What happened to the team, and what was the Shreddathon Challenge really all about?