New Carbanak / Anunak Attack Methodology
ID: 50866f8e-1618-4227-bf32-26432f0d2c44
STIX ID: report--50866f8e-1618-4227-bf32-26432f0d2c44
Threat Score
80/100
Uploaded: 2026-08-14
Published Date: 2016-12-31
Last Modified Date: 2016-12-31
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trustwave SpiderLabs documents a Carbanak/Anunak campaign targeting hotels and restaurants that uses phone-based social engineering to deliver malicious Word attachments with embedded VBS loaders (AdobeUpdateManagementTool.vbs) which fetch and run additional tools. The multi-stage infection performs reconnaissance (Nmap, RDP tools), privilege escalation (el32/el64 exploits, CVE-2013-3660), persistent backdoors (bf.exe injected into svchost), remote control, POS memory scraping for track data, and encrypted exfiltration to hardcoded C2 IPs/domains; the report includes file hashes, registry/service persistence details, beaconing patterns, and network IOCs.
