Revolut Hackers Used Infostealers for Elaborate Social Engineering

BREAKING: The investigations team at Duel has established contact with the hacker behind the recent Revolut incident, revealing alarming new details about the methods used to compromise the financial institution.

The Anatomy of the Attack

According to the information gathered, the attack was a sophisticated blend of technical compromise and social engineering:

  • Initial Access via Infostealers: The hacker gained access to government employee accounts using an infostealer. After gaining entry to an employee’s email, they would log in, add a recovery email under their control, begin logging activities, and silently monitor communications.
  • Evading Detection: To avoid raising suspicion, the hacker instantly deleted any outgoing emails they sent that were not intended for the original employee. They monitored the inbox 24/7 for responses. Upon receiving a reply to their fraudulent emails, they would immediately download it as a .eml file and delete it before the actual account owner noticed.
  • Targeting the Right Entity: The hacker admitted that while they initially tried forging court orders (a tactic presumably used against other companies), they quickly realized this wouldn’t succeed with Revolut. After conducting research, they determined the optimal target was Revolut’s Lithuania-based subsidiary, Revolut Bank UAB, which is obligated to respond to a European Investigation Order.
Tweet from Korra detailing the Duel investigation findings

Details of the investigation shared by the Duel team outlining the hacker’s methodology.

  • The Initial Breach: Using a compromised email account, the hacker sent a single, fraudulent request approximately five months ago. Revolut, believing the communication originated from the Italian government, complied with the fabricated order.
  • Sustained Control: From the compromised inbox, the hacker managed and terminated email threads that appeared to genuinely originate from multiple Italian government addresses.
  • A Five-Month Campaign: The hacker continuously sent requests over a five-month period. Astonishingly, Revolut reportedly never questioned the requests or withheld information. In one instance, when the hacker accidentally sent an incorrect document, Revolut’s support team allegedly guided them on how to correct it rather than detecting the fraud.
Email correspondence showing a pec.interno.it address communicating with Revolut

Correspondence demonstrating the hacker utilizing an Italian government email address to communicate with Revolut’s legal department.

“We remain in contact with the hacker and we’ve requested exclusivity of information related to the story to be kept with Duel. We believe it is in the public’s best interest for EVERY piece of information related to this to be released, so that the extent of Revolut’s failure can be brought to light, as well as the sheer stupidity of the manner in which the KYC paradigm is currently conducted.”

“The Duel team hopes that Revolut will be held accountable for their lack of due diligence and betraying their customers in such a severe manner, especially given the breadth and depth of the breach. Lives are now at risk. I’m personal friends with one of the victims, and he’ll probably have to move houses due to the continued (credible) kidnap threats.”

– The Duel Investigations Team

Hudson Rock’s Analysis & Intelligence

New Insight from Hudson Rock

While the Revolut hackers claimed they used Infostealers (initially telling researchers they used a ‘RAT’) to actively infect Italian government employees, Hudson Rock’s intelligence suggests a different scenario.

Images from the campaign clearly show correspondence with Revolut was conducted using ‘pec.interno.it’ email addresses, which belong to the Italian Ministry of the Interior.

By checking Hudson Rock’s extensive cybercrime database, we identified approximately 300 compromised pec.interno.it webmail logins stemming from already infected machines. Based on this intelligence, we assess that it is highly unlikely the hacker actively infected these specific employees themselves. Instead, they likely purchased or utilized existing Infostealer logs containing these credentials, attempting to obfuscate their true method of initial access.

Hudson Rock database showing compromised credentials for interno.it

Hudson Rock’s Cybercrime Intelligence database revealing numerous compromised credentials for the ‘interno.it’ domain, providing an easy avenue for the attackers.

Protect Your Organization

To learn more about how Hudson Rock protects companies from imminent intrusions caused by info-stealer infections of employees, partners, and users, as well as how we enrich existing cybersecurity solutions with our cybercrime intelligence API, please schedule a call with us here:

https://www.hudsonrock.com/schedule-demo

We also provide access to various free cybercrime intelligence tools that you can find here:

www.hudsonrock.com/free-tools

Thanks for reading, Rock Hudson Rock!

Follow us on LinkedIn: https://www.linkedin.com/company/hudson-rock
Follow us on Twitter: https://www.twitter.com/RockHudsonRock

The post Revolut Hackers Used Infostealers for Elaborate Social Engineering appeared first on InfoStealers.