Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: G0036

Description

GCMAN is a threat group that focuses on targeting banks for the purpose of transferring money to e-currency services. (Citation: Securelist GCMAN)

AI Analysis

· 1 week ago

Executive Summary

GCMAN, also known as G0036, targets financial institutions to facilitate unauthorized money transfers to e-currency services. Known for using remote access tools like VNC and SSH, their operations have raised concerns globally.

Goals & Targeting

GCMAN targets banks and financial institutions to achieve unauthorized monetary transfers, likely for the purpose of laundering funds through e-currency services. Their strategic focus on the financial sector underscores their intent to exploit vulnerabilities in critical economic systems, potentially leading to substantial financial losses and reputational damage for targeted organizations.

Enhanced Description

GCMAN is a sophisticated cyber threat actor primarily targeting the financial sector, with a focus on banks to enable fraudulent transfers to e-currency platforms. Their operations leverage remote access techniques such as VNC and SSH, indicating a capability to maintain persistence and control over compromised systems. While their primary motivation appears to be financial gain, GCMAN's activities pose significant risks to organizational security by compromising sensitive financial data and operational integrity.

Key Capabilities

  • Remote Access (VNC/SSH)
  • Data Exfiltration
  • Lateral Movement
  • Persistence

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Lateral Movement

ATT&CK Techniques

T1021.004
T1021.005

Software / Tooling

VNC Client/Server
SSH Tools

Campaigns & Victims

GCMAN has been active since at least 2019, with campaigns targeting financial institutions. Their operations often involve targeted attacks against bank systems to facilitate fraudulent transactions, highlighting their focus on the financial sector and the need for robust defensive measures.

IOC Patterns

  • VNC activity originating from external IPs
  • Excessive SSH login attempts
  • Known VNC/SSH scripts related to GCMAN campaigns

Recommended Actions

  • Enhance network monitoring for unusual VNC and SSH activities
  • Implement MFA in financial transactions
  • Conduct regular security audits on financial systems
  • Educate employees about phishing attempts

Suggested Tags

APT
Financial Fraud
Banking Sector
E-Currency Theft

Confidence Assessment

Confidence in GCMAN's descriptions is moderate with known TTPs and targets identified, but gaps exist regarding their exact origin and detailed campaign specifics.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Securelist GCMAN — Kaspersky Lab's Global Research & Analysis Team. (2016, February 8). APT-style bank robberies increase with Metel, GCMAN and Carbanak 2.0 attacks. Retrieved April 20, 2016.

Intel Summary

2

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

1

Tactics

Tags

APT
Financial Fraud
Banking Sector
E-Currency Theft

Details

MITRE ID
G0036
Type
Unknown
Country of Origin
R
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--0ea72cd5-ca30-46ba-bc04-378f701c658f
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.