Hidden Cobra Targets Turkish Financial Sector With New Bankshot Implant
2018-03-08 • Mcafee •
McAfee attributed a campaign against Turkish financial and government-linked finance organizations to Hidden Cobra based on Bankshot code similarity, victim sector, and control-server strings. Spear-phishing emails carried malicious Word documents with embedded Flash content exploiting CVE-2018-4878, which downloaded and executed Bankshot DLL implants from the lookalike domain falcancoin.io. The victims observed on March 2 and 3 included a major government-controlled financial organization, another Turkish government finance and trade organization, and three large Turkish financial institutions, with no other sectors or countries seen in telemetry. Bankshot acted as a backdoor for persistence and follow-on access, dynamically loading APIs, decrypting C2 strings, beaconing through HTTP POST fields such as board_id and user_id, and supporting commands for file listing, process control, system discovery, command execution, file read/write, deletion, and loading additional libraries. The activity matters because the implant closely matched earlier Bankshot variants associated with Hidden Cobra financial operations and could represent reconnaissance for a future financial heist.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d8af45210bf931bc5b03215ed30fb73… | 2018-03-07 | 2022-07-31 |
| DOMAIN | falcancoin.io | 2018-03-07 | 2018-06-22 |
| HASH | 234aa1635034630f48937729a1a3f89… | 2018-03-08 | 2018-03-08 |
| HASH | 6fee482cb9a05e860cb0894b1fbf153… | 2018-03-08 | 2018-03-08 |
| HASH | 3da19f7d6aa22d1be7f21830afb515a… | 2018-03-07 | 2018-03-08 |
| HASH | 62d28c7a4d17163a209e5f887cedeb4… | 2018-03-07 | 2018-03-08 |
| HASH | c68bfd97f5eff77d2cb44840a7ee3e1… | 2018-03-07 | 2018-03-08 |