All actors

Carbanak

Also reported as Carbon Spider, ELBRUS, Sangria Tempest, Anunak, FIN7 and 9 other names. Sources disagree on the origin.

Reports
905
Last reported
Known CVEs
312
Techniques in ATT&CK
9
Origin
Russia, Ukraine
ID
G0008
Merge evidence
11 alias matches

Reports per quarter

  1. 2014 Q2: 1 report
  2. 2014 Q3: no reports
  3. 2014 Q4: no reports
  4. 2015 Q1: 4 reports
  5. 2015 Q2: 2 reports
  6. 2015 Q3: 3 reports
  7. 2015 Q4: 3 reports
  8. 2016 Q1: 5 reports
  9. 2016 Q2: 1 report
  10. 2016 Q3: 3 reports
  11. 2016 Q4: 2 reports
  12. 2017 Q1: 7 reports
  13. 2017 Q2: 9 reports
  14. 2017 Q3: 2 reports
  15. 2017 Q4: 9 reports
  16. 2018 Q1: 2 reports
  17. 2018 Q2: 5 reports
  18. 2018 Q3: 14 reports
  19. 2018 Q4: 6 reports
  20. 2019 Q1: 11 reports
  21. 2019 Q2: 26 reports
  22. 2019 Q3: 4 reports
  23. 2019 Q4: 9 reports
  24. 2020 Q1: 12 reports
  25. 2020 Q2: 23 reports
  26. 2020 Q3: 25 reports
  27. 2020 Q4: 50 reports
  28. 2021 Q1: 49 reports
  29. 2021 Q2: 65 reports
  30. 2021 Q3: 76 reports
  31. 2021 Q4: 65 reports
  32. 2022 Q1: 62 reports
  33. 2022 Q2: 78 reports
  34. 2022 Q3: 54 reports
  35. 2022 Q4: 20 reports
  36. 2023 Q1: 20 reports
  37. 2023 Q2: 13 reports
  38. 2023 Q3: 20 reports
  39. 2023 Q4: 19 reports
  40. 2024 Q1: 8 reports
  41. 2024 Q2: 11 reports
  42. 2024 Q3: 21 reports
  43. 2024 Q4: 13 reports
  44. 2025 Q1: 7 reports
  45. 2025 Q2: 11 reports
  46. 2025 Q3: 9 reports
  47. 2025 Q4: 4 reports
  48. 2026 Q1: 4 reports
  49. 2026 Q2: 37 reports
  50. 2026 Q3: 1 report
Dated reports, 2014 Q2 to 2026 Q3.

Techniques seen in the last two years

Show all 277 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

CVEs named in reports

Show all 312 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. BlackCat (Malware Family)

    date ORKL added it fromORKL

  2. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  3. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

Show all 905 reports Show fewer
  1. REvil (Malware Family)

    date ORKL added it fromORKL

  2. IcedID (Malware Family)

    date ORKL added it fromORKL

  3. MimiKatz (Malware Family)

    date ORKL added it fromORKL

  4. Griffon (Malware Family)

    date ORKL added it fromORKL

  5. DarkSide (Malware Family)

    date ORKL added it fromORKL

  6. Cobalt Strike (Malware Family)

    date ORKL added it fromORKL

  7. BlackSuit Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  8. BumbleBee: Round Two

    publisher's date The DFIR Report fromORKLDFIR Report

  9. ALPHV-BlackCat ransomware family becoming more dangerous

    date in the title fromORKL

  10. RedSense

    Malpedia library date fromORKL

  11. RedSense

    Malpedia library date fromORKL

  12. CERT-UA

    Malpedia library date fromORKL

  13. CERT-UA

    Malpedia library date fromORKL

  14. RedSense

    Malpedia library date fromORKL

  15. Russian cyber attack campaigns and actors.pdf

    file creation date fromORKL

  16. yir-cyber-threats-annex-download.pdf

    Malpedia library date fromORKL

  17. Quantum Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  18. RedSense

    Malpedia library date fromORKL

  19. Conti ransomware source code investigation - part 1

    date in the title fromORKL

  20. CERT-UA

    Malpedia library date fromORKL

  21. 2021 Year In Review

    publisher's date The DFIR Report fromORKLDFIR Report

  22. 2021trends.pdf

    Malpedia library date fromORKL

  23. RedSense

    Malpedia library date fromORKL

  24. Nickel

    Malpedia library date Notice of Pleadings fromORKLCCS '25 data

  25. FIN7 Tools Resurface in the Field – Splinter or Copycat-

    date in the title fromORKL

  26. Understanding the Windows JavaScript Threat Landscape

    date in the title fromORKL

  27. BlackMatter- New Data Exfiltration Tool Used in Attacks

    date in the title fromORKL

  28. From Zero to Domain Admin

    publisher's date The DFIR Report fromORKLDFIR Report

  29. FIN7 Recruits Talent For Push Into Ransomware

    date in the title fromORKL

  30. RedSense

    Malpedia library date fromORKL

  31. eset_threat_report_t22021

    file creation date fromORKL

  32. report-old-dogs-new-tricks.pdf

    Malpedia library date fromORKL

  33. Ryuk Ransomware Now Targeting Webservers

    Malpedia library date fromORKL

  34. Conti Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  35. CTIR_casestudy_2.pdf

    file creation date fromORKL

  36. CTIR_casestudy_1.pdf

    file creation date fromORKL

  37. the-operations-of-winnti-group.pdf

    Malpedia library date fromORKL

  38. Carbanak and FIN7 Attack Techniques

    date in the title fromORKL

  39. report-bb-2021-threat-report.pdf

    Malpedia library date fromORKL

  40. Technical Analysis of Operation Diànxùn

    Malpedia library date fromORKL

  41. Bazar Drops the Anchor

    publisher's date The DFIR Report fromORKLDFIR Report

  42. Intezer-2020-Go-Malware-Round-Up.pdf

    Malpedia library date fromORKL

  43. Bazar, No Ryuk?

    publisher's date The DFIR Report fromORKLDFIR Report

  44. [Morphisec]_The_Evolution_of_the_FIN7_JssLoader

    Malpedia library date fromORKL

  45. Collaboration Between FIN7 and the RYUK Group

    date in the CCS '25 data Truesec fromORKLCCS '25 data

  46. Active Directory 侵害と推奨対策

    Malpedia library date fromORKL

  47. Russian cyber attack campaigns and actors

    date in the title fromORKL

  48. yoroi.company-Shadows From the Past Threaten Italian Enterprises

    date in the CCS '25 data Yoroi fromORKLCCS '25 data

  49. Shadows From The Past Threaten Italian Enterprises

    date in the title fromORKL

  50. ESET_Threat_Report_Q32020

    file creation date fromORKL

  51. Ryuk in 5 Hours

    publisher's date The DFIR Report fromORKLDFIR Report

  52. Ryuk's Return

    publisher's date The DFIR Report fromORKLDFIR Report

  53. OpBlueRaven- Unveiling Fin7-Carbanak - Part 1 - Tirion

    date in the title fromORKL

  54. 2020-q2-spamhaus-botnet-threat-report.pdf

    Malpedia library date fromORKL

  55. ESET_Threat_Report_Q22020

    file creation date fromORKL

  56. CERTFR-2020-CTI-008

    Malpedia library date CrowdStrike fromORKLCCS '25 data

  57. Pillowmint- FIN7’s Monkey Thief

    date in the title fromORKL

  58. Russian Cyber Attack Campaigns and Actors - Threat Research

    file creation date fromORKL

  59. 210527.pdf

    Malpedia library date FBI fromORKLCCS '25 data

  60. CTNT_Q1_2020_COVID-Report_Final.pdf

    Malpedia library date fromORKL

  61. Ursnif via LOLbins

    publisher's date The DFIR Report fromORKLDFIR Report

  62. Catching APT41 exploiting a zero-day vulnerability

    date in the CCS '25 data Darktrace fromCCS '25 data

  63. Introducing BIOLOAD- FIN7 BOOSTWRITE’s Lost Twin

    date in the title fromORKL

  64. Aarhus_miniseminar_291118.pdf

    Malpedia library date fromORKL

  65. Mahalo_FIN7

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  66. APT-Attacks-eng.pdf

    file creation date fromORKL

  67. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date ThaiCERT fromORKL

  68. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date Martijn van der Heide fromORKL

  69. The Rise of Dridex and the Role of ESPs

    date in the title fromORKL

  70. FIN7.5_ the infamous cybercrime rig “FIN7” continues its activities

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  71. CARBANAK Week Part Four: The CARBANAK Desktop Video Player

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  72. CARBANAK Week Part One: A Rare Occurrence

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  73. CARBANAK Week Part One- A Rare Occurrence

    date in the title fromORKL

  74. mpressioncss_ta_report_2019.pdf

    Malpedia library date fromORKL

  75. FIN7 Revisited- Inside Astra Panel and SQLRat Malware

    date in the title fromORKL

  76. Report2019GlobalThreatReport

    file creation date fromORKL

  77. CrowdStrike_GTR_2019.pdf

    file creation date fromORKL

  78. ENISA Threat Landscape Report 2018

    file creation date fromORKL

  79. Silence: Moving into the darkside

    date in the CCS '25 data Group-IB fromORKLCCS '25 data

  80. HITB-SG-2018-E - In the trails of WINDSHIFT [Autosaved]

    date in the CCS '25 data Bellingcat fromORKLCCS '25 data

  81. Three Carbanak cyber heist gang members arrested

    date in the title fromORKL

  82. Arrests Put New Focus on CARBON SPIDER Adversary Group

    date in the title fromORKL

  83. NotCarbanak Mystery - Source Code Leak

    date in the title fromORKL

  84. Cobalt Renaissance- new attacks and joint operations

    date in the title fromORKL

  85. Anunak: Apt Against Financial Institutions

    Malpedia library date Group-IB, FOX-IT fromORKLCCS '25 data

  86. Inside the Response of a Unique CARBANAK Intrusion

    file creation date RSA fromORKL

  87. The Shadows of Ghosts: Inside the Response of a... | RSA Link

    date in the CCS '25 data RSA fromORKLCCS '25 data

  88. The Carbanak/Fin7 syndicate

    file creation date RSA fromORKL

  89. Inside the Response of a Unique CARABANK Intrusion

    file creation date fromORKL

  90. Silence – a new Trojan attacking financial organizations

    date in the title fromORKL

  91. Behind the CARBANAK Backdoor

    date in the title fromORKL

  92. FIN7 Evolution and the Phishing LNK

    date in the title fromORKL

  93. Operation Grand Mars

    file creation date fromORKL

  94. Carbanak Group uses Google for malware command-and-control

    date in the title fromORKL

  95. New Carbanak / Anunak Attack Methodology

    date in the CCS '25 data Trustwave fromORKLCCS '25 data

  96. Visa Alert and Update on the Oracle Breach

    date in the CCS '25 data Brian Krebs fromORKLCCS '25 data

  97. Carbanak Oracle Breach

    date in the CCS '25 data Visa fromCCS '25 data

  98. proofpoint-threat-insight-carbanak-group-en

    date in the CCS '25 data Proofpoint fromORKLCCS '25 data

  99. Group-IB-Corkow-Report-EN.pdf

    file creation date fromORKL

  100. Evolution of Cyber Threats in the Corporate Sector

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  101. Russian financial cybercrime_ how it works - Securelist

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  102. Без названия

    file creation date fromORKL

  103. Carbanak is packing new guns

    date in the CCS '25 data ESET fromORKLCCS '25 data

  104. Carbanak gang is back and packing new guns

    date in the title fromORKL

  105. Operation Buhtrap, the trap for Russian accountants

    date in the title fromORKL

  106. Carbanak

    Malpedia library date fromORKL

  107. Carbanak

    date in the title fromORKL

  108. Carbanak_APT_eng.pdf

    Malpedia library date Kaspersky fromORKLCCS '25 data

  109. Carbanak APT The Great Bank Robbery

    Malpedia library date Kaspersky fromORKL

Newest first. Details opens the report in Explore.