Carberp
MITRE ATT&CK: S0484 View on attack.mitre.org
Aliases: Carberp
- First seen
- 2009-01-01 00:00:00
- Malware type
- trojan, credential-stealer
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 4 (4 malicious)
- Last IoC activity
- 2025-09-30 16:23:16
- Profile updated
- 2026-07-07 14:43:12
Targeted industries: financial-services government-and-public-sector education-and-nonprofits
Context
Carberp is a credential and information stealing malware that has been active since at least 2009. Carberp's source code was leaked online in 2013, and subsequently used as the foundation for the Carbanak backdoor.
Recent IoC activity
4 malicious indicators in Maltiverse are attributed to Carberp (S0484). The 4 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| URL | http://theassassinscreedrevolution.com/login/?x=11111111111111111111111111111111 | 2025-09-30 | 1 |
| URL | http://droopie76.net/login/?x=11111111111111111111111111111111 | 2025-09-30 | 1 |
| URL | http://www.drunkpikachu.com/ | 2025-09-30 | 1 |
| URL | http://tiktak02.com/accounts/authorization.html | 2025-09-30 | 1 |
Detection coverage
- 1 YARA rules
- 424 Sigma rules
Malware & tools used
- Bootkit (attack-pattern)
- Credentials from Password Stores (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Rootkit (attack-pattern)
- Credential API Hooking (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Virtualization/Sandbox Evasion (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- VNC (attack-pattern)
- Browser Session Hijacking (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- Asynchronous Procedure Call (attack-pattern)
- Security Software Discovery (attack-pattern)
- Query Registry (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Web Protocols (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Native API (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- System Information Discovery (attack-pattern)
- Screen Capture (attack-pattern)
- Process Discovery (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
Detection rules
- MALPEDIA_Win_Carberp_Auto (yara-rule)
Reports & references
- cocomelonc.github.io — Malware Av Evasion 8 (report)
- f5.com — Banking Trojans A Reference Guide To The Malware Family Tree (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Carberp (report)
- cdn1.esetstatic.com — White Papers Win 32 Carberp (report)
- web.archive.org — Ht T06 Dissecting Banking Trojan Carberp Copy1 (report)
- blog.avast.com — Carberp Epitaph (report)
- MITRE ATT&CK — S0484 (report)
- Kaspersky — 68732 (report)
- rsa.com — The Carbanak Fin7 Syndicate (report)
- Trend Micro — Carberp (report)