Carbanak
MITRE ATT&CK: S0030 View on attack.mitre.org
Aliases: Anunak, Sekur RAT, Carbanak
- First seen
- 2013-12-01 00:00:00
- Malware type
- rat, backdoor
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-02-26 16:10:17
- Profile updated
- 2026-07-07 15:43:43
Targeted industries: financial-services retail-and-hospitality
Targeted regions: country_code:us country_code:ru country_code:jp country_code:de
Context
Carbanak is a full-featured, remote backdoor used by a group of the same name (Carbanak). It is intended for espionage, data exfiltration, and providing remote access to infected machines.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to Carbanak (S0030). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | find-domain-a.com | 2026-02-26 | 2 |
Detection coverage
- 2 YARA rules
- 291 Sigma rules
Malware & tools used
- OS Credential Dumping (attack-pattern)
- Screen Capture (attack-pattern)
- Web Protocols (attack-pattern)
- Query Registry (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Windows Command Shell (attack-pattern)
- Portable Executable Injection (attack-pattern)
- Local Email Collection (attack-pattern)
- Process Discovery (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Remote Access Tools (attack-pattern)
- Keylogging (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Local Account (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- File Deletion (attack-pattern)
- Standard Encoding (attack-pattern)
- Data Transfer Size Limits (attack-pattern)
Used by threat actors
Detection rules
- CAPE_Carbanak (yara-rule)
- MALPEDIA_Win_Carbanak_Auto (yara-rule)
Reports & references
- app.box.com — P7Qzcury97Tuwk26694Uutujwqmwqyhe (report)
- media.kasperskycontenthub.com — Carbanak Apt Eng (report)
- threatintel.blog — Opblueraven Part1 (report)
- threatintel.blog — Opblueraven Part2 (report)
- secureworks.com — Gold Niagara (report)
- Palo Alto Unit 42 — Mulelibra (report)
- fox-it.com — Anunak Aka Carbanak Update (report)
- CrowdStrike — Carbon Spider Embraces Big Game Hunting Part 1 (report)
- Mandiant — Behind The Carbanak Backdoor (report)
- Mandiant — Evolution Of Fin7 (report)
- CrowdStrike — Carbon Spider Sprite Spider Target Esxi Servers With Ransomware (report)
- cert.ssi.gouv.fr — 20220427 Np Tlpwhite Anssi Fin7 (report)
- ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
- blog.sekoia.io — Exposing Fakebat Loader Distribution Methods And Adversary Infrastructure (report)
- Mandiant — Cds18 Technical S05 Att&Cking Fin7 (report)
- Mandiant — Evolution Of Fin7 (report)
- cocomelonc.github.io — Malware Av Evasion 8 (report)
- cocomelonc.github.io — Malware Pers 4 (report)
- cocomelonc.github.io — Malwild Book (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Carbanak (report)
- brighttalk.com — Fin7 Apt How Billion Dollar Crime Ring Remains Active After Leaders Arrest (report)
- Mandiant — Carbanak Week Part Two Continuing Source Code Analysis (report)
- prodaft.com — Fin7 Tlpclear (report)
- therecord.media — Two Carbanak Hackers Sentenced To Eight Years In Prison In Kazakhstan (report)
- blog.truesec.com — Collaboration Between Fin7 And The Ryuk Group A Truesec Investigation (report)