Overview
Our forensic investigation concluded that the illegal RTGS transactions were the result of a multi-stage compromise, enabled by weak authentication controls, unsafe operational practices and poor system governance.
The perpetrator first gained access through a development server and an unauthorized tool installed for development; subsequent access through two distinct routes—an internal email phishing, harvesting tokens and credentials and session tokens. With these, the perpetrator introduced administrative access using native Windows administration tools and created backup credentials.
Attack chain
Seven steps, reconstructed from forensic evidence.
Actor
A patient operator who understood the bank's controls better than systems realise.
TTP: how the attack worked
Mapped to MITRE ATT&CK for Enterprise.
IoC: what to look for
Behavioural indicators that can be turned into monitoring rules. Match to system behaviours, not just static signatures.
Remote-admin or dev tools running on servers outside the approved list.
Perpetrator logging in to servers via admin shares or RDP.
Authorised token used from outside device or location.
Database role changes with gaps or voids in audit logs.