S0484: Carberp
Security context for executives and security teams
Carberp matters because it represents Windows credential and information-stealing malware with a broad set of behaviors tied to discovery, credential access, stealth, persistence, command and control, lateral movement, and exfiltration. For leaders, the decision value is not just the malware name; it is whether the organization can prove it would notice credential theft from browsers or password stores, suspicious registry persistence, process injection, hidden components, remote control activity, and data leaving over web-based command channels.
Executive priority
Prioritize Carberp-relevant controls where Windows endpoints handle sensitive credentials, financial workflows, privileged access, or regulated data. The ATT&CK relationships point to business risks around identity compromise, persistence below normal visibility layers, remote access via VNC, and exfiltration over command-and-control channels. Executives should ask whether SOC, IR, endpoint, identity, and network teams have evidence for: Windows registry changes, credential-store access, browser-session abuse, process injection, web C2 traffic, and full remediation when rootkit or bootkit behavior is suspected.
Technical view
Carberp is documented by ATT&CK as Windows credential and information-stealing malware active since at least 2009, with source code leaked in 2013 and later used as a foundation for Carbanak. No official ATT&CK detection text is provided, so validation should be relationship-driven. SOC and IR teams should map detections and collection against the listed techniques: Query Registry, Rootkit, VNC, Encrypted/Encoded File, Match Legitimate Resource Name or Location, Exfiltration Over C2 Channel, DLL Injection, APC Injection, Credential API Hooking, Process Discovery, Exploitation for Privilege Escalation, Web Protocols, System Information Discovery, Ingress Tool Transfer, Native API, Screen Capture, Browser Session Hijacking, Virtualization/Sandbox Evasion, Security Software Discovery, Bootkit, Registry Run Keys / Startup Folder, Credentials from Password Stores, Credentials from Web Browsers, and Hidden Files and Directories.
Likely telemetry
- Windows endpoint process creation, command-line, parent-child process, and module/DLL load telemetry
- Windows Registry access and modification events, especially Run keys and suspicious resource names or locations
- Endpoint detection telemetry for process injection, API hooking, native API use, hidden files, rootkit indicators, and boot-level persistence indicators
- Browser and credential-store access evidence where available, including attempts to read saved browser credentials or interact with credential APIs
- Network telemetry for HTTP/S or other web-protocol command-and-control patterns and exfiltration over existing C2 channels
Detection direction
- Because ATT&CK provides no official detection guidance for this malware entry, validate coverage by technique rather than by malware name alone.
- Tune Windows detections for registry persistence, registry querying, startup-folder abuse, and suspicious resources that imitate legitimate names or locations.
- Correlate credential-access signals with process injection or browser interaction, especially activity involving credential stores, web browsers, or API hooking behavior.
- Review web-protocol traffic for unusual beaconing, tool transfer, or exfiltration patterns, but account for false positives because HTTP/S is common business traffic.
- Validate visibility for VNC use and distinguish approved remote support activity from unexpected remote control paths.
Mitigation priorities
- Start with identity and credential protection: reduce saved browser/password-store credential exposure, harden privileged accounts, and monitor credential access paths.
- Harden Windows persistence locations, including Registry Run keys and startup folders, with change monitoring and least-privilege administration.
- Improve endpoint prevention and detection for process injection, API hooking, hidden files, suspicious DLL loading, and unauthorized native API behavior.
- Restrict and monitor remote-control tools such as VNC, allowing only approved administrative use with authentication, logging, and network controls.
- Strengthen egress monitoring for web-protocol C2 and exfiltration while maintaining business-aware allowlisting and anomaly review.
Additional notes and limits
The object is a malware entry for Carberp, external ID S0484, in the enterprise ATT&CK domain. The official description identifies it as credential and information-stealing malware for Windows and notes the 2013 source-code leak and relationship to Carbanak’s foundation. The most actionable content comes from the supplied technique relationships rather than from an ATT&CK detection section.
ATT&CK provides no official detection text, no aliases, and no malware-level tactics for this object in the supplied fields. The relationships describe behaviors associated with the malware, but local telemetry, control configuration, approved administrative tooling, and environment-specific baselines are required to determine actual detection or exposure. This summary does not assert active exploitation, attribution, or guaranteed coverage.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Carberp
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(1)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.1 | 1.2 | Current bundle | fb5aea22ca97… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Trend Micro Carberp February 2014
Trend Micro. (2014, February 27). CARBERP. Retrieved July 29, 2020.
Open source URL - [2]KasperskyCarbanak
Kaspersky Lab's Global Research & Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved March 27, 2017.
Open source URL - [3]RSA Carbanak November 2017
RSA. (2017, November 21). THE CARBANAK/FIN7 SYNDICATE A HISTORICAL OVERVIEW OF AN EVOLVING THREAT. Retrieved July 29, 2020.
Open source URL - [4]ESET Carberp March 2012
Matrosov, A., Rodionov, E., Volkov, D., Harley, D. (2012, March 2). Win32/Carberp When You’re in a Black Hole, Stop Digging. Retrieved July 15, 2020.
Open source URL - [5]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [6]Trusteer Carberp October 2010
Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.
Open source URL - [7]KasperskyCarbanak
Kaspersky Lab's Global Research & Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved March 27, 2017.
Open source URL - [8]KasperskyCarbanak
Kaspersky Lab's Global Research & Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved March 27, 2017.
Open source URL - [9]RSA Carbanak November 2017
RSA. (2017, November 21). THE CARBANAK/FIN7 SYNDICATE A HISTORICAL OVERVIEW OF AN EVOLVING THREAT. Retrieved July 29, 2020.
Open source URL - [10]RSA Carbanak November 2017
RSA. (2017, November 21). THE CARBANAK/FIN7 SYNDICATE A HISTORICAL OVERVIEW OF AN EVOLVING THREAT. Retrieved July 29, 2020.
Open source URL - [11]Trend Micro Carberp February 2014
Trend Micro. (2014, February 27). CARBERP. Retrieved July 29, 2020.
Open source URL - [12]Trend Micro Carberp February 2014
Trend Micro. (2014, February 27). CARBERP. Retrieved July 29, 2020.
Open source URL - [13]mitre-attackS0484Open source URL
- [14]mitre-attackS0484Open source URL
- [15]mitre-attackS0484Open source URL
- [16]ESET Carberp March 2012
Matrosov, A., Rodionov, E., Volkov, D., Harley, D. (2012, March 2). Win32/Carberp When You’re in a Black Hole, Stop Digging. Retrieved July 15, 2020.
Open source URL - [17]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [18]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [19]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [20]Trusteer Carberp October 2010
Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.
Open source URL - [21]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [22]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [23]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [24]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [25]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [26]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [27]ESET Carberp March 2012
Matrosov, A., Rodionov, E., Volkov, D., Harley, D. (2012, March 2). Win32/Carberp When You’re in a Black Hole, Stop Digging. Retrieved July 15, 2020.
Open source URL - [28]ESET Carberp March 2012
Matrosov, A., Rodionov, E., Volkov, D., Harley, D. (2012, March 2). Win32/Carberp When You’re in a Black Hole, Stop Digging. Retrieved July 15, 2020.
Open source URL - [29]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [30]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [31]Trusteer Carberp October 2010
Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.
Open source URL - [32]Trusteer Carberp October 2010
Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.
Open source URL - [33]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [34]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [35]Trusteer Carberp October 2010
Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.
Open source URL - [36]Trusteer Carberp October 2010
Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.
Open source URL - [37]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [38]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [39]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [40]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [41]Trusteer Carberp October 2010
Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.
Open source URL - [42]Trusteer Carberp October 2010
Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.
Open source URL - [43]ESET Carberp March 2012
Matrosov, A., Rodionov, E., Volkov, D., Harley, D. (2012, March 2). Win32/Carberp When You’re in a Black Hole, Stop Digging. Retrieved July 15, 2020.
Open source URL - [44]ESET Carberp March 2012
Matrosov, A., Rodionov, E., Volkov, D., Harley, D. (2012, March 2). Win32/Carberp When You’re in a Black Hole, Stop Digging. Retrieved July 15, 2020.
Open source URL - [45]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [46]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [47]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [48]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [49]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [50]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [51]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [52]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [53]Trusteer Carberp October 2010
Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.
Open source URL - [54]Trusteer Carberp October 2010
Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.
Open source URL - [55]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [56]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [57]Trusteer Carberp October 2010
Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.
Open source URL - [58]Trusteer Carberp October 2010
Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.
Open source URL - [59]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [60]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [61]Trusteer Carberp October 2010
Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.
Open source URL - [62]Trusteer Carberp October 2010
Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.
Open source URL - [63]ESET Carberp March 2012
Matrosov, A., Rodionov, E., Volkov, D., Harley, D. (2012, March 2). Win32/Carberp When You’re in a Black Hole, Stop Digging. Retrieved July 15, 2020.
Open source URL - [64]ESET Carberp March 2012
Matrosov, A., Rodionov, E., Volkov, D., Harley, D. (2012, March 2). Win32/Carberp When You’re in a Black Hole, Stop Digging. Retrieved July 15, 2020.
Open source URL - [65]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [66]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL - [67]Trusteer Carberp October 2010
Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.
Open source URL - [68]Prevx Carberp March 2011
Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.
Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
