LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0484: Carberp

Carberp is a credential and information stealing malware that has been active since at least 2009. Carberp's source code was leaked online in 2013, and subsequently used as the foundation for the Carbanak backdoor.[1][2][3]

EnterpriseS0484MalwareObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Carberp matters because it represents Windows credential and information-stealing malware with a broad set of behaviors tied to discovery, credential access, stealth, persistence, command and control, lateral movement, and exfiltration. For leaders, the decision value is not just the malware name; it is whether the organization can prove it would notice credential theft from browsers or password stores, suspicious registry persistence, process injection, hidden components, remote control activity, and data leaving over web-based command channels.

Executive priority

Prioritize Carberp-relevant controls where Windows endpoints handle sensitive credentials, financial workflows, privileged access, or regulated data. The ATT&CK relationships point to business risks around identity compromise, persistence below normal visibility layers, remote access via VNC, and exfiltration over command-and-control channels. Executives should ask whether SOC, IR, endpoint, identity, and network teams have evidence for: Windows registry changes, credential-store access, browser-session abuse, process injection, web C2 traffic, and full remediation when rootkit or bootkit behavior is suspected.

Technical view

Carberp is documented by ATT&CK as Windows credential and information-stealing malware active since at least 2009, with source code leaked in 2013 and later used as a foundation for Carbanak. No official ATT&CK detection text is provided, so validation should be relationship-driven. SOC and IR teams should map detections and collection against the listed techniques: Query Registry, Rootkit, VNC, Encrypted/Encoded File, Match Legitimate Resource Name or Location, Exfiltration Over C2 Channel, DLL Injection, APC Injection, Credential API Hooking, Process Discovery, Exploitation for Privilege Escalation, Web Protocols, System Information Discovery, Ingress Tool Transfer, Native API, Screen Capture, Browser Session Hijacking, Virtualization/Sandbox Evasion, Security Software Discovery, Bootkit, Registry Run Keys / Startup Folder, Credentials from Password Stores, Credentials from Web Browsers, and Hidden Files and Directories.

Likely telemetry

  • Windows endpoint process creation, command-line, parent-child process, and module/DLL load telemetry
  • Windows Registry access and modification events, especially Run keys and suspicious resource names or locations
  • Endpoint detection telemetry for process injection, API hooking, native API use, hidden files, rootkit indicators, and boot-level persistence indicators
  • Browser and credential-store access evidence where available, including attempts to read saved browser credentials or interact with credential APIs
  • Network telemetry for HTTP/S or other web-protocol command-and-control patterns and exfiltration over existing C2 channels

Detection direction

  • Because ATT&CK provides no official detection guidance for this malware entry, validate coverage by technique rather than by malware name alone.
  • Tune Windows detections for registry persistence, registry querying, startup-folder abuse, and suspicious resources that imitate legitimate names or locations.
  • Correlate credential-access signals with process injection or browser interaction, especially activity involving credential stores, web browsers, or API hooking behavior.
  • Review web-protocol traffic for unusual beaconing, tool transfer, or exfiltration patterns, but account for false positives because HTTP/S is common business traffic.
  • Validate visibility for VNC use and distinguish approved remote support activity from unexpected remote control paths.

Mitigation priorities

  • Start with identity and credential protection: reduce saved browser/password-store credential exposure, harden privileged accounts, and monitor credential access paths.
  • Harden Windows persistence locations, including Registry Run keys and startup folders, with change monitoring and least-privilege administration.
  • Improve endpoint prevention and detection for process injection, API hooking, hidden files, suspicious DLL loading, and unauthorized native API behavior.
  • Restrict and monitor remote-control tools such as VNC, allowing only approved administrative use with authentication, logging, and network controls.
  • Strengthen egress monitoring for web-protocol C2 and exfiltration while maintaining business-aware allowlisting and anomaly review.
Additional notes and limits

The object is a malware entry for Carberp, external ID S0484, in the enterprise ATT&CK domain. The official description identifies it as credential and information-stealing malware for Windows and notes the 2013 source-code leak and relationship to Carbanak’s foundation. The most actionable content comes from the supplied technique relationships rather than from an ATT&CK detection section.

ATT&CK provides no official detection text, no aliases, and no malware-level tactics for this object in the supplied fields. The relationships describe behaviors associated with the malware, but local telemetry, control configuration, approved administrative tooling, and environment-specific baselines are required to determine actual detection or exposure. This summary does not assert active exploitation, attribution, or guaranteed coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Carberp

Carberp is a credential and information stealing malware that has been active since at least 2009. Carberp's source code was leaked online in 2013, and subsequently used as the foundation for the Carbanak backdoor.[1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

25 rows
DomainIDNameRelationship / procedure
EnterpriseT1542.003BootkitSub-technique

Carberp has installed a bootkit on the system to maintain persistence.[4]

EnterpriseT1555Credentials from Password Stores

Carberp's passw.plug plugin can gather account information from multiple instant messaging, email, and social media services, as well as FTP, VNC, and VPN clients.[5]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Carberp has masqueraded as Windows system file names, as well as "chkntfs.exe" and "syscron.exe".[5][6]

EnterpriseT1014Rootkit

Carberp has used user mode rootkit techniques to remain hidden on the system.[5]

EnterpriseT1056.004Credential API HookingSub-technique

Carberp has hooked several Windows API functions to steal credentials.[5]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

Carberp has maintained persistence by placing itself inside the current user's startup folder.[5]

EnterpriseT1497Virtualization/Sandbox Evasion

Carberp has removed various hooks before installing the trojan or bootkit to evade sandbox analysis or other analysis software.[4]

EnterpriseT1041Exfiltration Over C2 Channel

Carberp has exfiltrated data via HTTP to already established C2 servers.[5][6]

EnterpriseT1105Ingress Tool Transfer

Carberp can download and execute new plugins from the C2 server. [5][6]

EnterpriseT1021.005VNCSub-technique

Carberp can start a remote VNC session by downloading a new plugin.[5]

EnterpriseT1185Browser Session Hijacking

Carberp has captured credentials when a user performs login through a SSL session.[5][6]

EnterpriseT1068Exploitation for Privilege Escalation

Carberp has exploited multiple Windows vulnerabilities (CVE-2010-2743, CVE-2010-3338, CVE-2010-4398, CVE-2008-1084) and a .NET Runtime Optimization vulnerability for privilege escalation.[4][5]

EnterpriseT1055.004Asynchronous Procedure CallSub-technique

Carberp has queued an APC routine to explorer.exe by calling ZwQueueApcThread.[5]

EnterpriseT1518.001Security Software DiscoverySub-technique

Carberp has queried the infected system's registry searching for specific registry keys associated with antivirus products.[5]

EnterpriseT1012Query Registry

Carberp has searched the Image File Execution Options registry key for "Debugger" within every subkey.[5]

EnterpriseT1564.001Hidden Files and DirectoriesSub-technique

Carberp has created a hidden file in the Startup folder of the current user.[6]

EnterpriseT1685Disable or Modify Tools

Carberp has attempted to disable security software by creating a suspended process for the security software and injecting code to delete antivirus core files when the process is resumed.[5]

EnterpriseT1071.001Web ProtocolsSub-technique

Carberp has connected to C2 servers via HTTP.[6]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

Carberp has used XOR-based encryption to mask C2 server locations within the trojan.[5]

EnterpriseT1106Native API

Carberp has used the NtQueryDirectoryFile and ZwQueryDirectoryFile functions to hide files and directories.[6]

EnterpriseT1055.001Dynamic-link Library InjectionSub-technique

Carberp's bootkit can inject a malicious DLL into the address space of running processes.[4]

EnterpriseT1082System Information Discovery

Carberp has collected the operating system version from the infected system.[5]

EnterpriseT1113Screen Capture

Carberp can capture display screenshots with the screens_dll.dll plugin.[5]

EnterpriseT1057Process Discovery

Carberp has collected a list of running processes.[6]

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

Carberp's passw.plug plugin can gather passwords saved in Opera, Internet Explorer, Safari, Firefox, and Chrome.[5]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.2
Created
Modified
Raw hash
fb5aea22ca97ef5b...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.2Current bundlefb5aea22ca97…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Trend Micro Carberp February 2014

    Trend Micro. (2014, February 27). CARBERP. Retrieved July 29, 2020.

    Open source URL
  2. [2]
    KasperskyCarbanak

    Kaspersky Lab's Global Research & Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved March 27, 2017.

    Open source URL
  3. [3]
    RSA Carbanak November 2017

    RSA. (2017, November 21). THE CARBANAK/FIN7 SYNDICATE A HISTORICAL OVERVIEW OF AN EVOLVING THREAT. Retrieved July 29, 2020.

    Open source URL
  4. [4]
    ESET Carberp March 2012

    Matrosov, A., Rodionov, E., Volkov, D., Harley, D. (2012, March 2). Win32/Carberp When You’re in a Black Hole, Stop Digging. Retrieved July 15, 2020.

    Open source URL
  5. [5]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  6. [6]
    Trusteer Carberp October 2010

    Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.

    Open source URL
  7. [7]
    KasperskyCarbanak

    Kaspersky Lab's Global Research & Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved March 27, 2017.

    Open source URL
  8. [8]
    KasperskyCarbanak

    Kaspersky Lab's Global Research & Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved March 27, 2017.

    Open source URL
  9. [9]
    RSA Carbanak November 2017

    RSA. (2017, November 21). THE CARBANAK/FIN7 SYNDICATE A HISTORICAL OVERVIEW OF AN EVOLVING THREAT. Retrieved July 29, 2020.

    Open source URL
  10. [10]
    RSA Carbanak November 2017

    RSA. (2017, November 21). THE CARBANAK/FIN7 SYNDICATE A HISTORICAL OVERVIEW OF AN EVOLVING THREAT. Retrieved July 29, 2020.

    Open source URL
  11. [11]
    Trend Micro Carberp February 2014

    Trend Micro. (2014, February 27). CARBERP. Retrieved July 29, 2020.

    Open source URL
  12. [12]
    Trend Micro Carberp February 2014

    Trend Micro. (2014, February 27). CARBERP. Retrieved July 29, 2020.

    Open source URL
  13. [13]
    mitre-attackS0484
    Open source URL
  14. [14]
    mitre-attackS0484
    Open source URL
  15. [15]
    mitre-attackS0484
    Open source URL
  16. [16]
    ESET Carberp March 2012

    Matrosov, A., Rodionov, E., Volkov, D., Harley, D. (2012, March 2). Win32/Carberp When You’re in a Black Hole, Stop Digging. Retrieved July 15, 2020.

    Open source URL
  17. [17]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  18. [18]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  19. [19]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  20. [20]
    Trusteer Carberp October 2010

    Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.

    Open source URL
  21. [21]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  22. [22]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  23. [23]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  24. [24]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  25. [25]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  26. [26]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  27. [27]
    ESET Carberp March 2012

    Matrosov, A., Rodionov, E., Volkov, D., Harley, D. (2012, March 2). Win32/Carberp When You’re in a Black Hole, Stop Digging. Retrieved July 15, 2020.

    Open source URL
  28. [28]
    ESET Carberp March 2012

    Matrosov, A., Rodionov, E., Volkov, D., Harley, D. (2012, March 2). Win32/Carberp When You’re in a Black Hole, Stop Digging. Retrieved July 15, 2020.

    Open source URL
  29. [29]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  30. [30]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  31. [31]
    Trusteer Carberp October 2010

    Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.

    Open source URL
  32. [32]
    Trusteer Carberp October 2010

    Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.

    Open source URL
  33. [33]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  34. [34]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  35. [35]
    Trusteer Carberp October 2010

    Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.

    Open source URL
  36. [36]
    Trusteer Carberp October 2010

    Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.

    Open source URL
  37. [37]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  38. [38]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  39. [39]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  40. [40]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  41. [41]
    Trusteer Carberp October 2010

    Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.

    Open source URL
  42. [42]
    Trusteer Carberp October 2010

    Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.

    Open source URL
  43. [43]
    ESET Carberp March 2012

    Matrosov, A., Rodionov, E., Volkov, D., Harley, D. (2012, March 2). Win32/Carberp When You’re in a Black Hole, Stop Digging. Retrieved July 15, 2020.

    Open source URL
  44. [44]
    ESET Carberp March 2012

    Matrosov, A., Rodionov, E., Volkov, D., Harley, D. (2012, March 2). Win32/Carberp When You’re in a Black Hole, Stop Digging. Retrieved July 15, 2020.

    Open source URL
  45. [45]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  46. [46]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  47. [47]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  48. [48]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  49. [49]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  50. [50]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  51. [51]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  52. [52]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  53. [53]
    Trusteer Carberp October 2010

    Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.

    Open source URL
  54. [54]
    Trusteer Carberp October 2010

    Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.

    Open source URL
  55. [55]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  56. [56]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  57. [57]
    Trusteer Carberp October 2010

    Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.

    Open source URL
  58. [58]
    Trusteer Carberp October 2010

    Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.

    Open source URL
  59. [59]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  60. [60]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  61. [61]
    Trusteer Carberp October 2010

    Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.

    Open source URL
  62. [62]
    Trusteer Carberp October 2010

    Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.

    Open source URL
  63. [63]
    ESET Carberp March 2012

    Matrosov, A., Rodionov, E., Volkov, D., Harley, D. (2012, March 2). Win32/Carberp When You’re in a Black Hole, Stop Digging. Retrieved July 15, 2020.

    Open source URL
  64. [64]
    ESET Carberp March 2012

    Matrosov, A., Rodionov, E., Volkov, D., Harley, D. (2012, March 2). Win32/Carberp When You’re in a Black Hole, Stop Digging. Retrieved July 15, 2020.

    Open source URL
  65. [65]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  66. [66]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  67. [67]
    Trusteer Carberp October 2010

    Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.

    Open source URL
  68. [68]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.