Carbanak
MITRE ATT&CK: G0008 View on attack.mitre.org
Aliases: Anunak, Carbanak
- First seen
- 2013-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Related IoCs
- 2 (1 malicious)
- Last IoC activity
- 2026-02-26 16:10:17
- Profile updated
- 2026-07-07 11:50:25
Targeted industries: financial-services retail-and-hospitality
Context
Carbanak is a cybercriminal group that has used Carbanak malware to target financial institutions since at least 2013. Carbanak may be linked to groups tracked separately as Cobalt Group and FIN7 that have also used Carbanak malware.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to Carbanak (G0008). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | find-domain-a.com | 2026-02-26 | 2 |
Detection coverage
- 10 YARA rules
- 160 Sigma rules
Malware & tools used
- Masquerade Task or Service (attack-pattern)
- Rundll32 (attack-pattern)
- Valid Accounts (attack-pattern)
- Bidirectional Communication (attack-pattern)
- Windows Service (attack-pattern)
- Remote Access Tools (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Disable or Modify System Firewall (attack-pattern)
- Tool (attack-pattern)
- netsh (malware)
- Carbanak (malware)
- Mimikatz (malware)
- PsExec (malware)
Related threat objects
- FIN7 (threat-actor)
Reports & references
- europol.europa.eu — Mastermind Behind Eur 1 Billion Cyber Bank Robbery Arrested In Spain (report)
- media.kasperskycontenthub.com — Carbanak Apt Eng (report)
- MITRE ATT&CK — G0008 (report)
- Mandiant — Fin7 Phishing Lnk (report)
- secureworks.com — Gold Niagara (report)
- fox-it.com — Anunak Aka Carbanak Update (report)
- secureworks.com — Gold Kingswood (report)