Polish Banks Infected with Malware Hosted on Their Own Government’s Site
Zaufana Trzecia Strona, a local Polish news site, first reported the attacks late Friday, last week. The news site said that during the past week, the security teams at several, yet unnamed, Polish banks detected downloads of suspicious files and encrypted traffic going to uncommon IPs situated in many foreign countries.
As employees at different banks started looking into their systems, they found malware installed on numerous workstations and even some servers.
Subsequent investigations and a cooperation between different banks eventually discovered the source of the infection as being the official website of KNF, which, ironically, is the regulating body that keeps an eye out for the security of financial systems in Poland.
KNF website (via Zaufana Trzecia Strona)