Netskope Threat Labs

Carberp

ATP Sandbox Adv. HeuristicsAV

Carberp is a credential and information stealing malware family active since at least 2009. Its source code leaked online in 2013, and other crews subsequently used it as the foundation for the Carbanak backdoor.

First seen
March 2022
Last seen
October 2026

25 techniques across 11 tactics.

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0004 Privilege Escalation

  • T1068Exploitation for Privilege Escalation

TA0005 Stealth

TA0006 Credential Access

  • T1555Credentials from Password Stores

TA0007 Discovery

TA0008 Lateral Movement

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel

TA0112 Defense Impairment

  • T1685Disable or Modify Tools
Alert Name
Gen:Variant.Carberp.1
Gen:Variant.Carberp.5
Win32.Downloader.Carberp
Win32.Infostealer.Carberp
Win32.Trojan.Carberp
Win64.Trojan.Carberp