Carbon
MITRE ATT&CK: S0335 View on attack.mitre.org
Aliases: Carbon
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 20 (16 malicious)
- Last IoC activity
- 2026-08-09 06:59:48
- Profile updated
- 2026-07-07 12:43:51
Targeted industries: government-and-public-sector
Targeted regions: country_code:kz country_code:kg country_code:uz
Context
Carbon is a sophisticated, second-stage backdoor and framework that can be used to steal sensitive information from victims. Carbon has been selectively used by Turla to target government and foreign affairs-related organizations in Central Asia.
Recent IoC activity
16 malicious indicators in Maltiverse are attributed to Carbon (S0335). The 16 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | securenetsystem.net | 2026-08-09 | 1 |
| hostname | eddy-elderventures.com | 2026-07-02 | 1 |
| URL | http://winscoft.com/tcp/index.php | 2025-09-30 | 1 |
| URL | http://africa01.tk/africa/ | 2025-09-30 | 1 |
| URL | http://eddy-elderventures.com/js/goody/ | 2025-09-30 | 1 |
| URL | http://eddy-elderventures.com/js/eddy/ | 2025-09-30 | 1 |
| URL | http://tosin.org.in/mavlad/index.php | 2025-09-30 | 1 |
| URL | http://dreamworldhospitality.com/3/ | 2025-09-30 | 1 |
| URL | http://dreamworldhospitality.com/6/ | 2025-09-30 | 1 |
| URL | http://dreamworldhospitality.com/5/ | 2025-09-30 | 1 |
| URL | http://dreamworldhospitality.com/4/ | 2025-09-30 | 1 |
| URL | http://dreamworldhospitality.com/1/ | 2025-09-30 | 1 |
| URL | http://dreamworldhospitality.com/2/ | 2025-09-30 | 1 |
| URL | http://securenetsystem.net/panel/ | 2025-09-30 | 1 |
| URL | http://ssg-mcdaviz.org/chrisfad/chris/ | 2025-09-30 | 1 |
| URL | http://vipfilenet.uni.me/ml/vrs/cabon/tpanel/index.php?a=login | 2025-09-30 | 1 |
Detection coverage
- 288 Sigma rules
Malware & tools used
- Scheduled Task (attack-pattern)
- Web Service (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Query Registry (attack-pattern)
- Permission Groups Discovery (attack-pattern)
- System Time Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Local Data Staging (attack-pattern)
- Windows Service (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
- Remote System Discovery (attack-pattern)
- Web Protocols (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Process Discovery (attack-pattern)
Used by threat actors
- Turla (threat-actor)
Reports & references
- ESET — Carbon Paper Peering Turlas Second Stage Backdoor (report)
- Kaspersky — 88069 (report)
- MITRE ATT&CK — S0335 (report)