logo

New Carbanak / Anunak Attack Methodology

ID: 50866f8e-1618-4227-bf32-26432f0d2c44

STIX ID: report--50866f8e-1618-4227-bf32-26432f0d2c44

Threat Score

80/100

Uploaded: 2026-08-14

Published Date: 2016-12-31

Last Modified Date: 2016-12-31

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trustwave SpiderLabs documents a Carbanak/Anunak campaign targeting hotels and restaurants that uses phone-based social engineering to deliver malicious Word attachments with embedded VBS loaders (AdobeUpdateManagementTool.vbs) which fetch and run additional tools. The multi-stage infection performs reconnaissance (Nmap, RDP tools), privilege escalation (el32/el64 exploits, CVE-2013-3660), persistent backdoors (bf.exe injected into svchost), remote control, POS memory scraping for track data, and encrypted exfiltration to hardcoded C2 IPs/domains; the report includes file hashes, registry/service persistence details, beaconing patterns, and network IOCs.