Carbanak

MITRE ATT&CK: G0008 View on attack.mitre.org

Aliases: Anunak, Carbanak

First seen
2013-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Related IoCs
2 (1 malicious)
Last IoC activity
2026-02-26 16:10:17
Profile updated
2026-07-07 11:50:25

Targeted industries: financial-services retail-and-hospitality

Context

Carbanak is a cybercriminal group that has used Carbanak malware to target financial institutions since at least 2013. Carbanak may be linked to groups tracked separately as Cobalt Group and FIN7 that have also used Carbanak malware.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to Carbanak (G0008). The 1 most recently updated:

TypeIndicatorUpdatedSources
hostname find-domain-a.com 2026-02-26 2

Detection coverage

  • 10 YARA rules
  • 160 Sigma rules

Malware & tools used

  • Masquerade Task or Service (attack-pattern)
  • Rundll32 (attack-pattern)
  • Valid Accounts (attack-pattern)
  • Bidirectional Communication (attack-pattern)
  • Windows Service (attack-pattern)
  • Remote Access Tools (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Disable or Modify System Firewall (attack-pattern)
  • Tool (attack-pattern)
  • netsh (malware)
  • Carbanak (malware)
  • Mimikatz (malware)
  • PsExec (malware)

Related threat objects

  • FIN7 (threat-actor)

Reports & references

  • europol.europa.eu — Mastermind Behind Eur 1 Billion Cyber Bank Robbery Arrested In Spain (report)
  • media.kasperskycontenthub.com — Carbanak Apt Eng (report)
  • MITRE ATT&CK — G0008 (report)
  • Mandiant — Fin7 Phishing Lnk (report)
  • secureworks.com — Gold Niagara (report)
  • fox-it.com — Anunak Aka Carbanak Update (report)
  • secureworks.com — Gold Kingswood (report)

External references