Carbanak

MITRE ATT&CK: S0030 View on attack.mitre.org

Aliases: Anunak, Sekur RAT, Carbanak

First seen
2013-12-01 00:00:00
Malware type
rat, backdoor
Family
Malware family
Operating systems
windows
Related IoCs
1 (1 malicious)
Last IoC activity
2026-02-26 16:10:17
Profile updated
2026-07-07 15:43:43

Targeted industries: financial-services retail-and-hospitality

Targeted regions: country_code:us country_code:ru country_code:jp country_code:de

Context

Carbanak is a full-featured, remote backdoor used by a group of the same name (Carbanak). It is intended for espionage, data exfiltration, and providing remote access to infected machines.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to Carbanak (S0030). The 1 most recently updated:

TypeIndicatorUpdatedSources
hostname find-domain-a.com 2026-02-26 2

Detection coverage

  • 2 YARA rules
  • 291 Sigma rules

Malware & tools used

  • OS Credential Dumping (attack-pattern)
  • Screen Capture (attack-pattern)
  • Web Protocols (attack-pattern)
  • Query Registry (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Portable Executable Injection (attack-pattern)
  • Local Email Collection (attack-pattern)
  • Process Discovery (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Remote Access Tools (attack-pattern)
  • Keylogging (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Local Account (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • File Deletion (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Data Transfer Size Limits (attack-pattern)

Used by threat actors

Detection rules

  • CAPE_Carbanak (yara-rule)
  • MALPEDIA_Win_Carbanak_Auto (yara-rule)

Reports & references

  • app.box.com — P7Qzcury97Tuwk26694Uutujwqmwqyhe (report)
  • media.kasperskycontenthub.com — Carbanak Apt Eng (report)
  • threatintel.blog — Opblueraven Part1 (report)
  • threatintel.blog — Opblueraven Part2 (report)
  • secureworks.com — Gold Niagara (report)
  • Palo Alto Unit 42 — Mulelibra (report)
  • fox-it.com — Anunak Aka Carbanak Update (report)
  • CrowdStrike — Carbon Spider Embraces Big Game Hunting Part 1 (report)
  • Mandiant — Behind The Carbanak Backdoor (report)
  • Mandiant — Evolution Of Fin7 (report)
  • CrowdStrike — Carbon Spider Sprite Spider Target Esxi Servers With Ransomware (report)
  • cert.ssi.gouv.fr — 20220427 Np Tlpwhite Anssi Fin7 (report)
  • ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
  • blog.sekoia.io — Exposing Fakebat Loader Distribution Methods And Adversary Infrastructure (report)
  • Mandiant — Cds18 Technical S05 Att&Cking Fin7 (report)
  • Mandiant — Evolution Of Fin7 (report)
  • cocomelonc.github.io — Malware Av Evasion 8 (report)
  • cocomelonc.github.io — Malware Pers 4 (report)
  • cocomelonc.github.io — Malwild Book (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Carbanak (report)
  • brighttalk.com — Fin7 Apt How Billion Dollar Crime Ring Remains Active After Leaders Arrest (report)
  • Mandiant — Carbanak Week Part Two Continuing Source Code Analysis (report)
  • prodaft.com — Fin7 Tlpclear (report)
  • therecord.media — Two Carbanak Hackers Sentenced To Eight Years In Prison In Kazakhstan (report)
  • blog.truesec.com — Collaboration Between Fin7 And The Ryuk Group A Truesec Investigation (report)

External references