Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Carbanak

Also known as: Anunak, Carbanak, Carbanak Group, Carbon Spider, Ukraine, FIN7, tracked as, JokerStash, other names, not a single group, Sangria Tempest by Microsoft, Win32, Toshliph, as well as Win32, Wemosis

Description

Carbanak is a cybercriminal group that has used Carbanak malware to target financial institutions since at least 2013. Carbanak may be linked to groups tracked separately as Cobalt Group and FIN7 that have also used Carbanak malware.(Citation: Kaspersky Carbanak)(Citation: FireEye FIN7 April 2017)(Citation: Europol Cobalt Mar 2018)(Citation: Secureworks GOLD NIAGARA Threat Profile)(Citation: Secureworks GOLD KINGSWOOD Threat Profile)

Goals & Targeting

Targeted Sectors

Financial services
Financial services
Healthcare
Government
Hospitality
Energy
Retail
Defense
Gaming

Targeted Countries / Regions

RU
US
DE
CN
UA
PL
GB
AE

AI Analysis

· 1 week ago

Executive Summary

Carbanak is a sophisticated cybercriminal group targeting financial institutions since 2013. Known for their use of Carbanak malware, linked to groups like Cobalt Group and FIN7, they primarily seek financial gain through targeted attacks.

Goals & Targeting

Carbanak's strategic objectives center around achieving financial gains through targeted attacks on financial services sectors. Their focus on countries like Russia suggests a potential operational base or strategic interest in specific regions where their activities may go unnoticed or be less scrutinized. The group likely targets financial institutions due to the high value of sensitive data and the potential for significant financial rewards.

Enhanced Description

Carbanak, also known as Anunak or Carbon Spider, is a cybercriminal group that has been active since at least 2013. They are renowned for their use of the Carbanak malware, which has been employed in attacks against financial institutions. This group is linked to other notorious cybercrime organizations, including Cobalt Group and FIN7, both of which have also utilized the Carbanak malware. The primary motivation behind Carbanak's activities appears to be financial gain, with a focus on infiltrating financial institutions to extract sensitive data or facilitate fraudulent transactions.

Key Capabilities

  • Advanced use of Carbanak malware
  • Employment of Rundll32 as an execution vector
  • Modification and persistence in Windows services
  • Utilization of remote access tools

MITRE ATT&CK Tactics

Persistance
Execution
Credential Access
Discovery

ATT&CK Techniques

T1218.011
T1036.005
T1543.003
T1219
T1036.004
T1588.002

Software / Tooling

Carbanak malware

Campaigns & Victims

The group has been involved in campaigns such as Odinaff, which targets financial institutions globally. Their campaigns often exhibit a focus on stealth and long-term access, likely to enable sustained exfiltration of data or facilitate fraudulent activities over extended periods.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Abnormal Rundll32 processes
  • Unusual modifications in Windows services

Recommended Actions

  • Implement rigorous phishing detection mechanisms
  • Monitor for unusual process executions using tools like Rundll32
  • Conduct regular audits of system services and processes

Suggested Tags

APT
Financial Sector
Cybercrime

Confidence Assessment

The confidence level in Carbanak's details is moderate. While there is substantial information on their activities, the lack of clarity regarding their origins and exact modus operandi leaves some uncertainties.

ATT&CK Techniques

Credential Access
1 technique
Impact
1 technique
Initial Access
1 technique
Lateral Movement
1 technique

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 11 Filename 9

References

  1. Kaspersky Carbanak — Kaspersky Lab's Global Research and Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved August 23, 2018.
  2. FireEye FIN7 April 2017 — Carr, N., et al. (2017, April 24). FIN7 Evolution and the Phishing LNK. Retrieved April 24, 2017.
  3. Europol Cobalt Mar 2018 — Europol. (2018, March 26). Mastermind Behind EUR 1 Billion Cyber Bank Robbery Arrested in Spain. Retrieved October 10, 2018.
  4. Secureworks GOLD NIAGARA Threat Profile — CTU. (n.d.). GOLD NIAGARA. Retrieved September 21, 2021.
  5. Secureworks GOLD KINGSWOOD Threat Profile — Secureworks. (n.d.). GOLD KINGSWOOD. Retrieved October 18, 2021.
  6. Fox-It Anunak Feb 2015 — Prins, R. (2015, February 16). Anunak (aka Carbanak) Update. Retrieved January 20, 2017.
  7. www.huntress.com — Cited by web research for: not a single group
  8. www.eset.com — Cited by web research for: Win32
  9. attack.mitre.org — Cited by web research for: T1219
  10. docs.rapid7.com — Cited by web research for: T1583
  11. attack.mitre.org — Cited by web research for: T1543

Intel Summary

46

Techniques

63

Tools

1

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

APT
Financial Sector
Cybercrime

Details

MITRE ID
G0008
Type
Unknown
Resource Level
Unknown
Primary Motivation
Financial gain
Country of Origin
Spain (ES)
Confidence
90%
Added
Jul 22, 2026
STIX ID
intrusion-set--55033a4d-3ffe-46b2-99b4-2c1541e9ce1c
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.