Inside the Response of a Unique CARABANK Intrusion
ID: 9a5c5faf-e7e2-4b0b-ab7c-d5534df77610
STIX ID: report--9a5c5faf-e7e2-4b0b-ab7c-d5534df77610
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2017-11-10
Last Modified Date: 2017-11-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This RSA white paper analyzes a 2017 CARBANAK/FIN7 intrusion that exploited an Apache Struts remote code execution and a Dirty COW kernel escalation to gain administrative access, then deployed a standardized cross-platform toolset (SSHDOOR, AUDITUNNEL, WINEXE, TINYP, GOTROJ, etc.) to harvest credentials, tunnel traffic, and move laterally across Linux and Windows environments; the actors compromised ~154 systems with a ~35‑day dwell time and RSA documents detailed IOCs, parsing rules, detection queries, and the methodology used to contain and remediate the incident.
