Bankshot

S0239

Malware.View on attack.mitre.org

About this malware

Bankshot is a remote access tool (RAT) that was first reported by the Department of Homeland Security in December of 2017. In 2018, Lazarus Group used the Bankshot implant in attacks against the Turkish financial sector.

Techniques used25

Procedure examples25

TechniqueProcedure example
T1001.003
Protocol or Service Impersonation

Bankshot generates a false TLS handshake using a public certificate to disguise C2 network communications.

T1005
Data from Local System

Bankshot collects files from the local system.

T1012
Query Registry

Bankshot searches for certain Registry keys to be configured before executing the payload.

T1041
Exfiltration Over C2 Channel

Bankshot exfiltrates data over its C2 channel.

T1057
Process Discovery

Bankshot identifies processes and collects the process ids.

T1059.003
Windows Command Shell

Bankshot uses the command-line interface to execute arbitrary commands.

T1070
Indicator Removal

Bankshot deletes all artifacts associated with the malware from the infected machine.

T1070.004
File Deletion

Bankshot marks files to be deleted upon the next system reboot and uninstalls and removes itself from the system.

T1070.006
Timestomp

Bankshot modifies the time of a file as specified by the control server.

T1071.001
Web Protocols

Bankshot uses HTTP for command and control communication.

T1082
System Information Discovery

Bankshot gathers system information, network addresses, and the operation system version.

T1083
File and Directory Discovery

Bankshot searches for files on the victim's machine.

T1087.001
Local Account

Bankshot gathers domain and account names/information through process monitoring.

T1087.002
Domain Account

Bankshot gathers domain and account names/information through process monitoring.

T1105
Ingress Tool Transfer

Bankshot uploads files and secondary payloads to the victim's machine.

View all 25 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. McAfee Bankshot Open source
    Sherstobitoff, R. (2018, March 08). Hidden Cobra Targets Turkish Financial Sector With New Bankshot Implant. Retrieved May 18, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.