ATT&CKReferencesMcAfee Bankshot

McAfee Bankshot

Sherstobitoff, R. (2018, March 08). Hidden Cobra Targets Turkish Financial Sector With New Bankshot Implant. Retrieved May 18, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples20

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareBankshot

Bankshot collects files from the local system.

T1041
Exfiltration Over C2 Channel
MalwareBankshot

Bankshot exfiltrates data over its C2 channel.

T1057
Process Discovery
MalwareBankshot

Bankshot identifies processes and collects the process ids.

T1059.003
Windows Command Shell
MalwareBankshot

Bankshot uses the command-line interface to execute arbitrary commands.

T1070.004
File Deletion
MalwareBankshot

Bankshot marks files to be deleted upon the next system reboot and uninstalls and removes itself from the system.

T1070.006
Timestomp
MalwareBankshot

Bankshot modifies the time of a file as specified by the control server.

T1071.001
Web Protocols
MalwareBankshot

Bankshot uses HTTP for command and control communication.

T1082
System Information Discovery
MalwareBankshot

Bankshot gathers system information, network addresses, and the operation system version.

T1087.001
Local Account
MalwareBankshot

Bankshot gathers domain and account names/information through process monitoring.

T1087.002
Domain Account
MalwareBankshot

Bankshot gathers domain and account names/information through process monitoring.

T1106
Native API
MalwareBankshot

Bankshot creates processes using the Windows API calls: CreateProcessA() and CreateProcessAsUserA().

T1119
Automated Collection
MalwareBankshot

Bankshot recursively generates a list of files within a directory and sends them back to the control server.

T1132.002
Non-Standard Encoding
MalwareBankshot

Bankshot encodes commands from the control server using a range of characters and gzip.

T1134.002
Create Process with Token
MalwareBankshot

Bankshot grabs a user token using WTSQueryUserToken and then creates a process by impersonating a logged-on user.

T1203
Exploitation for Client Execution
GroupLazarus Group

Lazarus Group has exploited Adobe Flash vulnerability CVE-2018-4878 for execution.

T1203
Exploitation for Client Execution
MalwareBankshot

Bankshot leverages a known zero-day vulnerability in Adobe Flash to execute the implant into the victims’ machines.

T1204.002
Malicious File
GroupLazarus Group

Lazarus Group has attempted to get users to launch a malicious Microsoft Word attachment delivered via a spearphishing email.

T1543.003
Windows Service
MalwareBankshot

Bankshot can terminate a specific process by its process id.

T1566.001
Spearphishing Attachment
GroupLazarus Group

Lazarus Group has targeted victims with spearphishing emails containing malicious Microsoft Word documents.

T1680
Local Storage Discovery
MalwareBankshot

Bankshot gathers disk type and disk free space.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.