Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors MoneyTaker

Description

In less than two years, this group has conducted over 20 successful attacks on financial institutions and legal firms in the USA, UK and Russia. The group has primarily been targeting card processing systems, including the AWS CBR (Russian Interbank System) and purportedly SWIFT (US). Given the wide usage of STAR in LATAM, financial institutions in LATAM could have particular exposure to a potential interest from the MoneyTaker group.

AI Analysis

· 1 week ago

Executive Summary

MoneyTaker is a threat actor targeting financial institutions and legal firms in the USA, UK, Russia, and potentially LATAM, with a focus on card processing systems such as AWS CBR and SWIFT. Over 20 successful attacks in two years indicate a high operational tempo and significant capability to exploit financial infrastructure vulnerabilities.

Goals & Targeting

MoneyTaker’s targeting of financial institutions and legal firms suggests a primary motivation of financial gain, data exfiltration, or disruption of critical infrastructure. The focus on card processing systems such as SWIFT and AWS CBR indicates an interest in exploiting high-value financial data flows, potentially for monetary theft or to destabilize financial systems. Legal firms may be targeted for sensitive client data or to facilitate fraud. The inclusion of Russia and LATAM as potential targets highlights a strategic interest in regions with significant financial transaction volumes and potentially weaker cybersecurity postures.

Enhanced Description

MoneyTaker has executed over 20 successful attacks within two years, primarily targeting financial institutions and legal firms in the USA, UK, and Russia, with potential interest in LATAM due to the prevalence of STAR systems. The group’s focus on card processing infrastructures, including the Russian Interbank System (AWS CBR) and SWIFT in the US, highlights a strategic intent to exploit critical financial pathways. While specific technical methods remain undocumented, the group’s success suggests a combination of targeted spear-phishing, network infiltration, and exploitation of vulnerabilities in financial systems. The potential exposure of LATAM institutions underscores the need for global threat awareness, particularly in regions reliant on card processing technologies.

Key Capabilities

  • Targeted spear-phishing campaigns with malicious document payloads
  • Exploitation of vulnerabilities in card processing and financial systems
  • Network infiltration and lateral movement within enterprise environments
  • Data exfiltration techniques tailored for financial data theft

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Collection
Exfiltration

ATT&CK Techniques

T1210.001 - Exploit Public-Facing Application (Card Processing System Vulnerabilities)
T1071.001 - Proxy (C2 Communication via Encrypted Channels)
T1059.003 - Command and Scripting Interpreter: PowerShell (Post-Exploitation)
T1566.001 - Phishing (Targeted Email Campaigns)

Software / Tooling

Custom malware for financial system exploitation
Malicious Office documents with embedded macros
Exploitation frameworks for card processing systems

Campaigns & Victims

MoneyTaker’s campaigns exhibit a high operational tempo, with over 20 successful attacks in two years, primarily targeting financial institutions in the USA, UK, and Russia. The group’s campaigns likely involve spear-phishing, exploitation of card processing infrastructures, and lateral movement within compromised networks. Notable operations include alleged intrusions into SWIFT systems in the US and the Russian Interbank System (AWS CBR), with potential interest in LATAM institutions using STAR systems. Campaigns appear to prioritize stealth and persistence to avoid detection.

IOC Patterns

  • Spear-phishing with macro-laced Office documents targeting financial sector employees
  • C2 communication using encrypted protocols (e.g., HTTPS, DNS tunneling)
  • Staging infrastructure on bulletproof hosting services
  • Indicator of compromise (IOC) patterns linked to card processing system vulnerabilities

Recommended Actions

  • Implement advanced phishing detection and employee training programs
  • Conduct regular vulnerability assessments of card processing systems
  • Deploy network segmentation to isolate financial systems
  • Monitor for anomalous DNS or encrypted traffic patterns indicative of C2 activity
  • Enforce multi-factor authentication for critical financial applications

Suggested Tags

APT
Financial-sector
Espionage
Card-Processing-Exploitation

Confidence Assessment

Confidence in MoneyTaker’s targeting of financial institutions and legal firms is high, supported by multiple reported attacks. However, specific technical capabilities, tools, and MITRE technique details are inferred based on sector and system targeting, as explicit evidence remains limited. Gaps exist in confirmed tool use, sophistication levels, and full campaign timelines, necessitating further intelligence collection for precise attribution.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Financial Targeting
APT
Financial-sector
Espionage
Card-Processing-Exploitation

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.