Carbanak

S0030

Malware.View on attack.mitre.org

About this malware

Carbanak is a full-featured, remote backdoor used by a group of the same name (Carbanak). It is intended for espionage, data exfiltration, and providing remote access to infected machines.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1003
OS Credential Dumping

Carbanak obtains Windows logon password details.

T1012
Query Registry

Carbanak checks the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings for proxy configurations information.

T1021.001
Remote Desktop Protocol

Carbanak enables concurrent Remote Desktop Protocol (RDP) sessions.

T1027
Obfuscated Files or Information

Carbanak encrypts strings to make analysis more difficult.

T1030
Data Transfer Size Limits

Carbanak exfiltrates data in compressed chunks if a message is larger than 4096 bytes .

T1055.002
Portable Executable Injection

Carbanak downloads an executable and injects it directly into a new process.

T1056.001
Keylogging

Carbanak logs key strokes for configured processes and sends them back to the C2 server.

T1057
Process Discovery

Carbanak lists running processes.

T1059.003
Windows Command Shell

Carbanak has a command to create a reverse shell.

T1070.004
File Deletion

Carbanak has a command to delete files.

T1071.001
Web Protocols

The Carbanak malware communicates to its command server using HTTP with an encrypted payload.

T1113
Screen Capture

Carbanak performs desktop video recording and captures screenshots of the desktop and sends it to the C2 server.

T1114.001
Local Email Collection

Carbanak searches recursively for Outlook personal storage tables (PST) files within user directories and sends them back to the C2 server.

T1132.001
Standard Encoding

Carbanak encodes the message body of HTTP traffic with Base64.

T1136.001
Local Account

Carbanak can create a Windows account.

View all 18 procedure examples

Groups that use it2

Campaigns0

None recorded.

References2

  1. FireEye CARBANAK June 2017 Open source
    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.
  2. Kaspersky Carbanak Open source
    Kaspersky Lab's Global Research and Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved August 23, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.