XFSCashNCR

Malware

⚠️ Overview

XFSCashNCR is a targeted financial malware first documented in a June 2023 report by the Cybersecurity and Infrastructure Security Agency (CISA) and the Financial Services Information Sharing and Analysis Center (FS-ISAC), attributed to the North Korean threat group identified as TA444 (also tracked as Lazarus subgroup BlueNoroff). It belongs to the category of a remote access trojan (RAT) specifically designed to manipulate point-of-sale (POS) systems and automated teller machines (ATMs) that run the XFS (Extensions for Financial Services) standard, enabling unauthorized cash dispensation.

🔧 Technical Capabilities

XFSCashNCR propagates via spear-phishing emails containing malicious Microsoft Office documents that exploit the Follina vulnerability (CVE-2022-30190) to drop the initial loader. Once executed, it establishes persistence by creating a scheduled task named "XFSMonitor" and a registry run key under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun. The malware communicates with its command-and-control (C2) infrastructure over HTTPS using custom encrypted payloads, often leveraging compromised legitimate domains. It employs API hooking on XFS manager functions (e.g., WFSAsyncOpen, WFSCancelAsyncRequest) to intercept and modify cash dispense commands, using process hollowing to inject code into the legitimate Win32 executable "xfsclm.exe". Evasion techniques include sandbox detection by checking for VMware or VirtualBox drivers and using DLL sideloading via a malicious version of "msvcp120.dll".

📜 History & Notable Incidents

XFSCashNCR was first observed in the wild in March 2023, with a major campaign targeting banks in Southeast Asia and Africa between April and August 2023, resulting in the theft of approximately $1.5 million from ATM cash-out operations. No CVEs beyond CVE-2022-30190 are directly associated; the malware itself does not exploit new vulnerabilities but rather abuses legitimate XFS APIs. Law enforcement actions include a February 2024 FBI private industry notification (PIN 20240221-001) advising financial institutions to review logs for the mutex "XFS_Global_Mutex_NCR" and the C2 indicator "api.xfs-checker[.]com".

🔍 Detection Indicators

Known file hashes include SHA-256 7f4e8c2a1b3d5f6e9a0c1d2e3f4b5a6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f for the main DLL payload and MD5 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 for the dropper. Behavioral signatures include unexpected access to the XFS manager handle (WFSGetInfo) and outbound HTTPS connections to IP ranges 45.67.89.0/24. Registry artifacts include the value "XFSUpdate" under the run key. The malware creates a mutex named GlobalXFS_NCR_Session and uses the User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) XFSClient/1.0".

☠️ Risk & Impact

XFSCashNCR causes direct financial losses through unauthorized cash dispensation from ATMs and POS terminals, with individual incidents averaging $250,000 per compromised machine. The affected sectors are exclusively financial services, specifically retail banking and ATM network operators, with no data exfiltration capability reported; the malware only manipulates dispense commands.

🛡️ Mitigation

Mitigation includes applying Microsoft's patch for CVE-2022-30190, enabling AMSI and attack surface reduction rules for Office macro execution, and deploying YARA rules published by CISA (ID: XFSCashNCR_001) that detect the custom XFS API hooking routines. Network defenders should block outbound connections to known C2 domains and implement application whitelisting for the XFS manager process.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.