Menu
Browse

Carbanak

Aliases: 2 aliases
Primary URL Location Industry
Undetermined
Country Russia
Financial Services Icon
Financial Services
Profile

Carbanak, also known as the Carbanak Gang, is a Russian-based cybercrime group that develops and deploys the Carbanak malware suite. The group’s primary activity involves conducting financially motivated intrusions against organizations in the retail, hospitality, and banking sectors. It gains initial access by exploiting vulnerabilities in vendor web portals and then uses the Carbanak malware, often in conjunction with the Dridex trojan, to establish persistence and harvest credentials. Once inside a network, the attackers harvest passwords, create backdoors, and exfiltrate sensitive data such as payment card information and customer contact details. Their operations are characterized by a focus on stealing financial assets and enabling further compromise of merchant networks.

In August 2016, Carbanak targeted multiple point‑of‑sale system providers, including Oracle’s MICROS unit and five other vendors, compromising their servers to steal retail customer credentials and gain remote access to payment systems. The incident resulted in the potential exposure of data from over a million POS terminals worldwide, illustrating the group’s global reach and impact. Prior to this campaign, the group had been linked to earlier intrusions that involved the exfiltration of credit card data from financial institutions. Carbanak’s distinguishing attributes include its specialization in financial theft, its reliance on custom malware (Carbanak) combined with established tools like Dridex, and its consistent focus on the retail and hospitality verticals. The group is headquartered in Russia, and no public information about its ownership or corporate structure is available in the provided sources.

Incidents
Linked incidents available to members
1 incident