Threat group.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1036.004 Masquerade Task or Service |
Carbanak has copied legitimate service names to use for malicious services. |
| T1036.005 Match Legitimate Resource Name or Location |
Carbanak has named malware "svchost.exe," which is the name of the Windows shared service host program. |
| T1078 Valid Accounts |
Carbanak actors used legitimate credentials of banking employees to perform operations that sent them millions of dollars. |
| T1102.002 Bidirectional Communication |
Carbanak has used a VBScript named "ggldr" that uses Google Apps Script, Sheets, and Forms services for C2. |
| T1218.011 Rundll32 |
Carbanak installs VNC server software that executes through rundll32. |
| T1219 Remote Access Tools |
Carbanak used legitimate programs such as AmmyyAdmin and Team Viewer for remote interactive C2 to target systems. |
| T1543.003 Windows Service |
Carbanak malware installs itself as a service to provide persistence and SYSTEM privileges. |
| T1588.002 Tool |
Carbanak has obtained and used open-source tools such as PsExec and Mimikatz. |
| T1686 Disable or Modify System Firewall |
Carbanak may use netsh to add local firewall rule exceptions. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.