Description
Carberp is a credential and information stealing malware family active since at least 2009. Its source code leaked online in 2013, and other crews subsequently used it as the foundation for the Carbanak backdoor.
Stats
- First seen
- March 2022
- Last seen
- October 2026
MITRE ATT&CK techniques
25 techniques across 11 tactics.
TA0002 Execution
- T1106Native API
TA0004 Privilege Escalation
- T1068Exploitation for Privilege Escalation
TA0005 Stealth
TA0007 Discovery
TA0009 Collection
TA0011 Command and Control
TA0010 Exfiltration
- T1041Exfiltration Over C2 Channel
TA0112 Defense Impairment
- T1685Disable or Modify Tools
Alert name variants
| Alert Name |
|---|
| Gen:Variant.Carberp.1 |
| Gen:Variant.Carberp.5 |
| Win32.Downloader.Carberp |
| Win32.Infostealer.Carberp |
| Win32.Trojan.Carberp |
| Win64.Trojan.Carberp |