logo

Inside the Response of a Unique CARABANK Intrusion

ID: 9a5c5faf-e7e2-4b0b-ab7c-d5534df77610

STIX ID: report--9a5c5faf-e7e2-4b0b-ab7c-d5534df77610

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2017-11-10

Last Modified Date: 2017-11-10

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This RSA white paper analyzes a 2017 CARBANAK/FIN7 intrusion that exploited an Apache Struts remote code execution and a Dirty COW kernel escalation to gain administrative access, then deployed a standardized cross-platform toolset (SSHDOOR, AUDITUNNEL, WINEXE, TINYP, GOTROJ, etc.) to harvest credentials, tunnel traffic, and move laterally across Linux and Windows environments; the actors compromised ~154 systems with a ~35‑day dwell time and RSA documents detailed IOCs, parsing rules, detection queries, and the methodology used to contain and remediate the incident.