Carbanak, also tracked as Anunak and sometimes referred to as the Carbanak Group, is a financially motivated cybercrime threat actor and associated intrusion cluster known for large-scale attacks against banks, payment processors, e-payment systems, card-processing environments, and other financial institutions worldwide. The activity emerged around 2013 under the Anunak name and became widely known as Carbanak in 2015. The malware and tradecraft lineage later overlapped with or evolved into activity tracked as Cobalt or Cobalt Group, and reporting has also noted links or overlap with broader FIN7/Carbanak clustering in some cases. Carbanak is notable for shifting bank fraud from customer-focused theft to direct compromise of financial institutions’ internal operations. Rather than stealing from end users, the operators infiltrated bank networks, compromised employee workstations, and spent extended periods observing internal procedures, operator workflows, approval chains, and payment operations. This reconnaissance enabled them to imitate legitimate administrative behavior and conduct fraudulent transactions with insider-like precision. Reported monetization methods included ATM cash-out operations, fraudulent interbank or electronic payment transfers, and manipulation of banking databases to inflate balances before withdrawing the fabricated funds. Initial access was commonly achieved through targeted spearphishing of bank employees, often using weaponized Office documents or other socially engineered attachments. After compromise, Carbanak deployed a remote-access backdoor derived in part from leaked Carberp code. The malware supported remote control, keylogging, screenshot capture, screen-video recording, and other surveillance functions that helped operators learn victim-specific processes before theft. Command and control has been observed over standard web protocols and, in some cases, through abuse of legitimate cloud services such as Google Apps Script, Google Sheets, and Google Forms. Operationally, Carbanak made extensive use of living-off-the-land and dual-use tooling. Reported techniques include execution through Rundll32, persistence via Windows services and scheduled tasks, credential theft using tools such as Mimikatz and ProcDump against LSASS, and lateral movement through RDP, SMB, PsExec, and other administrative mechanisms. The group also used legitimate remote-access software including TeamViewer and Ammyy Admin, and employed masquerading by naming malware after benign Windows processes. Service installation for persistence and SYSTEM-level execution has been a recurring characteristic. Victimology has centered on the financial sector, with campaigns affecting more than 100 institutions across over 40 countries and causing aggregate losses widely estimated in the hundreds of millions to roughly one billion US dollars. Activity has been especially prominent in Russia, Ukraine, the CIS, Europe, and Asia, though the targeting was international in scope. No credible evidence establishes Carbanak as a nation-state actor; it is best characterized as a sophisticated financially motivated criminal operation. Law-enforcement action in 2018 reportedly led to the arrest of an alleged mastermind associated with Carbanak and Cobalt activity, but the tooling and tradecraft did not disappear. More recent reporting indicates re-emergence of Carbanak backdoor activity in 2024 and 2025, likely reflecting continued reuse or revival of the malware family and associated techniques rather than definitive proof that the original operators fully returned.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated bank-heist operations against banks, e-payment systems, and other financial institutions using spearphishing, long dwell time, insider-like reconnaissance, ATM jackpotting, fraudulent transfers, and database balance manipulation.
Listed as an associated threat actor for exploitation activity related to abuse of the Windows Cloud Files API / cldapi.dll detection.
Listed as a threat actor associated with exploitation and privilege-escalation detection coverage for Windows admin password changes by non-admin users.
Listed in the detection annotations as a threat actor associated with exploitation for privilege escalation and Windows service persistence/installation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.