Carberp

MITRE ATT&CK: S0484 View on attack.mitre.org

Aliases: Carberp

First seen
2009-01-01 00:00:00
Malware type
trojan, credential-stealer
Family
Malware family
Operating systems
windows
Related IoCs
4 (4 malicious)
Last IoC activity
2025-09-30 16:23:16
Profile updated
2026-07-07 14:43:12

Targeted industries: financial-services government-and-public-sector education-and-nonprofits

Context

Carberp is a credential and information stealing malware that has been active since at least 2009. Carberp's source code was leaked online in 2013, and subsequently used as the foundation for the Carbanak backdoor.

Recent IoC activity

4 malicious indicators in Maltiverse are attributed to Carberp (S0484). The 4 most recently updated:

Detection coverage

  • 1 YARA rules
  • 424 Sigma rules

Malware & tools used

  • Bootkit (attack-pattern)
  • Credentials from Password Stores (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Rootkit (attack-pattern)
  • Credential API Hooking (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Virtualization/Sandbox Evasion (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • VNC (attack-pattern)
  • Browser Session Hijacking (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Asynchronous Procedure Call (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Query Registry (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Web Protocols (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Native API (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Screen Capture (attack-pattern)
  • Process Discovery (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)

Detection rules

  • MALPEDIA_Win_Carberp_Auto (yara-rule)

Reports & references

  • cocomelonc.github.io — Malware Av Evasion 8 (report)
  • f5.com — Banking Trojans A Reference Guide To The Malware Family Tree (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Carberp (report)
  • cdn1.esetstatic.com — White Papers Win 32 Carberp (report)
  • web.archive.org — Ht T06 Dissecting Banking Trojan Carberp Copy1 (report)
  • blog.avast.com — Carberp Epitaph (report)
  • MITRE ATT&CK — S0484 (report)
  • Kaspersky — 68732 (report)
  • rsa.com — The Carbanak Fin7 Syndicate (report)
  • Trend Micro — Carberp (report)

External references