FIN7__2017__RSA_the-shadows-of-ghosts-carbanak-report_11-30-2017.pdf
ID: 04979b47-af0b-4c23-940b-a0a049b588d5
STIX ID: report--04979b47-af0b-4c23-940b-a0a049b588d5
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2017-12-04
Last Modified Date: 2017-12-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
RSA Incident Response describes a 2017 CARBANAK/FIN7 intrusion where actors exploited Apache Struts (CVE-2017-5638) to gain initial access, escalated privileges via the Dirty COW exploit, and deployed a cross-platform toolset (SSHDOOR, AUDITUNNEL, GOTROJ, TINYP, WINEXE, PSCAN, ALW, Mimikatz variants) to harvest credentials, move laterally and persist. The attackers operated for weeks (35 days dwell at discovery), impacted ~154 systems, used direct-to-IP Wget downloads and custom XOR/RC4-encoded C2 channels, and were ultimately contained and remediated after coordinated response; the report includes detailed IOCs and NetWitness detection content.
