Bankshot
MITRE ATT&CK: S0239 View on attack.mitre.org
Aliases: Trojan Manuscript, COPPERHEDGE, FoggyBrass, Bankshot
- First seen
- 2017-12-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:37:47
Targeted industries: financial-services
Targeted regions: country_code:tr
Context
Bankshot is a remote access tool (RAT) that was first reported by the Department of Homeland Security in December of 2017. In 2018, Lazarus Group used the Bankshot implant in attacks against the Turkish financial sector.
Detection coverage
- 457 Sigma rules
Malware & tools used
- Web Protocols (attack-pattern)
- Data from Local System (attack-pattern)
- File Deletion (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Timestomp (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Process Discovery (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- System Information Discovery (attack-pattern)
- Windows Service (attack-pattern)
- Native API (attack-pattern)
- Query Registry (attack-pattern)
- Non-Standard Encoding (attack-pattern)
- Automated Collection (attack-pattern)
- Protocol or Service Impersonation (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Local Account (attack-pattern)
- Domain Account (attack-pattern)
- Modify Registry (attack-pattern)
- Create Process with Token (attack-pattern)
- Windows Command Shell (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Local Storage Discovery (attack-pattern)
- Indicator Removal (attack-pattern)
- Non-Standard Port (attack-pattern)
Used by threat actors
- Lazarus Group (threat-actor)
Reports & references
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- secureworks.com — Nickel Gladstone (report)
- Kaspersky — 110355 (report)
- CISA — Aa22 108A (report)
- CISA — Aa22 108A Tradertraitor North Korea Apt Targets Blockchain Companies (report)
- blog.lexfo.fr — Lexfo Whitepaper The Lazarus Constellation (report)
- vblocalhost.com — Vb2021 Park (report)
- brandefense.io — Lazarus Apt Group Apt38 (report)
- us-cert.gov — Mar 10135536 B White (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Bankshot (report)
- malverse.it — Analisi Bankshot Copperhedge (report)
- blog.reversinglabs.com — Hidden Cobra (report)
- CISA — Aa22 108A (report)
- CISA — Ar20 232A (report)
- virusbulletin.com — Vb2018 Kalnai Poslusny (report)
- Kaspersky — 116326 (report)
- Kaspersky — 109490 (report)
- us-cert.gov — Ar20 133A (report)
- MITRE ATT&CK — S0239 (report)
- McAfee — Hidden Cobra Targets Turkish Financial Sector New Bankshot Implant (report)