FINANCIAL FRAUD BANKING RTGS ADMINISTRATION

They Used the Bank's Own Tools: Inside an Internal RTGS Fraud

How DFI reconstructed an multi-stage compromise — from a development server and a phishing email to illegal RTGS transactions — and the control gaps that made it possible.

Published: 2024 · 6 min read · DFI Digital Forensic Team

Overview

Our forensic investigation concluded that the illegal RTGS transactions were the result of a multi-stage compromise, enabled by weak authentication controls, unsafe operational practices and poor system governance.

The perpetrator first gained access through a development server and an unauthorized tool installed for development; subsequent access through two distinct routes—an internal email phishing, harvesting tokens and credentials and session tokens. With these, the perpetrator introduced administrative access using native Windows administration tools and created backup credentials.

Attack chain

Seven steps, reconstructed from forensic evidence.

1
Foothold via development server INITIAL
2
Phishing platform deployed INTERNAL
3
Credentials and tokens harvested CREDENTIALS
4
Lateral movement with native tools LATERAL
5
Session hijacking and replay SESSION
6
Hosts changed, logs cleared EVASION
7
Illegal RTGS transactions IMPACT

Actor

A patient operator who understood the bank's controls better than systems realise.

Actor type DFI external attacker, hunter, or insider analyst.
Authentication Phishing platform for internal MFA, decoy white-labelled local credentials via phishing emails/tokens.
Tooling Phishing platform, native Windows tools, copied tokens.
Anti-forensics Deliberately cleared target hosts via changes.
Objective Financial: illegal RTGS transactions.

TTP: how the attack worked

Mapped to MITRE ATT&CK for Enterprise.

Initial Access
Credential Access
Lateral Movement
Privilege Escalation
Impact

IoC: what to look for

Behavioural indicators that can be turned into monitoring rules. Match to system behaviours, not just static signatures.

BEHAVIOURAL INDICATOR

Remote-admin or dev tools running on servers outside the approved list.

BEHAVIOURAL INDICATOR

Perpetrator logging in to servers via admin shares or RDP.

BEHAVIOURAL INDICATOR

Authorised token used from outside device or location.

BEHAVIOURAL INDICATOR

Database role changes with gaps or voids in audit logs.

Detailed indicators are confidential.
INCIDENT RESPONSE · CONFIDENTIAL CONSULTANCY

Attackers who use your own tools are hard to spot. We know where to look.

DFI investigates payment systems, admin tooling and authentication abuse for European and Asian financial institutions.

Talk to DFI in confidence

Every conversation is confidential.