Old Bandook Malware Reappears

NJCCIC Alert

Original Release Date: 12/3/2020

Summary

Researchers from Check Point Research discovered multiple variants of Bandook, a 13-year-old banking trojan, targeting victims in an unusually wide variety of locations, including the US. The targeted sectors include government, finance, energy, food, healthcare, education, IT, and legal institutions. It is believed a third party sells the offensive infrastructure to governments and threat actors worldwide. Cybercriminals attempt to convince their targets to click on a ZIP file containing a malicious Microsoft Word document that, if opened and macros are enabled, delivers the Bandook payload and creates a backdoor into the organization’s systems or network.

Recommendations

The NJCCIC recommends users exercise caution when clicking on links or opening attachments sent in emails from both trusted and unknown entities, verify the legitimacy of requests via a separate means of communication, and refrain from enabling macros in documents unless there is a known use for this feature. For technical details and IOCs, please review the Check Point Research article.

New Jersey Cybersecurity & Communications Integration Cell

2 Schwarzkopf Dr, Ewing Township, NJ 08628

njccic@cyber.nj.gov

OUR COMMITMENT

The NJCCIC is a component organization within the New Jersey Office of Homeland Security and Preparedness. We are the State's one-stop-shop for cyber threat analysis, incident reporting, and information sharing and are committed to making New Jersey more resilient to cyber threats by spreading awareness and promoting the adoption of best practices.

Agency Seals of State of NJ, NJOHSP and NJCCIC

STAY CONNECTED:

View our Privacy Policy here.

View our Site Index here.