Carbon

MITRE ATT&CK: S0335 View on attack.mitre.org

Aliases: Carbon

Malware type
backdoor
Family
Malware family
Operating systems
windows
Related IoCs
20 (16 malicious)
Last IoC activity
2026-08-09 06:59:48
Profile updated
2026-07-07 12:43:51

Targeted industries: government-and-public-sector

Targeted regions: country_code:kz country_code:kg country_code:uz

Context

Carbon is a sophisticated, second-stage backdoor and framework that can be used to steal sensitive information from victims. Carbon has been selectively used by Turla to target government and foreign affairs-related organizations in Central Asia.

Recent IoC activity

16 malicious indicators in Maltiverse are attributed to Carbon (S0335). The 16 most recently updated:

Detection coverage

  • 288 Sigma rules

Malware & tools used

  • Scheduled Task (attack-pattern)
  • Web Service (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Query Registry (attack-pattern)
  • Permission Groups Discovery (attack-pattern)
  • System Time Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Windows Service (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Process Discovery (attack-pattern)

Used by threat actors

Reports & references

  • ESET — Carbon Paper Peering Turlas Second Stage Backdoor (report)
  • Kaspersky — 88069 (report)
  • MITRE ATT&CK — S0335 (report)

External references