Back to advisories
CriticalAdvisory
2 min read

Resurgence of HK-FIN-10 Targeting Internet Banking APIs

The local threat group HK-FIN-10 has resumed operations, carrying out unauthorized multi-account fund transfers totaling up to ₦1.84 billion in recent instances.

Critical Severity

This vulnerability requires immediate attention. Affected systems should be patched or mitigated as soon as possible.

Security Advisory: Resurgence of HK-FIN-10 Targeting Internet Banking APIs

The local threat group HK-FIN-10 has resumed operations, carrying out unauthorized multi-account fund transfers totaling up to ₦1.84 billion in recent instances. This campaign targets internet banking APIs between midnight and early morning, mirroring earlier 2025 attacks by abusing transaction narration indicators such as TFR RESERVE and SWEEPMAINTENANCE.

Threat Overview

  • Actor: HK-FIN-10
  • Target Sector: Nigerian financial institutions with internet banking channels
  • Attack Timing: Midnight and early morning hours
  • Recent Impact: Large-scale unauthorized transfers ranging from ₦500 million to ₦1.34 billion, routed into multi-bank mule accounts
  • Modus Operandi: API enumeration to locate funded accounts, followed by automated mass transfers exceeding 150 transactions per surge

Indicators of Compromise (IOCs) and Signatures

Transaction Narrations

  • TFR RESERVE, SWEEPMAINTENANCE PAYOUT

Targeted Vectors

  • Internet banking web applications, Customer-facing portal APIs and Backend integration gateways

Mule Network Behavior

  • Use of genuine bank accounts across multiple financial institutions and Reliance on peer networks to distribute funds quickly

Recommended Mitigations

API Security and Rate Limiting

  • Enforce strict rate limiting on API endpoints powering internet banking channels.
  • Deploy anomaly detection to monitor for high-frequency balance-checking requests.

Transaction Monitoring

  • Implement automated alerts for bulk midnight transactions matching narration strings such as:
    • TFR RESERVE PAYOUT SWEEPMAINTENANCE

Account Verification

  • Require step-up multi-factor authentication (MFA) for high-value or batch transfers executed outside standard business hours.

Law Enforcement Collaboration

  • Immediately flag and freeze suspicious receiving accounts across multi-bank networks.
  • Share relevant telemetry with cybercrime response authorities.

Key Takeaway

This campaign shows that API abuse and weak transaction controls can enable large-scale financial theft in a short period. Financial institutions should prioritise API hardening, behavioral monitoring, and rapid interbank coordination to reduce exposure and contain suspicious transfers quickly.

Reference