In what is one of Zimbabwe’s largest reported financial cyber heists, a 24 year old Midlands State University student was brought before the courts for hacking and stealing US $1,136,179 from a local bank, CABS.
According a report by Herald, the student, Sabelo Malunga, did attachment at CABS, and apparently exploited the access gained during his time there to install SUPREMO, a remote access software that then enabled his access after he had left. He apparently downloaded SUPREMO onto a CABS machine in January this year while still on attachment.
After his attachment ended (on 23 February), he could access the CABS systems and he used that access to plant malware tools that would create fraudulent Visa and ZIPIT transactions.
The Visa transactions were international ATM transactions linked to CABS-issued debit cards for $210,500 and they were discovered on 27 March. The transactions were flagged by Visa but the money had already been lost.
The bank’s IT team discovered the malware on 13 April and an internal reconciliation uncovered the ZIPIT transactions, some 1,911 of them, used to transfer US $925,679 to EcoCash, InnBucks, CBZ and Ecobank. This amount was also not recovered.
From the dates, it looks like the student had access for an estimated 4+ weeks.
There’s no mention about whether the transactions would siphon money from other bank customer accounts or a different pool of money within the bank’s system. There’s also no mention of how CABS’s endpoint cyber-security tools did not catch this remote access earlier.
According to the report, CABS used the services of a South African digital forensics company to “contain and eradicate the malware and investigate the breach.”
The student has not yet been asked to plead and was remanded in custody until Thursday. This means all these are just allegations for now.
The remote access software used in the attack, SUPREMO, is a legitimate tool similar to TeamViewer, AnyDesk, or Chrome Remote Desktop. However, while SUPREMO has built-in security measures and encryption, it has been exploited by hackers and scammers for unauthorized access to victims’ computers. The feature usually used is a feature where it can configured to start at system boot, allowing unattended remote access.
The post MSU Student Accused in US$1.1 Million CABS Cybertheft appeared first on Techzim.