Kaspersky Lab's Global Research and Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved August 23, 2018.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.004 Masquerade Task or Service |
GroupCarbanak | Carbanak has copied legitimate service names to use for malicious services. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupCarbanak | Carbanak has named malware "svchost.exe," which is the name of the Windows shared service host program. |
| T1056.001 Keylogging |
MalwareCarbanak | Carbanak logs key strokes for configured processes and sends them back to the C2 server. |
| T1071.001 Web Protocols |
MalwareCarbanak | The Carbanak malware communicates to its command server using HTTP with an encrypted payload. |
| T1078 Valid Accounts |
GroupCarbanak | Carbanak actors used legitimate credentials of banking employees to perform operations that sent them millions of dollars. |
| T1132.001 Standard Encoding |
MalwareCarbanak | Carbanak encodes the message body of HTTP traffic with Base64. |
| T1218.011 Rundll32 |
GroupCarbanak | Carbanak installs VNC server software that executes through rundll32. |
| T1543.003 Windows Service |
GroupCarbanak | Carbanak malware installs itself as a service to provide persistence and SYSTEM privileges. |
| T1573.001 Symmetric Cryptography |
MalwareCarbanak | Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode). Carbanak also uses XOR with random keys for its communications. |
| T1588.002 Tool |
GroupCarbanak | Carbanak has obtained and used open-source tools such as PsExec and Mimikatz. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.