ATT&CKGroupsCarbanak

Carbanak

G0008

Threat group.View on attack.mitre.org

About this group

Carbanak is a cybercriminal group that has used Carbanak malware to target financial institutions since at least 2013. Carbanak may be linked to groups tracked separately as Cobalt Group and FIN7 that have also used Carbanak malware.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1036.004
Masquerade Task or Service

Carbanak has copied legitimate service names to use for malicious services.

T1036.005
Match Legitimate Resource Name or Location

Carbanak has named malware "svchost.exe," which is the name of the Windows shared service host program.

T1078
Valid Accounts

Carbanak actors used legitimate credentials of banking employees to perform operations that sent them millions of dollars.

T1102.002
Bidirectional Communication

Carbanak has used a VBScript named "ggldr" that uses Google Apps Script, Sheets, and Forms services for C2.

T1218.011
Rundll32

Carbanak installs VNC server software that executes through rundll32.

T1219
Remote Access Tools

Carbanak used legitimate programs such as AmmyyAdmin and Team Viewer for remote interactive C2 to target systems.

T1543.003
Windows Service

Carbanak malware installs itself as a service to provide persistence and SYSTEM privileges.

T1588.002
Tool

Carbanak has obtained and used open-source tools such as PsExec and Mimikatz.

T1686
Disable or Modify System Firewall

Carbanak may use netsh to add local firewall rule exceptions.

Software4

Campaigns0

None recorded.

References5

  1. Europol Cobalt Mar 2018 Open source
    Europol. (2018, March 26). Mastermind Behind EUR 1 Billion Cyber Bank Robbery Arrested in Spain. Retrieved October 10, 2018.
  2. FireEye FIN7 April 2017 Open source
    Carr, N., et al. (2017, April 24). FIN7 Evolution and the Phishing LNK. Retrieved April 24, 2017.
  3. Kaspersky Carbanak Open source
    Kaspersky Lab's Global Research and Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved August 23, 2018.
  4. Secureworks GOLD KINGSWOOD Threat Profile Open source
    Secureworks. (n.d.). GOLD KINGSWOOD. Retrieved October 18, 2021.
  5. Secureworks GOLD NIAGARA Threat Profile Open source
    CTU. (n.d.). GOLD NIAGARA. Retrieved September 21, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.