Hidden Cobra Targets Turkish Financial Sector With New Bankshot Implant

2018-03-08 Mcafee

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/hidden-cobra-targets-turkish-financial-sector-new-bankshot-implant/

McAfee attributed a campaign against Turkish financial and government-linked finance organizations to Hidden Cobra based on Bankshot code similarity, victim sector, and control-server strings. Spear-phishing emails carried malicious Word documents with embedded Flash content exploiting CVE-2018-4878, which downloaded and executed Bankshot DLL implants from the lookalike domain falcancoin.io. The victims observed on March 2 and 3 included a major government-controlled financial organization, another Turkish government finance and trade organization, and three large Turkish financial institutions, with no other sectors or countries seen in telemetry. Bankshot acted as a backdoor for persistence and follow-on access, dynamically loading APIs, decrypting C2 strings, beaconing through HTTP POST fields such as board_id and user_id, and supporting commands for file listing, process control, system discovery, command execution, file read/write, deletion, and loading additional libraries. The activity matters because the implant closely matched earlier Bankshot variants associated with Hidden Cobra financial operations and could represent reconnaissance for a future financial heist.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN falcancoin.io 2018-03-07 2018-06-22
HASH a2e966edee45b30bb6bb5c978e55833… 2018-03-08 2018-03-08
HASH 843c17b06a3aee22447f02130790989… 2018-03-08 2018-03-08
HASH 65e7d2338735ec04fd9692d020298e5… 2018-03-08 2018-03-08
HASH 166e8c643a4db0df6ffd6e3ab536b3d… 2018-03-08 2018-03-08
HASH 343ebca579bb888eb8ccb811f9b5228… 2018-03-08 2018-03-08
HASH 650b7d25f4ed87490f8467eb48e0443… 2018-03-08 2018-03-08

Related Actors

Related Reports

« Back