Thursday, May 15, 2025
HomeComputer SecurityWith New Bankshot Malware Cybercrime Group Hidden Cobra Targets Financial Sectors

With New Bankshot Malware Cybercrime Group Hidden Cobra Targets Financial Sectors

Published on

SIEM as a Service

Follow Us on Google News

Hidden Cobra cybercrime group continues to target multiple industries and financial sectors. With this new aggressive campaign, the group implanted Bankshot malware in Turkish financial system.

Bankshot malware last appeared in the year of 2017, it is designed to remain persistent in the victim’s network, also it is capable of searching for hosts that related to financial SWIFT network, destroy evidence and perform other destructive functions.

The New aggressive campaign discovered by McAfee Threat Research team, according to their investigation the infection occurred between March 2 and 3. Attackers targeted Turkish government organization and the attack not surfaced in any other countries.

Malware Distribution – Hidden Cobra

Attackers targeted victims through the spear phishing email campaigns that contain the malicious document attached in name Agreement.docx and it appears to be agreement document.

- Advertisement - Google News
Hidden Cobra

But the document contains embedded Adobe Flash exploit that leverages the vulnerability CVE-2018-4878 and downloads and executes the implants hidden in zip files form the website falcancoin[dot]io that appears to be like Cryptoexchange platform Falcon Coin.

Also Read Most Important Tools and Resources For Security Researcher, Malware Analyst, Reverse Engineer

The downloaded implants will be executed when the victims view the document and it communicates with the three command and control server that hardcore, two of them are Chinese gambling sites.McAfee Threat Research team published a detailed analysis report.

The bankshot malware was first detected by Department of Homeland Security back on December 13, 2017, researchers from McAfee says the new sample matches 99% to the 2017 variant.

This campaign will have a very high success ratio against the victims who still running with an unpatched version of Flash.

IOCs

Hashes
650b7d25f4ed87490f8467eb48e0443fb244a8c4
65e7d2338735ec04fd9692d020298e5a7953fd8d
166e8c643a4db0df6ffd6e3ab536b3de9edc9fb7
a2e966edee45b30bb6bb5c978e55833eec169098

Domains
530hr[dot]com/data/common.php
028xmz[dot]com/include/common.php
168wangpi[dot]com/include/charset.php
Falcancoin[dot]io
Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Critical BitLocker Flaw Exploited in Minutes: Bitpixie Vulnerability Proof of Concept Unveiled

Security researchers have demonstrated a non-invasive method to bypass Microsoft BitLocker encryption on Windows...

Google Chrome Zero-Day Vulnerability (CVE-2025-4664) Actively Exploited in The Wild

Google has rolled out a fresh Stable Channel update for the Chrome browser across...

Threat Actors Leverage Weaponized HTML Files to Deliver Horabot Malware

A recent discovery by FortiGuard Labs has unveiled a cunning phishing campaign orchestrated by...

TA406 Hackers Target Government Entities to Steal Login Credentials

The North Korean state-sponsored threat actor TA406, also tracked as Opal Sleet and Konni,...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Threat Actors Leverage Weaponized HTML Files to Deliver Horabot Malware

A recent discovery by FortiGuard Labs has unveiled a cunning phishing campaign orchestrated by...

Katz Stealer Malware Hits 78+ Chromium and Gecko-Based Browsers

Newly disclosed information-stealing malware dubbed Katz Stealer has emerged as a significant threat to...

Hackers Weaponize KeePass Password Manager to Spread Malware and Steal Passwords

Threat actors have successfully exploited the widely-used open-source password manager, KeePass, to spread malware...