Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Carbanak group stole $1BN, but were detected in December

by The Gurus
February 16, 2015
in Editor's News
Share on FacebookShare on Twitter

The group who have reportedly stolen $1 billion in two years from 30 countries was initially spotted in December.
 
The report by Kaspersky Lab found that a multi-national gang of cyber criminals from Russia, Ukraine, China and parts of Europe found that the “Carbanak” criminal gang attempted to attack up to 100 banks, e-payment systems and other financial institutions in around 30 countries where the largest sums were grabbed by hacking into banks and stealing up to $10 million in each raid.
 
On average, each bank robbery took between two and four months and began by gaining entry into an employee’s computer through spear phishing, infecting the victim with the Carbanak malware.
 
However the Dutch security investigation firm Fox-IT said that the characteristics correlate with what it saw from the Anunak group, and it said in an update that Anunak has ties with Carbanak.
 
“Anunak is the name the malware author gave to the main malware used in these attacks,” it said. “Carbanak is the name the anti-virus industry gave to this malware, which is a combination of the words ‘Anunak’ and ‘Carberp’, as the Anunak malware has used code from Carberp.”
 
Fox-IT previously reported on Anunak as being an APT-like criminal group with ties to the Carberp group from some years ago. The attack types include previously unseen direct attacks to Russian bank ATM’s and core financial systems of banks, while focusing on POS malware and credit card counterfeiting in the rest of the world, with their main focus on US retail.
 
The company said that since early December, the group has decreased their activities and may have even stopped entirely.
 
It said: “Without any insight into the evidence Kaspersky has obtained, we can only repeat our view that Anunak has targeted only banks in Russia and we have no concrete reports of compromised banks outside of Russia directly related to this criminal group. The compromises outside Russia related to retail compromises with the goal of obtaining credit card data to create counterfeit credit cards.”
 
Amichai Shulman, CTO of Imperva, said: “Whatever technologies these banks were using to protect themselves failed. It’s time to look for new technologies. Such an operation resulted in countless acts of internal credential theft and explorations within the bank network. Clearly setting up traps within end stations would have triggered multiple alerts over time. Organisations must deploy this new technology.
 
“The operation involved multiple that are ‘unnatural’ or ‘rare’ in normal operations such as ‘tricking’ the balance of accounts. Clearly it is impossible to scrutinise each and every such operation. Thus a technology that looks at the aggregate effect of such operation over time is something required in today’s landscape.”
 
Kaspersky Lab’s report claimed that the cyber criminals began by gaining entry into an employee’s computer through spear phishing, infecting the victim with the Carbanak malware. They were then able to access the internal network and track down administrators’ computers for video surveillance.
 
Mike Spykerman, vice president of product management at OPSWAT, said: “This is yet another hacking originating from spear phishing attacks: According to the Kaspersky report, the hackers were able to gain access to the banking systems by sending out emails to banking employees with a malware laced Word attachment, which when opened, executed a backdoor for the attackers. The problem with these attacks is that because they are targeted to only a small number of individuals, the malware can get past anti-virus engines.”
 
Neil Costigan, CEO of BehavioSec, said: “The figures released by Kaspersky today should make banks all over the world look up from their morning coffee. It’s not only the scale of the attacks that will ring alarm bells, but the type; each ‘bank robbery’ is reportedly taking between two and four months. We are no longer talking about one man with a balaclava, but protracted, sophisticated, patient attacks with criminals lurking for months to learn the banks’ systems. This approach is viable, so long as the banks rely on outdated ‘one off’ authentication requests.”
 

Tags: APTattackBankfinancialPOSSpear Phishing
ShareTweet
Previous Post

Spam Gazing – Anthem breach double phishing whammy

Next Post

Dell SonicWALL secures The Cloud

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol