{
  "family": "bankoren",
  "sample_count": 1,
  "category": "trojan",
  "description": "<h3>Executive Summary</h3>\nBankoren is a specialized banking trojan engineered to stealthily harvest financial credentials, intercept two-factor authentication (2FA) tokens, and facilitate fraudulent wire transfers. It primarily targets the customers of regional and international banking institutions, posing a severe financial risk to both individuals and corporate entities.\n\n<h3>Operational Tactics and Infection Vector</h3>\nBankoren is most commonly distributed via highly convincing spear-phishing emails. These emails often spoof legitimate banks or government agencies, urging the victim to open an attached, macro-laced document or click a link leading to a compromised website hosting an exploit kit.\n\nOnce the host is infected, Bankoren operates quietly in the background, utilizing advanced \"man-in-the-browser\" (MitB) capabilities. When the victim navigates to a targeted banking portal, the trojan activates, employing several attack methodologies:\n<ul>\n<li><strong>Web Injections:</strong> Bankoren modifies the HTML of the banking site in real-time, injecting fraudulent fields into the login page to capture social security numbers, PINs, or mother's maiden names.</li>\n<li><strong>Form Grabbing:</strong> It captures the victim's username and password the moment they click \"submit,\" circumventing TLS/SSL encryption because the data is intercepted locally.</li>\n<li><strong>Transaction Manipulation:</strong> Advanced variants can alter the destination account of a legitimate wire transfer initiated by the victim, routing the funds to a money mule account while displaying the correct information to the user.</li>\n</ul>\n\n<h3>Security and Financial Implications</h3>\nBankoren is an acute financial threat. A successful infection bypasses traditional perimeter security and directly targets the endpoint's interaction with financial services, leading to unauthorized access, significant monetary theft, and regulatory compliance violations.\n\n<h3>Mitigation and Defense</h3>\n<ul>\n<li><strong>Endpoint Threat Detection (EDR):</strong> Deploy EDR platforms capable of detecting browser process injection (e.g., hooking of `explorer.exe` or browser executables) and unauthorized API calls associated with form grabbing.</li>\n<li><strong>User Security Awareness:</strong> Conduct rigorous, continuous training for employees—particularly in finance and HR departments—to identify sophisticated spear-phishing lures and verify the authenticity of financial requests.</li>\n<li><strong>Out-of-Band Authentication:</strong> Financial institutions should mandate true out-of-band authentication (like a hardware security key or biometric confirmation on a separate device) for all high-value transactions to defeat MitB manipulation.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Trojan.Bankoren",
    "Banker.Bankoren",
    "Win32/Bankoren"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1056.004",
    "T1185",
    "T1566.001"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T16:06:52Z",
  "type": "Banking Trojan",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}