Malware
Bankshot
Also known as: COPPERHEDGE · FoggyBrass
Indicators of Compromise 9
MITRE ATT&CK TTPs 28
T1001.001 T1003 T1018 T1021.001 T1021.002 T1040 T1055 T1059 T1059.001 T1070.001 T1070.004 T1071.001 T1078 T1082 T1085 T1087 T1090 T1098 T1105 T1129 T1133 T1189 T1203 T1485 T1495 T1534 T1566 T1566.002
Junk Data
Command And Control
OS Credential Dumping
Credential Access
Remote System Discovery
Discovery
Remote Desktop Protocol
Lateral Movement
SMB/Windows Admin Shares
Lateral Movement
Network Sniffing
Credential Access
Process Injection
Defense Evasion
Command and Scripting Interpreter
Execution
PowerShell
Execution
Clear Windows Event Logs
Defense Evasion
File Deletion
Defense Evasion
Web Protocols
Command And Control
Valid Accounts
Defense Evasion
System Information Discovery
Discovery
T1085
Account Discovery
Discovery
Proxy
Command And Control
Account Manipulation
Persistence
Ingress Tool Transfer
Command And Control
Shared Modules
Execution
External Remote Services
Persistence
Drive-by Compromise
Initial Access
Exploitation for Client Execution
Execution
Data Destruction
Impact
Firmware Corruption
Impact
Internal Spearphishing
Lateral Movement
Phishing
Initial Access
Spearphishing Link
Initial Access
Source Articles
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Gunra ransomware, a Conti-derived operation, has been actively targeting critical infrastructure sectors globally, including healthcare, financial services, and government facilities. The group exploits known vulnerabilities in Fortinet (CVE-2025-24472) and Schneider Electric (CVE-2024-5559) devices to gain initial access, then uses Impacket tools for lateral movement and credential dumping. Gunra employs a double extortion model, exfiltrating data before encryption, and has listed 51 victims on its leak site since April 2025, primarily in South Korea, Brazil, and Europe. The group has ties to affiliate programs, uses WhatsApp for negotiations, and has demonstrated advanced capabilities such as MFA bypass and session hijacking via SSL-VPN manipulation.
hacker-news ·3w ago
Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
A state-sponsored threat actor has conducted a campaign exploiting a zero-day buffer overflow vulnerability in AnySign4PC, a South Korean financial-security software, through compromised legitimate websites used as watering holes. The attack allows remote code execution without user interaction by leveraging malicious WebSocket communication and DLL side-loading, leading to the deployment of SIGNBT or COPPERHEDGE backdoors. These backdoors enable remote command execution, file theft, reconnaissance, and lateral movement using tools like Mimikatz and RDP. The campaign overlaps technically with Gunra ransomware operations in infrastructure and artifacts, though no formal attribution to a specific group like Lazarus is made in the joint advisory.
hacker-news ·4w ago