Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

Carbanak

Carbanak is a cybercriminal group that has used Carbanak malware to target financial institutions since at least 2013. Carbanak may be linked to groups tracked separately as Cobalt Group and FIN7 that have also used Carbanak malware.(Citation: Kaspersky Carbanak)(Citation: FireEye FIN7 April 2017)(Citation: Europol Cobalt Mar 2018)(Citation: Secureworks GOLD NIAGARA Threat Profile)(Citation: Secureworks GOLD KINGSWOOD Threat Profile)
ID: G0008
Associated Groups: Anunak
Version: 2.0
Created: 31 May 2017
Last Modified: 18 Oct 2021

Associated Group Descriptions

Name Description
Anunak (Citation: Fox-It Anunak Feb 2015)

Techniques Used

Domain ID Name Use
Enterprise T1543 .003 Create or Modify System Process: Windows Service

Carbanak malware installs itself as a service to provide persistence and SYSTEM privileges.(Citation: Kaspersky Carbanak)

Enterprise T1562 .004 Impair Defenses: Disable or Modify System Firewall

Carbanak may use netsh to add local firewall rule exceptions.(Citation: Group-IB Anunak)

Enterprise T1036 .004 Masquerading: Masquerade Task or Service

Carbanak has copied legitimate service names to use for malicious services.(Citation: Kaspersky Carbanak)

.005 Masquerading: Match Legitimate Name or Location

Carbanak has named malware "svchost.exe," which is the name of the Windows shared service host program.(Citation: Kaspersky Carbanak)

Enterprise T1588 .002 Obtain Capabilities: Tool

Carbanak has obtained and used open-source tools such as PsExec and Mimikatz.(Citation: Kaspersky Carbanak)

Enterprise T1218 .011 System Binary Proxy Execution: Rundll32

Carbanak installs VNC server software that executes through rundll32.(Citation: Kaspersky Carbanak)

Enterprise T1102 .002 Web Service: Bidirectional Communication

Carbanak has used a VBScript named "ggldr" that uses Google Apps Script, Sheets, and Forms services for C2.(Citation: Forcepoint Carbanak Google C2)