Resurgence of HK-FIN-10 Targeting Internet Banking APIs
The local threat group HK-FIN-10 has resumed operations, carrying out unauthorized multi-account fund transfers totaling up to ₦1.84 billion in recent instances.
Critical Severity
This vulnerability requires immediate attention. Affected systems should be patched or mitigated as soon as possible.
Security Advisory: Resurgence of HK-FIN-10 Targeting Internet Banking APIs
The local threat group HK-FIN-10 has resumed operations, carrying out unauthorized multi-account fund transfers totaling up to ₦1.84 billion in recent instances. This campaign targets internet banking APIs between midnight and early morning, mirroring earlier 2025 attacks by abusing transaction narration indicators such as TFR RESERVE and SWEEPMAINTENANCE.
Threat Overview
- Actor: HK-FIN-10
- Target Sector: Nigerian financial institutions with internet banking channels
- Attack Timing: Midnight and early morning hours
- Recent Impact: Large-scale unauthorized transfers ranging from ₦500 million to ₦1.34 billion, routed into multi-bank mule accounts
- Modus Operandi: API enumeration to locate funded accounts, followed by automated mass transfers exceeding 150 transactions per surge
Indicators of Compromise (IOCs) and Signatures
Transaction Narrations
TFR RESERVE,SWEEPMAINTENANCEPAYOUT
Targeted Vectors
- Internet banking web applications, Customer-facing portal APIs and Backend integration gateways
Mule Network Behavior
- Use of genuine bank accounts across multiple financial institutions and Reliance on peer networks to distribute funds quickly
Recommended Mitigations
API Security and Rate Limiting
- Enforce strict rate limiting on API endpoints powering internet banking channels.
- Deploy anomaly detection to monitor for high-frequency balance-checking requests.
Transaction Monitoring
- Implement automated alerts for bulk midnight transactions matching narration strings such as:
TFR RESERVEPAYOUTSWEEPMAINTENANCE
Account Verification
- Require step-up multi-factor authentication (MFA) for high-value or batch transfers executed outside standard business hours.
Law Enforcement Collaboration
- Immediately flag and freeze suspicious receiving accounts across multi-bank networks.
- Share relevant telemetry with cybercrime response authorities.
Key Takeaway
This campaign shows that API abuse and weak transaction controls can enable large-scale financial theft in a short period. Financial institutions should prioritise API hardening, behavioral monitoring, and rapid interbank coordination to reduce exposure and contain suspicious transfers quickly.