• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • HomePage
  • Instructor
  • Syllabus
  • Schedule
    • First Half of the Semester
      • Week 1: Course Introduction
      • Week 2: Meterpreter, Avoiding Detection, Client Side Attacks, and Auxiliary Modules
      • Week 3: Social Engineering Toolkit, SQL Injection, Karmetasploit, Building Modules in Metasploit, and Creating Exploits
      • Week 4: Porting Exploits, Scripting, and Simulating Penetration Testing
      • Week 5: Independent Study – Perform Metasploit Attack and Create Presentation
      • Week 6: Ettercap
      • Week 7: Introduction to OWASP’s WebGoat application
    • Second Half of the Semester
      • Week 8: Independent Study
      • Week 9: Introduction to Wireless Security
      • Week 10: Wireless Recon, WEP, and WPA2
      • Week 11: WPA2 Enterprise, Wireless beyond WiFi
      • Week 12: Jack the Ripper, Cain and Able, Delivery of Sample Operating Systems
      • Week 13: Independent Study – Analyze provided Operating System Samples and Create Assessment Report
      • Week 14: Deliver Assessment to Operating System Class either in person or via teleconferenc
  • Assignments
    • Analysis Reports
    • Group Project Report and Presentation
  • Webex
  • Harvard Coursepack
  • Gradebook

MIS 5212-Advanced Penetration Testing

MIS 5212 - Section 001 - Wade Mackey

Fox School of Business

North Korea Threat Group Targeting Turkish Financial Orgs

March 11, 2018 by Elizabeth V Calise 1 Comment

Hidden Cobra, a threat group linked to North Korea, has turned its interest to the financial institutions in Turkey. McAfee reported finding malware (known as Bankshot) associated with the group surfacing on systems belonging to three large financial organizations and at least two of major government-controlled entities involved in finance and trade in Turkey. The malware is designed to persist on compromised systems for further exploits. Stated by McAfee, this suggests that Hidden Cobra is trying to gather specific information that can be used to launch more attacks.

The FBI and the US Department of Homeland Security has described the group having a wide range of attack tools at its disposal. This includes: denial-of-service botnets, wiper malware, and remote access Trojans. The attacker’ tool choice, Bankshot, was also used in a Korean bank attack and in banks in Latin America. McAfee’s investigation showed that Bankshot implants were distributed via phishing emails. The emails contained a malicious word document with an embedded exploit for a recently disclosed Adobe Flash vulnerability.

https://www.darkreading.com/attacks-breaches/north-korea-threat-group-targeting-turkish-financial-orgs/d/d-id/1331223

Filed Under: Week 02 Tagged With:

Reader Interactions

Comments

  1. Donald Hoxhaj says

    May 11, 2018 at 1:28 am

    That’s pretty bad considering that these attacks happened on the top 3 financial institutions. It’s still unsure why the attacks happened, but if they have already compromised sensitive financial data, then it might actually cause huge financial loss or even breakdown of the Turkish economy. It’s important to revisit the security systems or try to grab hands of 3rd party security companies to see the source.

    Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Weekly Discussions

  • Uncategorized (10)
  • Week 01 (18)
  • Week 02 (9)
  • Week 03 (13)
  • Week 04 (17)
  • Week 05 (12)
  • Week 06 (16)
  • Week 07 (2)
  • Week 08 (8)
  • Week 09 (5)
  • Week 10 (10)
  • Week 11 (5)
  • Week 12 (5)
  • Week 13 (2)
  • Week 14 (7)

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in