Carbanak, also known as Anunak and Sekur RAT, is a Windows remote-access backdoor initially derived from Carberp. It is associated with financially motivated intrusions by the Carbanak group and FIN7, but is not exclusive to either actor. Its deployment has supported attacks against banks and businesses in retail, restaurant, gambling, and hospitality industries, including operations targeting payment-card data.
Carbanak can obtain Windows logon password details, record keystrokes from configured processes, enumerate running processes, capture screenshots, and record desktop video. Captured keystrokes and desktop recordings can be transmitted to command-and-control infrastructure. It can also create local Windows accounts, enable concurrent Remote Desktop Protocol sessions, and delete files. It maintains persistence through Windows startup mechanisms that automatically execute commands after reboot. Its communications use Base64 encoding of HTTP message bodies, RC2 encryption in CBC mode, and XOR with random keys.
FIN7 has deployed adapted versions of Carbanak following targeted phishing emails with malicious attachments, sometimes reinforced by telephone calls to make the messages appear legitimate. Carbanak has also been executed through the POWERTRASH loader. Its remote-access, credential-theft, and surveillance functions support post-compromise access and financially motivated theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
While the code in the different families – Carbanak (Win32/Spy.Sekur), Win32/Spy.Agent.ORM, and Win32/Wemosis – is different it does contain similar traits, including the same digital certificate.
[T1190] CVE-2017-5638 (Apache Struts) Technique Élévation de privilèges sur un système d’exploitation Linux.
While the code in the different families – Carbanak (Win32/Spy.Sekur), Win32/Spy.Agent.ORM, and Win32/Wemosis – is different it does contain similar traits, including the same digital certificate.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Carbanak (aka Anunak, Sekur RAT) is also used for a remote backdoor (initially based on Carberp) that was used by Carbanak group until 2016.
The malware most commonly associated with FIN7 is the Carbanak family ... The Carbanak malware is not, however, exclusive to FIN7.
CTU researchers assess with moderate confidence that GOLD KINGSWOOD is associated with, and may be a progression of the group referred to as Carbanak that has targeted banks in Russia and Ukraine since early 2014.
An alleged FIN7 campaign, tracked as UNC4536 and UNC3319 by Mandiant, that distributed NetSupport RAT, possibly followed by DiceLoader or Carbanak.
An alleged FIN7 campaign, tracked as UNC4536 and UNC3319 by Mandiant, that distributed NetSupport RAT, possibly followed by DiceLoader or Carbanak.
Evil Corp aurait, d’après Blueliv, propagé d’autres codes malveillants ... mais aussi Carbanak.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
Adversaries may create a local account to maintain access to victim systems. ... Such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
61 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
124 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a possible follow-on payload in a separate FIN7-linked campaign.
Annotations ID Technique Tactic T1078 Valid Accounts Initial Access T1098 Account Manipulation Persistence T1548.001 Setuid and Setgid Privilege Escalation Delivery Installation Exploitation ... Carbanak ...
A banking-focused backdoor/RAT used to infiltrate financial institutions, observe operator workflows, capture keystrokes and screen/video, move laterally, and enable ATM jackpotting, fraudulent transfers, and account-balance manipulation.
A historically significant financial intrusion toolkit/backdoor associated in the content with FIN7/Carbanak Group and major theft from financial institutions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.