Carberp

S0484

Malware.View on attack.mitre.org

About this malware

Carberp is a credential and information stealing malware that has been active since at least 2009. Carberp's source code was leaked online in 2013, and subsequently used as the foundation for the Carbanak backdoor.

Techniques used25

Procedure examples25

TechniqueProcedure example
T1012
Query Registry

Carberp has searched the Image File Execution Options registry key for "Debugger" within every subkey.

T1014
Rootkit

Carberp has used user mode rootkit techniques to remain hidden on the system.

T1021.005
VNC

Carberp can start a remote VNC session by downloading a new plugin.

T1027.013
Encrypted/Encoded File

Carberp has used XOR-based encryption to mask C2 server locations within the trojan.

T1036.005
Match Legitimate Resource Name or Location

Carberp has masqueraded as Windows system file names, as well as "chkntfs.exe" and "syscron.exe".

T1041
Exfiltration Over C2 Channel

Carberp has exfiltrated data via HTTP to already established C2 servers.

T1055.001
Dynamic-link Library Injection

Carberp's bootkit can inject a malicious DLL into the address space of running processes.

T1055.004
Asynchronous Procedure Call

Carberp has queued an APC routine to explorer.exe by calling ZwQueueApcThread.

T1056.004
Credential API Hooking

Carberp has hooked several Windows API functions to steal credentials.

T1057
Process Discovery

Carberp has collected a list of running processes.

T1068
Exploitation for Privilege Escalation

Carberp has exploited multiple Windows vulnerabilities (CVE-2010-2743, CVE-2010-3338, CVE-2010-4398, CVE-2008-1084) and a .NET Runtime Optimization vulnerability for privilege escalation.

T1071.001
Web Protocols

Carberp has connected to C2 servers via HTTP.

T1082
System Information Discovery

Carberp has collected the operating system version from the infected system.

T1105
Ingress Tool Transfer

Carberp can download and execute new plugins from the C2 server.

T1106
Native API

Carberp has used the NtQueryDirectoryFile and ZwQueryDirectoryFile functions to hide files and directories.

View all 25 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References3

  1. KasperskyCarbanak Open source
    Kaspersky Lab's Global Research & Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved March 27, 2017.
  2. RSA Carbanak November 2017 Open source
    RSA. (2017, November 21). THE CARBANAK/FIN7 SYNDICATE A HISTORICAL OVERVIEW OF AN EVOLVING THREAT. Retrieved July 29, 2020.
  3. Trend Micro Carberp February 2014 Open source
    Trend Micro. (2014, February 27). CARBERP. Retrieved July 29, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.