FASTCash is the name used by U.S. authorities for a series of financially motivated ATM cash-out operations attributed to North Korean state-linked cyber actors. The activity is associated with the Democratic People’s Republic of Korea’s broader use of offensive cyber operations to generate revenue in support of regime objectives and sanctions evasion. FASTCash is part of a wider DPRK portfolio of illicit financial operations that has also included bank fraud, cryptocurrency theft, and other revenue-generating intrusions. The FASTCash operations involved compromises of payment-switching and banking infrastructure to enable fraudulent ATM withdrawals at scale across multiple countries. These campaigns were designed to manipulate transaction authorization processes so cash could be withdrawn rapidly and globally, yielding tens of millions of dollars. The operations demonstrate North Korean capability in financially motivated intrusion sets focused on banking and payment systems rather than conventional espionage alone. As a DPRK-linked activity cluster, FASTCash aligns with North Korea’s long-observed shift toward cyber-enabled theft as a state revenue mechanism. The actor’s behavior is consistent with initial access into financial networks, post-compromise manipulation of transaction systems, defense evasion, and exfiltration of value through fraudulent cash-outs. Public reporting in the supplied facts supports attribution to North Korean actors at the country level, but does not provide high-confidence detail on specific sub-groups or alternative aliases beyond FASTCash itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.