logo

MoneyTaker__2017__Group-IB_MoneyTaker_report.pdf

ID: 8c5a328b-480d-4fd3-b52b-bd3a1f9d9fd4

STIX ID: report--8c5a328b-480d-4fd3-b52b-bd3a1f9d9fd4

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2017-12-11

Last Modified Date: 2017-12-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive summary Group-IB's report analyzes the MoneyTaker campaign (May 2016–Nov 2017), a financially-motivated, highly targeted criminal group that exfiltrated funds and banking documentation from ~20 organisations using Metasploit/Meterpreter, fileless PowerShell/VBS persistence, bespoke MoneyTaker modules that automated replacement of interbank transfer data (AWS CBR), banking and POS trojans (Citadel, Kronos, ScanPOS), and operational security such as forged SSL certs and whitelist-based persistence servers; the report includes detailed IOCs (hashes, IPs, SSL fingerprints), attack timelines, and defensive recommendations.