Netskope Threat Labs

Carbanak

ATP Sandbox Adv. HeuristicsAV

Carbanak (a.k.a. Anunak) is a backdoor and trojan associated with the FIN7 threat group that targets financial institutions, retailers, and hospitality companies for espionage and financial theft. Operators use it to survey banking environments, capture credentials, and move to systems that process high value transactions, and campaigns have extracted sums estimated in the hundreds of millions of dollars. The group combines targeted phishing and infrastructure intrusions, and its tooling has evolved continuously since the family first surfaced in the mid 2010s.

First seen
March 2022
Last seen
October 2026
Anunak

18 techniques across 9 tactics.

TA0002 Execution

TA0003 Persistence

TA0005 Stealth

TA0006 Credential Access

  • T1003OS Credential Dumping

TA0007 Discovery

TA0008 Lateral Movement

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1030Data Transfer Size Limits
Alert Name
Document-OLE.Backdoor.Carbanak
Document-RTF.Trojan.Carbanak
Dump:Generic.CBL.Carbanak.1.FFFFFFFE
Generic.BAT.Carbanak.1.9985FA7D
Generic.CBL.Carbanak.1.7547EEA6
Generic.CBL.Carbanak.1.7776416C
Generic.CBL.Carbanak.1.C2C718C6
Generic.JVL.Carbanak.5.15FC9636
Generic.JVL.Carbanak.5.B075A8EE
Generic.JVL.Carbanak.5.DE7CD1C0