Also known as: Anunak, Carbanak, Carbanak Group, Carbon Spider, Ukraine, FIN7, tracked as, JokerStash, other names, not a single group, Sangria Tempest by Microsoft, Win32, Toshliph, as well as Win32, Wemosis
Carbanak is a cybercriminal group that has used Carbanak malware to target financial institutions since at least 2013. Carbanak may be linked to groups tracked separately as Cobalt Group and FIN7 that have also used Carbanak malware.(Citation: Kaspersky Carbanak)(Citation: FireEye FIN7 April 2017)(Citation: Europol Cobalt Mar 2018)(Citation: Secureworks GOLD NIAGARA Threat Profile)(Citation: Secureworks GOLD KINGSWOOD Threat Profile)
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Carbanak is a sophisticated cybercriminal group targeting financial institutions since 2013. Known for their use of Carbanak malware, linked to groups like Cobalt Group and FIN7, they primarily seek financial gain through targeted attacks.
Goals & Targeting
Carbanak's strategic objectives center around achieving financial gains through targeted attacks on financial services sectors. Their focus on countries like Russia suggests a potential operational base or strategic interest in specific regions where their activities may go unnoticed or be less scrutinized. The group likely targets financial institutions due to the high value of sensitive data and the potential for significant financial rewards.
Enhanced Description
Carbanak, also known as Anunak or Carbon Spider, is a cybercriminal group that has been active since at least 2013. They are renowned for their use of the Carbanak malware, which has been employed in attacks against financial institutions. This group is linked to other notorious cybercrime organizations, including Cobalt Group and FIN7, both of which have also utilized the Carbanak malware. The primary motivation behind Carbanak's activities appears to be financial gain, with a focus on infiltrating financial institutions to extract sensitive data or facilitate fraudulent transactions.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The group has been involved in campaigns such as Odinaff, which targets financial institutions globally. Their campaigns often exhibit a focus on stealth and long-term access, likely to enable sustained exfiltration of data or facilitate fraudulent activities over extended periods.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in Carbanak's details is moderate. While there is substantial information on their activities, the lack of clarity regarding their origins and exact modus operandi leaves some uncertainties.
Odinaff
No observed data linked yet.
46
Techniques
63
Tools
1
Campaigns
40
IOCs
0
Observed Data
13
Tactics