Bankshot is a Windows backdoor and remote access implant associated with the Lazarus Group, also tracked under the Hidden Cobra umbrella, and has been linked to financially motivated operations including campaigns targeting Turkish financial institutions. It has been described as an HTTP backdoor supporting a broad command set and as part of a Lazarus toolset used for post-compromise control, reconnaissance, collection, and exfiltration.
Bankshot can enumerate running processes, collect process identifiers, and gather domain and account information through process monitoring. It also queries for specific Registry conditions before executing its payload and stores data in the Windows Registry. The malware can recursively enumerate files in directories, collect files from the local system, and transmit gathered data back to its command-and-control infrastructure over the same channel used for operator communications.
The implant supports process creation through native Windows APIs, including execution in alternate user contexts, and can terminate processes by process ID. It uses obfuscation and encoding techniques including XOR-decoded embedded strings and non-standard command encoding with character-range transformations and gzip to hinder analysis and network detection. Bankshot also includes cleanup functionality: it can mark files for deletion on reboot, uninstall itself, and remove itself from an infected host.
Public reporting has consistently placed Bankshot within the broader Lazarus malware ecosystem alongside other DPRK-linked tooling used in espionage and financial intrusion activity. Its observed behavior aligns with a modular post-exploitation backdoor focused on host discovery, file collection, command execution, and covert command-and-control communications on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Hidden Cobra Targets Turkish Financial Sector With New Bankshot Implant
26 distinct techniques documented for this family, organized by ATT&CK tactic.
One of them is an execution in the command line (see Figure 2), where the action is basically the execution of the console command cmd.exe /c %Source% > %LogFile% 2>&1
There are several static features that vary between the instances: dynamic Windows API resolution and the obfuscation of procedure and library names... the use of commercial packers, etc.
Dynamic resolution of Windows APIs ... The technique is very typical and has already been described [2, p.59].
This is achieved by sending the bot’s client-server traffic as a part of a fake TLS packet that mimics the TLS protocol and seemingly initiates a legitimate connection.
Many examples describe post-intrusion cleanup, anti-forensics, and removal of artifacts such as logs, scripts, malware components, scheduled tasks, registry keys, and temporary files.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
AdFind can enumerate domain users. APT41 used built-in net commands to enumerate domain administrator users. BloodHound can collect information about domain users, including identification of domain admin accounts.
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
This is achieved by sending the bot’s client-server traffic as a part of a fake TLS packet that mimics the TLS protocol and seemingly initiates a legitimate connection.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
Adversaries may encode data with a non-standard data encoding system to make the content of command and control traffic more difficult to detect. Command and control (C2) information can be encoded using a non-standard data encoding system that diverges from existing protocol specifications.
66 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... Bankshot ... (v1.1→v1.2) ...
Bankshot (v1.1→v1.2)
Malware that can modify file timestamps based on command-and-control instructions.
A Lazarus-associated implant mentioned as having functional overlap with WinorDLL64 and used as supporting context for attribution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.