KTAC005 is a suspected financially motivated cybercrime activity cluster tracked in connection with the deployment of CARBANAK/ANUNAK through IDATLOADER, also known as HIJACKLOADER and GHOSTPULSE. The cluster is assessed as potentially linked to the broader Carbanak ecosystem, a long-running set of interrelated financially motivated intrusion groups that includes activity commonly tracked alongside FIN7 and Cobalt Gang. The association is based on analysis of a recent CARBANAK/ANUNAK sample delivered via IDATLOADER and exhibiting CARBANAK-consistent functionality and internal references. Observed tradecraft includes use of a loader that stores payloads in PNG image data and can employ sideloading techniques, followed by delivery of a sophisticated remote access trojan through steganographic encapsulation. The CARBANAK/ANUNAK payload showed process and service enumeration, multithreaded execution, and named-pipe-based inter-thread communication, indicating mature post-compromise capability and defense-evasion-aware tooling. The broader Carbanak-linked ecosystem has historically conducted financially driven intrusions against large enterprises and has evolved from financial fraud and point-of-sale malware toward ransomware-aligned operations, including coordination with major ransomware families. Attribution of KTAC005 to established Carbanak-linked operators remains an assessment rather than a confirmed identification, because historical CARBANAK source-code leakage leaves open the possibility of third-party reuse. Even so, the use of a recent CARBANAK/ANUNAK variant and the sophistication of the tooling support tracking KTAC005 as a distinct suspected Carbanak-related cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.