MoneyTaker__2017__Group-IB_MoneyTaker_report.pdf
ID: 8c5a328b-480d-4fd3-b52b-bd3a1f9d9fd4
STIX ID: report--8c5a328b-480d-4fd3-b52b-bd3a1f9d9fd4
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2017-12-11
Last Modified Date: 2017-12-11
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive summary
Group-IB's report analyzes the MoneyTaker campaign (May 2016–Nov 2017), a financially-motivated, highly targeted criminal group that exfiltrated funds and banking documentation from ~20 organisations using Metasploit/Meterpreter, fileless PowerShell/VBS persistence, bespoke MoneyTaker modules that automated replacement of interbank transfer data (AWS CBR), banking and POS trojans (Citadel, Kronos, ScanPOS), and operational security such as forged SSL certs and whitelist-based persistence servers; the report includes detailed IOCs (hashes, IPs, SSL fingerprints), attack timelines, and defensive recommendations.
