Original Release Date: 12/3/2020
Researchers from Check Point Research discovered multiple variants of Bandook, a 13-year-old banking trojan, targeting victims in an unusually wide variety of locations, including the US. The targeted sectors include government, finance, energy, food, healthcare, education, IT, and legal institutions. It is believed a third party sells the offensive infrastructure to governments and threat actors worldwide. Cybercriminals attempt to convince their targets to click on a ZIP file containing a malicious Microsoft Word document that, if opened and macros are enabled, delivers the Bandook payload and creates a backdoor into the organization’s systems or network.
The NJCCIC recommends users exercise caution when clicking on links or opening attachments sent in emails from both trusted and unknown entities, verify the legitimacy of requests via a separate means of communication, and refrain from enabling macros in documents unless there is a known use for this feature. For technical details and IOCs, please review the Check Point Research article.