Hidden Cobra Targets Turkish Financial Sector With New Bankshot Implant
2018-03-08 • Mcafee •
McAfee attributed a campaign against Turkish financial and government-linked finance organizations to Hidden Cobra based on Bankshot code similarity, victim sector, and control-server strings. Spear-phishing emails carried malicious Word documents with embedded Flash content exploiting CVE-2018-4878, which downloaded and executed Bankshot DLL implants from the lookalike domain falcancoin.io. The victims observed on March 2 and 3 included a major government-controlled financial organization, another Turkish government finance and trade organization, and three large Turkish financial institutions, with no other sectors or countries seen in telemetry. Bankshot acted as a backdoor for persistence and follow-on access, dynamically loading APIs, decrypting C2 strings, beaconing through HTTP POST fields such as board_id and user_id, and supporting commands for file listing, process control, system discovery, command execution, file read/write, deletion, and loading additional libraries. The activity matters because the implant closely matched earlier Bankshot variants associated with Hidden Cobra financial operations and could represent reconnaissance for a future financial heist.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | falcancoin.io | 2018-03-07 | 2018-06-22 |
| HASH | a2e966edee45b30bb6bb5c978e55833… | 2018-03-08 | 2018-03-08 |
| HASH | 843c17b06a3aee22447f02130790989… | 2018-03-08 | 2018-03-08 |
| HASH | 65e7d2338735ec04fd9692d020298e5… | 2018-03-08 | 2018-03-08 |
| HASH | 166e8c643a4db0df6ffd6e3ab536b3d… | 2018-03-08 | 2018-03-08 |
| HASH | 343ebca579bb888eb8ccb811f9b5228… | 2018-03-08 | 2018-03-08 |
| HASH | 650b7d25f4ed87490f8467eb48e0443… | 2018-03-08 | 2018-03-08 |