SOC Incident Toolkit
Back to Campaigns
Domino Effect

Domino Effect

FIN7ContiTrickbotDominoloaderCarbanakCobalt StrikeDomino Loader

Former members of the Conti ransomware group use malware developed by the FIN7 group for financial purposes, compromising systems for follow-on exploits; FIN7 has used the "Domino" tool in its attacks since at least last October.

Indicators of Compromise

Domains (225)

jurisdictionient.comadvantagendum.combungalowphotographyblog.commainstreamology.comenpfereschemry.tkbloodshedize.comembarrassmentozoa.comstartmakingsenseofself.comcapermission.comparalyzedoary.comuncertaintology.comceremonal.comcorpily.comtreatmenthuse.comrefrigeratoraholic.comrevokeodoe.comfgfotr.comwww.prodaft.comhealingwithclarity.comimplicationious.com+205 more

Hashes (1322)

bb22e8eb9439e274bf5441ee708c78e78c4e5a1988dc7ad06a98cd3545c478e840c4dc04a080fbd24d0164b46567265b8186e03fcb2b8a38bd9b3ba60599e81ad06b23fcc87fbf82c945afb218b8333c056c1585db419539753e5aa4a9fa09c3894c0129123266fbd2b2c4db1648c0c699a6694312a446697c8b2519da9a10e86f7a5ceb9362f5ce196d0b045b36a7408ce2590d9354e221fa48886d8ee5afb7a04dfae8271de627a07ea2b60dc8e381d74a283f9bee0a871007fa92e2036997d17b1d8528ec37919c3c4d61b8fdbf135cabc4e2868f3ed1a7c0b437944e1e204416221b2667144e114d03937c55822a0e5a7d5b2c4a03db0c4e0e5861c0e952b940f191be767643f7ef81b89dc00f32f58c61bda2867fd5c5aefefacffc5d0fa06833f8df22a80485e24f4d9f55967362ec5544d37d49ab9cef449358684f3f9d99768cb5526783598c0c0c5a1145d88157539c61b135f80111e945c4fbafdc5bfdb86ff5f42a3334c8f87a8e70749d3fe20f5c806d19665f7abd9079b2df16039566d53ed3347e42dd3e957557c7979bcb8259a2a535cb5eb91af699b02a79e91b41a8d0aecbd358bfbc32de4a30857f4361fe723bb40ea96f61366e21a92d0e59a06ad2089b63794398f33752fd5176b80b1caae3573db89c0c18efe86d6d2566e0536019c1715ece7ddfeef8aaa35a53211bbeea5e2f19704729ab11985dc4304a04aa3581cfc762f9ef26c3f44bc58aa7860c981f988ca66154373c3f8afd8ccf0550df292104ff956a4f24882d4ac9897d418ea3d73864e9ded58610bc387a55fdc9d9afb362066dfeb2cd1652f1c268bacb3879a836ec05226465b70bad27c24f2d0d5b0abd9b7fe2bbad4822+1302 more

IPv4 (413)

45.87.154.208176.103.63.10494.156.189.87185.205.210.2337.252.4.131109.234.38.249194.104.136.182193.37.212.185195.2.92.62185.16.40.6794.158.244.200109.234.34.196162.241.225.216193.187.175.21374.118.139.1323.225.195.20109.234.37.28213.32.39.47185.217.1.23162.248.227.53+393 more

CVEs (19)

CVE-2021-3156CVE-2021-42321CVE-2020-0688CVE-2017-0199CVE-2021-34523CVE-2021-40539CVE-2021-31207CVE-2021-42278CVE-2022-22954CVE-2021-34473CVE-2021-26855CVE-2016-0099CVE-2021-44228CVE-2021-42287CVE-2022-30190CVE-2020-1472CVE-2021-26858CVE-2021-34527CVE-2021-26857

APT Groups

FIN7

Notes

<b>Conclusions</b><div>FIN7 is an enemy worth dealing with, with concessions ending in losses of up to a billion dollars. While this foe is dangerous, the basic security hygiene outlined by both the NIST and CIS frameworks can reduce storage in the actor's environment, as well as the average time required for detection and mitigation from them. In addition, knowledge of group tools, tactics, and operations allows defenders to more effectively predict the actions of attackers and address their outlines and threats to your organization.</div>

Mitigation

<div><b><font>Carbanak</font></b></div><div>Carbanak is a cybercriminal group that has used Carbanak malware to target financial institutions since at least 2013. Carbanak may be linked to groups tracked separately as Cobalt Group and FIN7 that have also used Carbanak malware.[1][2][3][4][5]</div><div><br></div><div><b style="font-family: Mazzard; color: rgb(57, 67, 76);"><font>Associated Group Descriptions</font></b><br></div><div><table class="table table-bordered table-alternate mt-2" style="box-sizing: border-box; border-collapse: collapse; width: 1367.25px; margin-bottom: 1rem; color: rgb(33, 37, 41); border: 1px solid rgb(223, 223, 223); empty-cells: hide; font-family: Roboto-Regular, sans-serif; font-size: 16px; margin-top: 0.5rem !important; background-color: rgb(242, 242, 242) !important;"><thead style="box-sizing: border-box;"><tr style="box-sizing: border-box;"><th style="box-sizing: border-box; text-align: inherit; padding: 0.6rem; vertical-align: bottom; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(223, 223, 223) rgb(223, 223, 223) rgb(222, 226, 230); border-image: initial; font-size: 0.9rem;">Name</th><th style="box-sizing: border-box; text-align: inherit; padding: 0.6rem; vertical-align: bottom; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(223, 223, 223) rgb(223, 223, 223) rgb(222, 226, 230); border-image: initial; font-size: 0.9rem;">Description</th></tr></thead><tbody style="box-sizing: border-box; background: white; color: rgb(57, 67, 76);"><tr style="box-sizing: border-box;"><td style="box-sizing: border-box; padding: 0.75rem; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><font>Anunak</font></td><td style="box-sizing: border-box; padding: 0.75rem; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><p style="box-sizing: border-box; margin-bottom: 0px;"><span id="scite-ref-6-a" class="scite-citeref-number" style="box-sizing: border-box;"><span style="box-sizing: border-box; position: relative; font-size: 12px; line-height: 0; vertical-align: baseline; top: -0.5em;"><a href="https://www.fox-it.com/en/news/blog/anunak-aka-carbanak-update/" target="_blank" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">[6]</a></span></span></p></td></tr></tbody></table><div style="box-sizing: border-box; margin-top: 0px; line-height: 1.2; color: rgb(57, 67, 76); margin-bottom: 0.5rem !important; padding-top: 1rem !important;"><b>Techniques Used</b></div><table class="table techniques-used background table-bordered" style="box-sizing: border-box; border-collapse: collapse; width: 1367.25px; margin-bottom: 1rem; color: rgb(33, 37, 41); border: 1px solid rgb(223, 223, 223); empty-cells: hide; font-family: Roboto-Regular, sans-serif; font-size: 16px;"><thead style="box-sizing: border-box;"><tr style="box-sizing: border-box; border-bottom: 2px solid rgb(222, 226, 230); background: rgb(242, 242, 242);"><th class="p-2" style="box-sizing: border-box; text-align: inherit; padding: 0.6rem; vertical-align: bottom; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(223, 223, 223) rgb(223, 223, 223) rgb(222, 226, 230); border-image: initial; font-size: 0.9rem;">Domain</th><th class="p-2" style="box-sizing: border-box; text-align: inherit; padding: 0.6rem; vertical-align: bottom; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(223, 223, 223) rgb(223, 223, 223) rgb(222, 226, 230); border-image: initial; font-size: 0.9rem;">ID</th><th class="p-2" style="box-sizing: border-box; text-align: inherit; padding: 0.6rem; vertical-align: bottom; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(223, 223, 223) rgb(223, 223, 223) rgb(222, 226, 230); border-image: initial; font-size: 0.9rem;">Name</th><th class="p-2" style="box-sizing: border-box; text-align: inherit; padding: 0.6rem; vertical-align: bottom; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(223, 223, 223) rgb(223, 223, 223) rgb(222, 226, 230); border-image: initial; font-size: 0.9rem;">Use</th></tr></thead><tbody style="box-sizing: border-box;"><tr class="sub technique noparent enterprise" id="enterprise" style="box-sizing: border-box; border-left: none;"><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border-top: 1px solid rgb(223, 223, 223); border-right: 1px solid rgb(223, 223, 223); border-bottom: none; border-left: 1px solid rgb(223, 223, 223); border-image: initial;">Enterprise</td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border-top: 1px solid rgb(223, 223, 223); border-right: 1px solid rgb(223, 223, 223); border-bottom: none; border-left: 1px solid rgb(223, 223, 223); border-image: initial;"><a href="https://attack.mitre.org/techniques/T1543" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">T1543</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/techniques/T1543/003" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">.003</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/techniques/T1543" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Create or Modify System Process</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1543/003" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Windows Service</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><p style="box-sizing: border-box; margin-bottom: 0px;"><a href="https://attack.mitre.org/groups/G0008" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Carbanak</a>&nbsp;malware installs itself as a service to provide persistence and SYSTEM privileges.<span id="scite-ref-1-a" class="scite-citeref-number" style="box-sizing: border-box;"><span style="box-sizing: border-box; position: relative; font-size: 12px; line-height: 0; vertical-align: baseline; top: -0.5em;"><a href="https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/08064518/Carbanak_APT_eng.pdf" target="_blank" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">[1]</a></span></span></p></td></tr><tr class="sub technique noparent enterprise" id="enterprise" style="box-sizing: border-box; border-left: none;"><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border-top: 1px solid rgb(223, 223, 223); border-right: 1px solid rgb(223, 223, 223); border-bottom: none; border-left: 1px solid rgb(223, 223, 223); border-image: initial;">Enterprise</td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border-top: 1px solid rgb(223, 223, 223); border-right: 1px solid rgb(223, 223, 223); border-bottom: none; border-left: 1px solid rgb(223, 223, 223); border-image: initial;"><a href="https://attack.mitre.org/techniques/T1562" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">T1562</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/techniques/T1562/004" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">.004</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/techniques/T1562" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Impair Defenses</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1562/004" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Disable or Modify System Firewall</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><p style="box-sizing: border-box; margin-bottom: 0px;"><a href="https://attack.mitre.org/groups/G0008" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Carbanak</a>&nbsp;may use&nbsp;<a href="https://attack.mitre.org/software/S0108" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">netsh</a>&nbsp;to add local firewall rule exceptions.<span id="scite-ref-7-a" class="scite-citeref-number" style="box-sizing: border-box;"><span style="box-sizing: border-box; position: relative; font-size: 12px; line-height: 0; vertical-align: baseline; top: -0.5em;"><a href="http://www.group-ib.com/files/Anunak_APT_against_financial_institutions.pdf" target="_blank" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">[7]</a></span></span></p></td></tr><tr class="sub technique noparent enterprise" id="enterprise" style="box-sizing: border-box; border-left: none;"><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border-top: 1px solid rgb(223, 223, 223); border-right: 1px solid rgb(223, 223, 223); border-bottom: none; border-left: 1px solid rgb(223, 223, 223); border-image: initial;">Enterprise</td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border-top: 1px solid rgb(223, 223, 223); border-right: 1px solid rgb(223, 223, 223); border-bottom: none; border-left: 1px solid rgb(223, 223, 223); border-image: initial;"><a href="https://attack.mitre.org/techniques/T1036" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">T1036</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/techniques/T1036/004" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">.004</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/techniques/T1036" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Masquerading</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1036/004" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Masquerade Task or Service</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><p style="box-sizing: border-box; margin-bottom: 0px;"><a href="https://attack.mitre.org/groups/G0008" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Carbanak</a>&nbsp;has copied legitimate service names to use for malicious services.<span id="scite-ref-1-a" class="scite-citeref-number" style="box-sizing: border-box;"><span style="box-sizing: border-box; position: relative; font-size: 12px; line-height: 0; vertical-align: baseline; top: -0.5em;"><a href="https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/08064518/Carbanak_APT_eng.pdf" target="_blank" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">[1]</a></span></span></p></td></tr><tr class="sub technique enterprise" id="enterprise" style="box-sizing: border-box; border-left: none;"><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border-top: none; border-right: 1px solid rgb(223, 223, 223); border-bottom: none; border-left: 1px solid rgb(223, 223, 223); border-image: initial; width: 5ex;"></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border-top: none; border-right: 1px solid rgb(223, 223, 223); border-bottom: none; border-left: 1px solid rgb(223, 223, 223); border-image: initial; width: 5ex;"></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/techniques/T1036/005" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">.005</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/techniques/T1036" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Masquerading</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1036/005" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Match Legitimate Name or Location</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><p style="box-sizing: border-box; margin-bottom: 0px;"><a href="https://attack.mitre.org/groups/G0008" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Carbanak</a>&nbsp;has named malware "svchost.exe," which is the name of the Windows shared service host program.<span id="scite-ref-1-a" class="scite-citeref-number" style="box-sizing: border-box;"><span style="box-sizing: border-box; position: relative; font-size: 12px; line-height: 0; vertical-align: baseline; top: -0.5em;"><a href="https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/08064518/Carbanak_APT_eng.pdf" target="_blank" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">[1]</a></span></span></p></td></tr><tr class="sub technique noparent enterprise" id="enterprise" style="box-sizing: border-box; border-left: none;"><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border-top: 1px solid rgb(223, 223, 223); border-right: 1px solid rgb(223, 223, 223); border-bottom: none; border-left: 1px solid rgb(223, 223, 223); border-image: initial;">Enterprise</td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border-top: 1px solid rgb(223, 223, 223); border-right: 1px solid rgb(223, 223, 223); border-bottom: none; border-left: 1px solid rgb(223, 223, 223); border-image: initial;"><a href="https://attack.mitre.org/techniques/T1588" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">T1588</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/techniques/T1588/002" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">.002</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/techniques/T1588" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Obtain Capabilities</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1588/002" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Tool</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><p style="box-sizing: border-box; margin-bottom: 0px;"><a href="https://attack.mitre.org/groups/G0008" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Carbanak</a>&nbsp;has obtained and used open-source tools such as&nbsp;<a href="https://attack.mitre.org/software/S0029" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">PsExec</a>&nbsp;and&nbsp;<a href="https://attack.mitre.org/software/S0002" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Mimikatz</a>.<span id="scite-ref-1-a" class="scite-citeref-number" style="box-sizing: border-box;"><span style="box-sizing: border-box; position: relative; font-size: 12px; line-height: 0; vertical-align: baseline; top: -0.5em;"><a href="https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/08064518/Carbanak_APT_eng.pdf" target="_blank" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">[1]</a></span></span></p></td></tr><tr class="technique enterprise" id="enterprise" style="box-sizing: border-box;"><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border-top: 1px solid rgb(223, 223, 223); border-right: 1px solid rgb(223, 223, 223); border-bottom: none; border-left: 1px solid rgb(223, 223, 223); border-image: initial;">Enterprise</td><td colspan="2" style="box-sizing: border-box; padding: 10px; vertical-align: top; border-top: 1px solid rgb(223, 223, 223); border-right: 1px solid rgb(223, 223, 223); border-bottom: none; border-left: 1px solid rgb(223, 223, 223); border-image: initial;"><a href="https://attack.mitre.org/techniques/T1219" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">T1219</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/techniques/T1219" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Remote Access Software</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><p style="box-sizing: border-box; margin-bottom: 0px;"><a href="https://attack.mitre.org/groups/G0008" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Carbanak</a>&nbsp;used legitimate programs such as AmmyyAdmin and Team Viewer for remote interactive C2 to target systems.<span id="scite-ref-7-a" class="scite-citeref-number" style="box-sizing: border-box;"><span style="box-sizing: border-box; position: relative; font-size: 12px; line-height: 0; vertical-align: baseline; top: -0.5em;"><a href="http://www.group-ib.com/files/Anunak_APT_against_financial_institutions.pdf" target="_blank" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">[7]</a></span></span></p></td></tr><tr class="sub technique noparent enterprise" id="enterprise" style="box-sizing: border-box; border-left: none;"><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border-top: 1px solid rgb(223, 223, 223); border-right: 1px solid rgb(223, 223, 223); border-bottom: none; border-left: 1px solid rgb(223, 223, 223); border-image: initial;">Enterprise</td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border-top: 1px solid rgb(223, 223, 223); border-right: 1px solid rgb(223, 223, 223); border-bottom: none; border-left: 1px solid rgb(223, 223, 223); border-image: initial;"><a href="https://attack.mitre.org/techniques/T1218" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">T1218</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/techniques/T1218/011" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">.011</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/techniques/T1218" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">System Binary Proxy Execution</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1218/011" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Rundll32</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><p style="box-sizing: border-box; margin-bottom: 0px;"><a href="https://attack.mitre.org/groups/G0008" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Carbanak</a>&nbsp;installs VNC server software that executes through rundll32.<span id="scite-ref-1-a" class="scite-citeref-number" style="box-sizing: border-box;"><span style="box-sizing: border-box; position: relative; font-size: 12px; line-height: 0; vertical-align: baseline; top: -0.5em;"><a href="https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/08064518/Carbanak_APT_eng.pdf" target="_blank" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">[1]</a></span></span></p></td></tr><tr class="technique enterprise" id="enterprise" style="box-sizing: border-box;"><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border-top: 1px solid rgb(223, 223, 223); border-right: 1px solid rgb(223, 223, 223); border-bottom: none; border-left: 1px solid rgb(223, 223, 223); border-image: initial;">Enterprise</td><td colspan="2" style="box-sizing: border-box; padding: 10px; vertical-align: top; border-top: 1px solid rgb(223, 223, 223); border-right: 1px solid rgb(223, 223, 223); border-bottom: none; border-left: 1px solid rgb(223, 223, 223); border-image: initial;"><a href="https://attack.mitre.org/techniques/T1078" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">T1078</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/techniques/T1078" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Valid Accounts</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><p style="box-sizing: border-box; margin-bottom: 0px;"><a href="https://attack.mitre.org/groups/G0008" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Carbanak</a>&nbsp;actors used legitimate credentials of banking employees to perform operations that sent them millions of dollars.<span id="scite-ref-1-a" class="scite-citeref-number" style="box-sizing: border-box;"><span style="box-sizing: border-box; position: relative; font-size: 12px; line-height: 0; vertical-align: baseline; top: -0.5em;"><a href="https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/08064518/Carbanak_APT_eng.pdf" target="_blank" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">[1]</a></span></span></p></td></tr><tr class="sub technique noparent enterprise" id="enterprise" style="box-sizing: border-box; border-bottom: 1px solid rgb(223, 223, 223); border-left: none;"><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border-top: 1px solid rgb(223, 223, 223); border-right: 1px solid rgb(223, 223, 223); border-bottom: none; border-left: 1px solid rgb(223, 223, 223); border-image: initial;">Enterprise</td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border-top: 1px solid rgb(223, 223, 223); border-right: 1px solid rgb(223, 223, 223); border-bottom: none; border-left: 1px solid rgb(223, 223, 223); border-image: initial;"><a href="https://attack.mitre.org/techniques/T1102" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">T1102</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/techniques/T1102/002" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">.002</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/techniques/T1102" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Web Service</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1102/002" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Bidirectional Communication</a></td><td style="box-sizing: border-box; padding: 10px; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><p style="box-sizing: border-box; margin-bottom: 0px;"><a href="https://attack.mitre.org/groups/G0008" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Carbanak</a>&nbsp;has used a VBScript named "ggldr" that uses Google Apps Script, Sheets, and Forms services for C2.<span id="scite-ref-8-a" class="scite-citeref-number" style="box-sizing: border-box;"><span style="box-sizing: border-box; position: relative; font-size: 12px; line-height: 0; vertical-align: baseline; top: -0.5em;"><a href="https://blogs.forcepoint.com/security-labs/carbanak-group-uses-google-malware-command-and-control" target="_blank" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">[8]</a></span></span></p></td></tr></tbody></table><div style="box-sizing: border-box; margin-top: 0px; margin-bottom: 0.5rem; line-height: 1.2; color: rgb(57, 67, 76); padding-top: 1rem !important;"><b><font>Software</font></b></div></div><div style="box-sizing: border-box; margin-top: 0px; margin-bottom: 0.5rem; line-height: 1.2; color: rgb(57, 67, 76); padding-top: 1rem !important;"><table class="table table-bordered table-alternate mt-2" style="box-sizing: border-box; border-collapse: collapse; width: 1367.25px; margin-bottom: 1rem; color: rgb(33, 37, 41); border: 1px solid rgb(223, 223, 223); empty-cells: hide; font-family: Roboto-Regular, sans-serif; font-size: 16px; margin-top: 0.5rem !important; background-color: rgb(242, 242, 242) !important;"><thead style="box-sizing: border-box;"><tr style="box-sizing: border-box;"><th style="box-sizing: border-box; text-align: inherit; padding: 0.6rem; vertical-align: bottom; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(223, 223, 223) rgb(223, 223, 223) rgb(222, 226, 230); border-image: initial; font-size: 0.9rem;">ID</th><th style="box-sizing: border-box; text-align: inherit; padding: 0.6rem; vertical-align: bottom; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(223, 223, 223) rgb(223, 223, 223) rgb(222, 226, 230); border-image: initial; font-size: 0.9rem;">Name</th><th style="box-sizing: border-box; text-align: inherit; padding: 0.6rem; vertical-align: bottom; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(223, 223, 223) rgb(223, 223, 223) rgb(222, 226, 230); border-image: initial; font-size: 0.9rem;">References</th><th style="box-sizing: border-box; text-align: inherit; padding: 0.6rem; vertical-align: bottom; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(223, 223, 223) rgb(223, 223, 223) rgb(222, 226, 230); border-image: initial; font-size: 0.9rem;">Techniques</th></tr></thead><tbody style="box-sizing: border-box; background: white; color: rgb(57, 67, 76);"><tr style="box-sizing: border-box;"><td style="box-sizing: border-box; padding: 0.75rem; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/software/S0030" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">S0030</a></td><td style="box-sizing: border-box; padding: 0.75rem; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/software/S0030" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Carbanak</a></td><td style="box-sizing: border-box; padding: 0.75rem; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><span id="scite-ref-1-a" class="scite-citeref-number" style="box-sizing: border-box;"><span style="box-sizing: border-box; position: relative; font-size: 12px; line-height: 0; vertical-align: baseline; top: -0.5em;"><a href="https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/08064518/Carbanak_APT_eng.pdf" target="_blank" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">[1]</a></span></span></td><td style="box-sizing: border-box; padding: 0.75rem; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/techniques/T1071" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Application Layer Protocol</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1071/001" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Web Protocols</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1547" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Boot or Logon Autostart Execution</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1547/001" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Registry Run Keys / Startup Folder</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1059" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Command and Scripting Interpreter</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1059/003" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Windows Command Shell</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1136" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Create Account</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1136/001" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Local Account</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1132" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Data Encoding</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1132/001" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Standard Encoding</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1030" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Data Transfer Size Limits</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1114" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Email Collection</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1114/001" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Local Email Collection</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1573" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Encrypted Channel</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1573/001" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Symmetric Cryptography</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1070" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Indicator Removal</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1070/004" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">File Deletion</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1056" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Input Capture</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1056/001" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Keylogging</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1027" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Obfuscated Files or Information</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1003" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">OS Credential Dumping</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1057" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Process Discovery</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1055" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Process Injection</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1055/002" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Portable Executable Injection</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1012" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Query Registry</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1219" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Remote Access Software</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1021" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Remote Services</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1021/001" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Remote Desktop Protocol</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1113" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Screen Capture</a></td></tr><tr style="box-sizing: border-box;"><td style="box-sizing: border-box; padding: 0.75rem; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/software/S0002" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">S0002</a></td><td style="box-sizing: border-box; padding: 0.75rem; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/software/S0002" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Mimikatz</a></td><td style="box-sizing: border-box; padding: 0.75rem; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><span id="scite-ref-1-a" class="scite-citeref-number" style="box-sizing: border-box;"><span style="box-sizing: border-box; position: relative; font-size: 12px; line-height: 0; vertical-align: baseline; top: -0.5em;"><a href="https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/08064518/Carbanak_APT_eng.pdf" target="_blank" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">[1]</a></span></span></td><td style="box-sizing: border-box; padding: 0.75rem; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/techniques/T1134" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Access Token Manipulation</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1134/005" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">SID-History Injection</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1098" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Account Manipulation</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1547" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Boot or Logon Autostart Execution</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1547/005" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Security Support Provider</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1555" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Credentials from Password Stores</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1555/003" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Credentials from Web Browsers</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1555" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Credentials from Password Stores</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1555" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Credentials from Password Stores</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1555/004" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Windows Credential Manager</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1003" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">OS Credential Dumping</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1003/001" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">LSASS Memory</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1003" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">OS Credential Dumping</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1003/002" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Security Account Manager</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1003" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">OS Credential Dumping</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1003/004" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">LSA Secrets</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1003" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">OS Credential Dumping</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1003/006" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">DCSync</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1207" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Rogue Domain Controller</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1649" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Steal or Forge Authentication Certificates</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1558" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Steal or Forge Kerberos Tickets</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1558/001" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Golden Ticket</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1558" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Steal or Forge Kerberos Tickets</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1558/002" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Silver Ticket</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1552" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Unsecured Credentials</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1552/004" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Private Keys</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1550" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Use Alternate Authentication Material</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1550/003" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Pass the Ticket</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1550" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Use Alternate Authentication Material</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1550/002" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Pass the Hash</a></td></tr><tr style="box-sizing: border-box;"><td style="box-sizing: border-box; padding: 0.75rem; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/software/S0108" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">S0108</a></td><td style="box-sizing: border-box; padding: 0.75rem; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/software/S0108" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">netsh</a></td><td style="box-sizing: border-box; padding: 0.75rem; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><span id="scite-ref-7-a" class="scite-citeref-number" style="box-sizing: border-box;"><span style="box-sizing: border-box; position: relative; font-size: 12px; line-height: 0; vertical-align: baseline; top: -0.5em;"><a href="http://www.group-ib.com/files/Anunak_APT_against_financial_institutions.pdf" target="_blank" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">[7]</a></span></span></td><td style="box-sizing: border-box; padding: 0.75rem; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/techniques/T1546" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Event Triggered Execution</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1546/007" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Netsh Helper DLL</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1562" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Impair Defenses</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1562/004" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Disable or Modify System Firewall</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1090" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Proxy</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1518" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Software Discovery</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1518/001" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Security Software Discovery</a></td></tr><tr style="box-sizing: border-box;"><td style="box-sizing: border-box; padding: 0.75rem; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/software/S0029" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">S0029</a></td><td style="box-sizing: border-box; padding: 0.75rem; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/software/S0029" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">PsExec</a></td><td style="box-sizing: border-box; padding: 0.75rem; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><span id="scite-ref-1-a" class="scite-citeref-number" style="box-sizing: border-box;"><span style="box-sizing: border-box; position: relative; font-size: 12px; line-height: 0; vertical-align: baseline; top: -0.5em;"><a href="https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/08064518/Carbanak_APT_eng.pdf" target="_blank" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">[1]</a></span></span></td><td style="box-sizing: border-box; padding: 0.75rem; vertical-align: top; border: 1px solid rgb(223, 223, 223);"><a href="https://attack.mitre.org/techniques/T1136" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Create Account</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1136/002" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Domain Account</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1543" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Create or Modify System Process</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1543/003" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Windows Service</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1570" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Lateral Tool Transfer</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1021" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Remote Services</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1021/002" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">SMB/Windows Admin Shares</a>,&nbsp;<a href="https://attack.mitre.org/techniques/T1569" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">System Services</a>:&nbsp;<a href="https://attack.mitre.org/techniques/T1569/002" style="box-sizing: border-box; color: rgb(79, 124, 172); background-color: transparent;">Service Execution</a></td></tr></tbody></table></div><div><br></div>