---
title: The $81 Million Heist from a Hypervisor Introspection Perspective
description: October 2016 is security awareness month, not that anyone really need to raise awareness on this; last week's distributed denial of service (DDoS) attacks on DYN left numerous global enterprises’ websites unreachable, resulting in customer impact and lost business revenue.
image: https://businessinsights.bitdefender.com/hubfs/the-81-million-heist-from-a-hypervisor-introspection-perspective-2.jpg
---

[![](https://businessinsights.bitdefender.com/hubfs/2021/09/logo-white.svg)](https://businessinsights.bitdefender.com/?hsLang=en-us)

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

- [For Home](https://www.bitdefender.com/solutions/)
- [For Business](https://www.bitdefender.com/business/)
- [Resources](https://www.bitdefender.com/business/resource-library.html)
- [Webinars](https://www.bitdefender.com/business/webinars.html)

# [BUSINESS INSIGHTS](https://businessinsights.bitdefender.com/?hsLang=en-us)

[#Enterprise Security](https://businessinsights.bitdefender.com/topic/enterprise-security) [#Virtualization & Data Center Security](https://businessinsights.bitdefender.com/topic/virtualization-data-center-security)

 By [**Liviu Arsene**](https://businessinsights.bitdefender.com/author/liviu-arsene) / Oct 27, 2016

# The $81 Million Heist from a Hypervisor Introspection Perspective

Share this [![Share on email](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/email-color.png)](mailto:?subject=Check%20out%20https://businessinsights.bitdefender.com/the-81-million-heist-from-a-hypervisor-introspection-perspective&utm_medium=social&utm_source=email%20&body=Check%20out%20https://businessinsights.bitdefender.com/the-81-million-heist-from-a-hypervisor-introspection-perspective&utm_medium=social&utm_source=email) [![Share on twitter](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://businessinsights.bitdefender.com/the-81-million-heist-from-a-hypervisor-introspection-perspective&utm_medium=social&utm_source=twitter&url=https://businessinsights.bitdefender.com/the-81-million-heist-from-a-hypervisor-introspection-perspective&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on linkedin](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://businessinsights.bitdefender.com/the-81-million-heist-from-a-hypervisor-introspection-perspective&utm_medium=social&utm_source=linkedin) [![Share on facebook](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/facebook-color.png)](http://www.facebook.com/share.php?u=https://businessinsights.bitdefender.com/the-81-million-heist-from-a-hypervisor-introspection-perspective&utm_medium=social&utm_source=facebook)

*Note: This article was developed in collaboration with Marc Trouard-Riolle, Principal Product Marketing Manager, Citrix Systems Inc.*

 

October 2016 is security awareness month, not that anyone really need to raise awareness on this; last week's distributed denial of service (DDoS) attacks on DYN left numerous global enterprises’ websites unreachable, resulting in customer impact and lost business revenue.

The [Security Affairs website recently reported](http://securityaffairs.co/wordpress/50680/cyber-crime/global-cost-of-cybercrime.html) the global annual cybercrime costs to businesses in 2015 as being roughly $3 trillion, with 2021 projections reaching $6 trillion. As cybercriminals produced an average of 230,000 new malware samples per day during 2015, with twelve people online becoming victims of cybercrime every second of the day, global spending is expected exceed $1 trillion over the next five years.

Businesses are finally starting to wake-up to the fact that the damage being caused by cybercriminals, far exceeds the amount they are currently willing to spend on security for our data assets, with losses not just from sales revenue, as advanced persisted threats (APTs) are often about valuable corporate (and customer) data exfiltration.

One recent APT [on a Bangladesh bank](http://www.reuters.com/article/us-usa-nyfed-bangladesh-malware-exclusiv-idUSKCN0XM0DR) exploited vulnerabilities in the SWIFT financial platform, managing to issue a transfer of $951 million. In this instance, $81 million was actually transferred successfully internationally, and what it proves is that cybercriminals are willing to spend time and effort developing targeted malware enabling attacks on financially-profitable data from individual organizations. Adrian Nish, BAE’s head of threat intelligence stated "he had never seen such an elaborate scheme from criminal hackers”.

So how did these cybercriminals carry out such an elaborate attack?

It seems that even months following the attack, technical details are still scarce, however, [BAE Systems's published findings](http://baesystemsai.blogspot.com/2016/04/two-bytes-to-951m.html) identifying tools believed to have been used in the heist, containing “sophisticated functionality for interacting with local SWIFT Alliance Access software running in the victim infrastructure”. This included tools to cover the thieves tracks, and delay any attack identification and response, allowing greater time to complete the heist.

Essentially, the malware was able to patch a specific “liboradb.dll” library module, resulting in the host application to believe a failed security check had in fact succeeded, and enabling the malware the privileges to grant itself the ability to execute database transactions on the victim network. Further details on this, including how the malware also attempted to protect itself with printer manipulation can be found at the link above.

Bitdefender has developed in collaboration with Citrix a technology that can help prevent attacks such as the $81 million theft.

Bitdefender HVI (Hypervisor Introspection) is a revolutionary technology that scans raw memory at the hypervisor level, without any in-guest (VM) agents, leveraging a recent XenServer API. Zero-day protection through memory introspection comes from outside of the VM, enabling the solution to even detect sophisticated unknown threats, such as APTs, intercepting and blocking them from tampering with the memory stack, injecting remediation tools if necessary.

Citrix XenServer 7, [released in May 2017](https://www.citrix.com/blogs/?p=174222166) includes a new security feature unique to the server and desktop virtualization market, called Direct Inspect APIs, which enables Bitdefender HVI to leverage memory introspection techniques from a hypervisor-layer security appliance.

It should be highlighted that Bitdefender’s integration is squarely focused at malicious memory activity and is complementary to traditional disk/file based endpoint solutions. 

It’s difficult to know whether the solution would have completely prevented the theft of $81 million, however it would have certainly detected the attempt to patch the “liboradb.dll” file, involving a write process to an area of memory that should be read-only. This patch was critical to the heist, and in preventing its execution would have stopped that portion of the APT and the hackers gaining access to SWIFT’s Alliance software. 

As global security threats and their perpetrators become more sophisticated, organizations must continue to evolve their business security postures using more in-depth approaches. XenServer Direct Inspect APIs together with Bitdefender offers one such approach.

Bitdefender HVI is currently in technical preview, for more information on how it works and how you can test it, check out the official webpage [here](http://www.bitdefender.com/business/hypervisor-introspection.html).

[![Bitdefender Hypervisor Introspection](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/026fb307-0223-46eb-81e8-59be446e892a.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/026fb307-0223-46eb-81e8-59be446e892a)

### Explore More Topics

- [Enterprise Security (743)](https://businessinsights.bitdefender.com/topic/enterprise-security)
- [Threat Research (201)](https://businessinsights.bitdefender.com/topic/threat-research)
- [Cloud Security (174)](https://businessinsights.bitdefender.com/topic/cloud-security)
- [SMB Security (170)](https://businessinsights.bitdefender.com/topic/smb-security)
- [Ransomware (166)](https://businessinsights.bitdefender.com/topic/ransomware)
- [Privacy and Data Protection (137)](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)
- [Cybersecurity Awareness (134)](https://businessinsights.bitdefender.com/topic/cybersecurity-awareness)
- [Endpoint Protection & Management (126)](https://businessinsights.bitdefender.com/topic/endpoint-protection-management)
- [Endpoint Detection and Response (124)](https://businessinsights.bitdefender.com/topic/endpoint-detection-and-response)
- [Managed Detection and Response (119)](https://businessinsights.bitdefender.com/topic/managed-detection-and-response)
- [Virtualization & Data Center Security (82)](https://businessinsights.bitdefender.com/topic/virtualization-data-center-security)
- [Threat Intelligence (76)](https://businessinsights.bitdefender.com/topic/threat-intelligence)
- [IT Compliance & Regulations (71)](https://businessinsights.bitdefender.com/topic/it-compliance-regulations)
- [Bitdefender Threat Debrief (55)](https://businessinsights.bitdefender.com/topic/bitdefender-threat-debrief)
- [Managed Service Providers (53)](https://businessinsights.bitdefender.com/topic/managed-service-providers)
- [#Featured (52)](https://businessinsights.bitdefender.com/topic/featured)
- [Advanced Persistent Threats (46)](https://businessinsights.bitdefender.com/topic/advanced-persistent-threats)
- [Events (38)](https://businessinsights.bitdefender.com/topic/events)
- [Independent Testing (18)](https://businessinsights.bitdefender.com/topic/independent-testing)
- [Cybersecurity Advisory Services (9)](https://businessinsights.bitdefender.com/topic/cybersecurity-advisory-services)
- [Podcast (3)](https://businessinsights.bitdefender.com/topic/podcast)
- [top (2)](https://businessinsights.bitdefender.com/topic/top)

See all topics

### Subscribe to Blog Updates

## Read more about this topic

<https://businessinsights.bitdefender.com/lax-employee-cybersecurity-habits-pose-growing-danger-to-businesses?hsLang=en-us>

### [Lax Employee Cybersecurity Habits Pose Growing Danger to Businesses](https://businessinsights.bitdefender.com/lax-employee-cybersecurity-habits-pose-growing-danger-to-businesses?hsLang=en-us)

<https://businessinsights.bitdefender.com/how-to-be-a-cybersecurity-leader-for-the-whole-organization?hsLang=en-us>

### [How to Be a Cybersecurity Leader for the Whole Organization](https://businessinsights.bitdefender.com/how-to-be-a-cybersecurity-leader-for-the-whole-organization?hsLang=en-us)

<https://businessinsights.bitdefender.com/ciso-improving-security?hsLang=en-us>

### [Five ways your CISO has saved your cyber](https://businessinsights.bitdefender.com/ciso-improving-security?hsLang=en-us)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2685110570-png/Bitdefender-Mar2015-Theme/Images/avatar_img_footer.png)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2676149282-png/Bitdefender-Mar2015-Theme/Images/logo_white_footer.png)

- [![https://twitter.com/Bitdefender_Ent](https://businessinsights.bitdefender.com/hs-fs/file-2658233851-png/Bitdefender-Mar2015-Theme/Images/ft_soc_tw.png?width=33&name=ft_soc_tw.png)](https://twitter.com/Bitdefender_Ent)
- [![Linkedin-icon-300x300](https://businessinsights.bitdefender.com/hs-fs/hubfs/Bitdefender-Mar2015-Theme/Images/Linkedin-icon-300x300.png?width=33&name=Linkedin-icon-300x300.png)](https://www.linkedin.com/company/bitdefender-gravityzone-enterprise-security)
- [![](https://businessinsights.bitdefender.com/hs-fs/file-2676149307-png/Bitdefender-Mar2015-Theme/Images/ft_soc_yt.png)](https://www.youtube.com/user/BitdefenderSecurity)

- [Legal Terms](https://www.bitdefender.com/legal/)
- [Privacy Policy](https://www.bitdefender.com/site/view/legal-privacy-policy-for-bitdefender-websites.html)
- [EULA](https://www.bitdefender.com/site/view/legal-eula.html)
- [Contact Us](https://www.bitdefender.com/business/contact.html)

Copyright © 1997-2023 Bitdefender All rights reserved.

![](https://px.spiceworks.com/px/5rec)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Liviu Arsene",
    "url" : "https://businessinsights.bitdefender.com/author/liviu-arsene"
  },
  "datePublished" : "2016-10-27T17:00:00.000Z",
  "headline" : "The $81 Million Heist from a Hypervisor Introspection Perspective",
  "image" : [ "https://businessinsights.bitdefender.com/hubfs/the-81-million-heist-from-a-hypervisor-introspection-perspective-2.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://businessinsights.bitdefender.com/the-81-million-heist-from-a-hypervisor-introspection-perspective",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://businessinsights.bitdefender.com/hubfs/Bitdefender_Logo_Transparent-2.png"
    },
    "name" : "Bitdefender"
  }
}
```