The Carbanak financial APT group made the headlines when Group-IB and Fox-IT broke the newsin December 2014, followed by the Kaspersky report in February 2015. The two reports describe the same cybercriminal gang which stole up to several hundreds of millions of dollars from various financial institutions.
However, the story is interesting not only because of the large amount of money stolen but also from a technical point of view. The Carbanak team does not just blindly compromise large numbers of computers and try to ‘milk the cow’ as other actors do, instead they act like a mature APT-group. They only compromise specific high-value targets and once inside the company networks, move laterally to hosts that can be monetized.
Carbanak gang is back and packing new guns
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.