Carberp is a Russian cybercrime group and associated banking malware ecosystem known for large-scale fraud operations against remote banking systems, particularly in Russia and Ukraine. The group was an early and prominent adopter of specialized malware for attacks on client-bank platforms and major Russian banks, and it remained active and technically adaptive even after arrests disrupted parts of the operation. Carberp is best known for targeting remote banking software rather than relying solely on generic web-injection approaches. Documented tradecraft includes code injection into trusted processes for defense evasion, runtime modification of Java bytecode in banking applications, and use of additional modules to manipulate payment workflows and bypass transaction protections. A notable capability involved targeting BIFIT iBank 2 by altering Java code at runtime, enabling on-the-fly modification of payment documents and attacker control over transactions. Reported functionality also included bypass of one-time-password protections in some workflows. The ecosystem also used remote-access tooling to support hands-on fraud operations. Carberp operators were reported to deploy both modified and unmodified legitimate remote administration software as backdoor components, complicating detection and enabling manual interaction with infected systems. Associated tooling such as RDPdoor was used to profile infected hosts and attached devices, with particular focus on smartcard devices used in Russian remote banking environments. Where suitable devices were present, operators could enable remote access to those devices and abuse operating-system-level smartcard interfaces to undermine transaction-signing protections. Known aliases and related components include AgentX.jar, detected as Java/Spy.Banker, and RDPdoor. Carberp has been described as one of the leading banking malware operations in the Russian region and a major source of banking fraud incidents affecting Russia and Ukraine.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a comparative cybercrime group known for banking malware with functionality to modify the JVM and track payment software activity, and described as a leading crime-market actor in Russia.
Banking malware/cybercrime activity focused on attacking client-bank systems and abusing smartcard devices in Russian remote banking environments, including collecting smartcard/device details and enabling remote smartcard control.
Financially motivated cybercrime group conducting banking fraud primarily against remote banking systems in Russia/Ukraine. Uses the Carberp malware ecosystem including droppers and Java components to modify banking client software (e.g., iBank2) at runtime, bypass OTP, and enable fraudulent transfers; also leverages legitimate remote-access tools (e.g., TeamViewer-derived components, Ammyy, Mipko) as backdoor/remote administration plugins for manual money transfers and access to infected hosts.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.