ATT&CKReferencesKaspersky Carbanak

Kaspersky Carbanak

Kaspersky Lab's Global Research and Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved August 23, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1036.004
Masquerade Task or Service
GroupCarbanak

Carbanak has copied legitimate service names to use for malicious services.

T1036.005
Match Legitimate Resource Name or Location
GroupCarbanak

Carbanak has named malware "svchost.exe," which is the name of the Windows shared service host program.

T1056.001
Keylogging
MalwareCarbanak

Carbanak logs key strokes for configured processes and sends them back to the C2 server.

T1071.001
Web Protocols
MalwareCarbanak

The Carbanak malware communicates to its command server using HTTP with an encrypted payload.

T1078
Valid Accounts
GroupCarbanak

Carbanak actors used legitimate credentials of banking employees to perform operations that sent them millions of dollars.

T1132.001
Standard Encoding
MalwareCarbanak

Carbanak encodes the message body of HTTP traffic with Base64.

T1218.011
Rundll32
GroupCarbanak

Carbanak installs VNC server software that executes through rundll32.

T1543.003
Windows Service
GroupCarbanak

Carbanak malware installs itself as a service to provide persistence and SYSTEM privileges.

T1573.001
Symmetric Cryptography
MalwareCarbanak

Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode). Carbanak also uses XOR with random keys for its communications.

T1588.002
Tool
GroupCarbanak

Carbanak has obtained and used open-source tools such as PsExec and Mimikatz.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.