Hidden Cobra Targets Turkish Financial Sector With New Bankshot Implant | McAfee Blogs
ID: 86ded346-d388-489d-86c5-fdfcc08466bd
STIX ID: report--86ded346-d388-489d-86c5-fdfcc08466bd
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2018-06-05
Last Modified Date: 2018-06-05
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
McAfee researchers describe an active Hidden Cobra campaign that used a Flash zero-day (CVE-2018-4878) embedded in spearphishing Word documents to deploy the Bankshot backdoor against multiple Turkish financial and government-controlled financial organizations; the report provides detailed reverse-engineering of the DLL implant, C2 infrastructure and IOCs (file hashes, domains), documents its capabilities (data collection, remote command execution, file wiping), and warns of likely reconnaissance for potential future financial theft.
