Bankshot (also tracked as COPPERHEDGE and FoggyBrass by various security firms) is a sophisticated remote access trojan (RAT) primarily used in targeted attacks against financial institutions, media organizations, and government entities. First identified in campaigns attributed to the Lazarus Group—a state-sponsored threat actor—this malware gives attackers complete control over infected Windows machines. While originally designed for espionage and data theft in high-profile breaches, variants of Bankshot have appeared in broader distribution campaigns that can affect small businesses and individual users who fall victim to spear-phishing or software supply-chain compromises.

Bankshot — cybersecurity illustration
Photo by Tima Miroshnichenko on Pexels
Think you're infected right now? Disconnect from the internet immediately (unplug Ethernet or disable Wi-Fi). Do not log into banking, email, or work accounts until the machine is cleaned. Call us at (770) 679-1003 for emergency malware removal—we're located at 1112 Alpharetta St, Roswell, GA 30075. Bankshot can capture keystrokes, screenshots, and files in real time.

Threat Profile

Malware NameBankshot (COPPERHEDGE, FoggyBrass)
Threat TypeRemote Access Trojan (RAT), Backdoor
PlatformWindows (all versions)
File TypeWindows PE executable (.exe, .dll)
First ObservedLate 2017 (publicly disclosed February 2018)
AttributionLazarus Group (APT38, Hidden Cobra)
Primary TargetsFinancial institutions, media companies, government agencies; opportunistic infections via supply-chain attacks
AV Detection NamesTrojan.Bankshot, COPPERHEDGE, FoggyBrass, Backdoor.Win32.Lazarus, Lazarus.RAT (varies by vendor)
CapabilitiesRemote command execution, file upload/download, keylogging, screenshot capture, process manipulation, persistence mechanisms
SeverityHigh—complete system compromise with data exfiltration risk
Removal DifficultyModerate to High (rootkit-like persistence, registry modifications, multi-stage payload)
Last Updated (Malpedia)2026-09-24

How It Spreads

Bankshot typically arrives through carefully crafted spear-phishing emails that impersonate legitimate business communications. Attackers research their targets—employees at banks, accounting departments, HR personnel—and send messages with malicious attachments or links that appear work-related. The initial infection vector often involves a weaponized Microsoft Office document (Word or Excel) with embedded macros, or a PDF that exploits known vulnerabilities in outdated reader software. Once the victim opens the document and enables macros (or simply views the PDF on a vulnerable system), Bankshot silently installs itself.

In addition to direct email attacks, Bankshot has been distributed through compromised software updates and watering-hole attacks—where legitimate websites frequented by target groups are infected to deliver the malware. Small businesses and individual users occasionally encounter Bankshot variants bundled with pirated software, fake software installers downloaded from unofficial sources, or as a secondary payload delivered by other malware already present on the system.

Common distribution methods include:

  • Spear-phishing emails with weaponized Office documents or PDFs
  • Malicious links in emails that download the trojan disguised as a legitimate file
  • Drive-by downloads from compromised or malicious websites
  • Software supply-chain attacks (trojanized legitimate applications or updates)
  • Exploit kits targeting unpatched browser or plugin vulnerabilities
  • USB drives and removable media in highly targeted scenarios

What It Does On Your Machine

Once executed, Bankshot establishes persistence by copying itself to system directories and modifying Windows registry keys to ensure it runs every time your computer starts. The malware typically installs a backdoor that connects to a remote command-and-control (C2) server, allowing attackers to issue commands, upload additional malware modules, and exfiltrate stolen data. Bankshot is modular—the initial dropper may be relatively small, but it downloads additional payloads tailored to the attacker's objectives for your specific machine.

The trojan can log every keystroke you type (capturing passwords, credit card numbers, and confidential messages), take periodic screenshots of your desktop, enumerate all files on your hard drive, and selectively upload documents, databases, or financial records to attacker-controlled servers. It can also execute arbitrary commands as if the attacker were sitting at your keyboard, install additional malware, manipulate running processes, and disable security software. Some variants include features to detect and evade virtual machines or sandboxes used by security researchers, making analysis more difficult.

Behaviorally, infected systems may exhibit sluggish performance, unexplained network activity (even when idle), or security software that mysteriously stops working. You might notice unusual outbound connections to foreign IP addresses, though Bankshot often uses encrypted communications and legitimate-looking network protocols to blend in with normal traffic. The malware typically remains silent and avoids obvious symptoms to maintain long-term access for espionage or data theft.

Typical Bankshot persistence and behavioral indicators (observed in sandbox): C:\Windows\System32\svchost.exe ← Malware often masquerades as legitimate Windows process C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\taskhost.exe ← Copy of malware executable Registry Key (persistence): HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ "Windows Update Service" = "C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\taskhost.exe" Network Connections: Outbound TCP connections to various C2 domains/IPs ← Changes per campaign; encrypted traffic File Modifications: Creates/modifies files in %TEMP%\ and %APPDATA%\ directories Injects code into explorer.exe, svchost.exe, or browser processes

Manual Removal — Step by Step

01

Disconnect from the Internet

Immediately unplug your Ethernet cable or turn off Wi-Fi. This prevents the malware from receiving commands, exfiltrating more data, or downloading additional payloads while you work on removal.

02

Boot into Safe Mode with Networking

Restart your computer and press F8 (or Shift+F8 on newer systems) during boot to access Advanced Boot Options. Select "Safe Mode with Networking." This loads Windows with minimal drivers and prevents most malware from auto-starting, making removal easier. On Windows 10/11, you may need to use Settings > Update & Security > Recovery > Restart Now, then navigate to Troubleshoot > Advanced Options > Startup Settings > Restart > press 5 for Safe Mode with Networking.

03

Run a Full Scan with Updated Anti-Malware Software

If you have reputable antivirus software installed, update its definitions (you'll need internet briefly—use a wired connection if possible, or mobile hotspot). Run a complete system scan. Bankshot is detected by most major security vendors under names like Trojan.Bankshot, COPPERHEDGE, or Backdoor.Win32.Lazarus. Quarantine or delete all detected threats. If your current antivirus didn't catch it initially, consider downloading a secondary on-demand scanner like Malwarebytes or HitmanPro from a clean computer, transferring via USB.

04

Manually Check Startup Programs and Registry Entries

Press Windows+R, type msconfig, and hit Enter. Go to the Startup tab (or "Open Task Manager" on Windows 10/11, then the Startup tab in Task Manager). Look for unfamiliar entries, especially those with no publisher or located in %APPDATA%, %TEMP%, or C:\Windows\System32 with suspicious names. Disable them. Next, press Windows+R, type regedit, and navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. Delete any entries pointing to unfamiliar executables in user directories or temp folders.

05

Delete Malicious Files from Disk

Using File Explorer, navigate to C:\Users\[YourUsername]\AppData\Roaming\Microsoft\Windows\, %TEMP%, and C:\Windows\System32\. Sort by Date Modified to find recently created suspicious executables. Bankshot often uses names that mimic legitimate Windows processes (taskhost.exe, svchost.exe, dwm.exe) but placed in wrong directories. Delete these files. You may need to take ownership or use an unlocker tool if Windows reports "file in use." Show hidden files (View tab > Hidden items checkbox) to see everything.

06

Check Browser Extensions and Reset Settings

Open each browser (Chrome, Firefox, Edge) and review installed extensions. Remove anything unfamiliar or installed without your knowledge. Bankshot can install malicious browser extensions to monitor web activity or inject content. Consider resetting browser settings to defaults (this won't delete bookmarks but will remove extensions and clear cookies). In Chrome: Settings > Reset Settings > Restore settings to their original defaults.

07

Review Scheduled Tasks

Press Windows+R, type taskschd.msc, and hit Enter to open Task Scheduler. Browse through the Task Scheduler Library and look for tasks you didn't create, especially those running executables from %APPDATA% or %TEMP%. Bankshot sometimes creates scheduled tasks for persistence. Right-click and delete suspicious entries.

08

Change All Passwords from a Clean Device

Because Bankshot includes keylogging capabilities, assume every password typed while infected has been compromised. Use a different computer, tablet, or smartphone to change passwords for email, banking, work accounts, and any sensitive services. Enable two-factor authentication wherever possible for an extra layer of security.

09

Update Windows and All Software

Once the malware is removed, ensure Windows Update has installed all available patches (Settings > Update & Security > Windows Update). Update all installed software—especially browsers, Adobe Reader, Java, and Microsoft Office—to close vulnerabilities Bankshot or future malware might exploit.

10

Monitor for Reinfection and Consider Professional Verification

Restart your computer normally (not Safe Mode) and monitor for the next few days. Watch Task Manager for unusual CPU/network activity. Run periodic scans. Because Bankshot is sophisticated and can use rootkit techniques, consider having a professional verify complete removal—especially if the infected machine handles financial data or business operations. We offer thorough malware forensics at our Roswell shop.

Prevention

  1. Never enable macros in Office documents from untrusted sources or unexpected emails. Legitimate businesses rarely require macro-enabled documents, and this is the #1 entry point for Bankshot infections.
  2. Keep Windows and all software up to date. Enable automatic updates for the operating system, browsers, Adobe products, and Java. Most Bankshot campaigns exploit known vulnerabilities that have available patches.
  3. Use reputable antivirus/anti-malware software and keep it updated. Enable real-time protection and schedule regular scans. While no solution is perfect, modern security software detects most Bankshot variants.
  4. Be skeptical of unexpected email attachments and links, even from apparent colleagues or business contacts. Verify legitimacy through a separate communication channel (phone call, direct text) before opening attachments, especially .doc, .xls, .pdf, or .zip files.
  5. Download software only from official vendor websites or trusted app stores. Avoid third-party download sites, torrent repositories, and "free" versions of paid software—these are common malware distribution points.
  6. Implement least-privilege user accounts. Don't use an Administrator account for daily tasks. A standard user account limits malware's ability to modify system files and registry keys, making infection and persistence more difficult.
  7. Enable a firewall and consider network monitoring if you run a business. Unusual outbound connections to foreign servers can be early warning signs of compromise. Windows Firewall provides basic protection; small businesses should consider commercial UTM appliances.
  8. Back up important data regularly to an external drive or cloud service not continuously connected to your PC. If you do get infected, you can restore files without paying ransom or losing irreplaceable data.
Our 90-Day Warranty: When we remove Bankshot or any other malware from your computer, you're covered by our 90-day warranty against reinfection by the same threat. If the same malware comes back within three months (and you haven't introduced new risk factors), we'll re-clean your system at no additional charge. We stand behind our work.

Bring It In

Bankshot is not a simple virus you can always eliminate with a one-click scan. It's a sophisticated remote access trojan designed for espionage and data theft, often employing rootkit techniques and multiple persistence mechanisms. If you suspect your Windows PC is infected—especially if you've noticed unusual network activity, security software mysteriously disabled, or you work in finance, media, or handle sensitive business data—professional malware removal is the safest path. Our technicians at Computer Repair Roswell have the forensic tools and experience to completely eradicate Bankshot, verify your system is clean, and help you secure it against future attacks.

We're located at 1112 Alpharetta St, Roswell, GA 30075, and you can reach us at (770) 679-1003. Bring your computer in for a free diagnostic, or call to discuss remote assistance options if you cannot travel. Don't take chances with a trojan this capable—let us restore your peace of mind with thorough, professional malware remediation backed by our 90-day reinfection warranty.