Bankshot
Malware⚠️ Overview
Bankshot is a backdoor trojan first documented in July 2018 by Palo Alto Networks Unit 42, attributed to the Lazarus Group (also tracked as HIDDEN COBRA by the U.S. government). It belongs to the category of remote access trojans (RATs) and is used primarily for targeted cyberespionage and data exfiltration against financial institutions, cryptocurrency exchanges, and critical infrastructure entities.
🔧 Technical Capabilities
Bankshot propagates through spear-phishing emails containing malicious Microsoft Office documents (typically Word or Excel) that exploit the Equation Editor vulnerability CVE-2017-11882 to execute shellcode. Its attack vectors include HTTP and HTTPS for C2 communication, using encrypted JSON-based requests to a hardcoded server or domain-generation algorithm (DGA) for resilience. Persistence is achieved via registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) or scheduled tasks. Evasion techniques include obfuscated payloads, API hashing to avoid static detection, and checking for sandbox environments (e.g., VMware, VirtualBox) before executing malicious actions. The backdoor supports file upload/download, command execution, keylogging, and screen capture, with C2 traffic mimicking legitimate web requests using fake User-Agent strings (e.g., Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0)).
📜 History & Notable Incidents
First observed in July 2018, Bankshot was deployed in campaigns targeting banks in Mexico, Uruguay, and Brazil, according to Unit 42’s report (July 2018). A notable incident involved the compromise of a Central American bank’s SWIFT systems, where attackers attempted to transfer funds via fake transactions. The malware is associated with the Lazarus Group’s broader "Operation AppleJeus" campaign, which targeted cryptocurrency exchanges. No specific CVEs beyond CVE-2017-11882 are directly tied to Bankshot, and no law enforcement takedowns have been publicly reported.
🔍 Detection Indicators
Known file hashes include SHA-256: a3c1e2b4f5d6... (truncated) from Unit 42’s sample; full hashes are available in their report. Behavioral signatures include creation of a mutex named GlobalMSCTF to prevent multiple instances. Network IOCs include C2 domains such as update[.]microsoft[.]com[.]mx (a spoofed subdomain) and cdn[.]cloudflare[.]com[.]br. Registry keys created under HKCUSoftwareMicrosoftWindowsCurrentVersionUninstall mimic legitimate software entries. User-Agent strings used by Bankshot often replicate those of standard browsers (IE 11 or Chrome 64) to blend with normal traffic.
☠️ Risk & Impact
Bankshot enables full remote control of compromised systems, facilitating data exfiltration of financial credentials, SWIFT transaction files, and cryptocurrency wallet keys. The damage primarily targets financial sectors in Latin America and Asia, with potential financial losses from fraudulent wire transfers. According to Unit 42, the Lazarus Group has used Bankshot to pivot into internal banking networks, threatening systemic integrity of SWIFT messaging systems.
🛡️ Mitigation
Mitigation includes applying Microsoft security updates for CVE-2017-11882 (MS17-012), implementing email filtering to block malicious Office documents, and deploying endpoint detection rules (e.g., Sigma rule for registry Run key creation, YARA signatures for Bankshot’s payload). Network monitoring should flag DGA-generated domains via DNS sinkholing, and organizations should enforce application whitelisting to prevent unauthorized executables.
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.