PULSE NAME
Carbanak gang is back and packing new guns
WHITE Anunak AlienVault 2015-09-08 Modified: 2017-08-30
82
IOCs
HIGH VOLUME
The Carbanak financial APT group made the headlines when Group-IB and Fox-IT broke the news in December 2014, followed by the Kaspersky report in February 2015. The two reports describe the same cybercriminal gang which stole up to several hundreds of millions of dollars from various financial institutions. However, the story is interesting not only because of the large amount of money stolen but also from a technical point of view. The Carbanak team does not just blindly compromise large numbers of computers and try to ‘milk the cow’ as other actors do, instead they act like a mature APT-group. They only compromise specific high-value targets and once inside the company networks, move laterally to hosts that can be monetized.
Indicators of Compromise (4 / 82 total)
All domain hostname FileHash-SHA1 CVE YARA FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 0b5dc030e73074b18b1959d1cf7177ff510dbc2a0ec2b8bb927936f59eb3d14d 2017-08-23
FileHash-SHA256 18e3e840a5e5b75747d6b961fca66a670e3faef252aaa416a88488967b47ac1c 2017-08-23
FileHash-SHA256 ad6bb982a1ecfe080baf0a2b27950f989c107949b1cf02b6e0907f1a568ece15 2017-08-23
FileHash-SHA256 fc609adef44b5c64de029b2b2cff22a6f36b6bdf9463c1bd320a522ed39de5d9 2017-08-23