Auteur Sujet: [FireEye]Behind the CARBANAK Backdoor  (Lu 3058 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
[FireEye]Behind the CARBANAK Backdoor
« le: juin 12, 2017, 18:00:28 »
Behind the CARBANAK Backdoor

[html]

In this blog, we will take a closer look at the powerful, versatile
  backdoor known as CARBANAK (aka Anunak). Specifically, we will
  focus on the operational details of its use over the past few years,
  including its configuration, the minor variations observed from sample
  to sample, and its evolution. With these details, we will then draw
  some conclusions about the operators of CARBANAK. For some additional
  background on the CARBANAK backdoor, see the papers by   href="https://securelist.com/files/2015/02/Carbanak_APT_eng.pdf">Kaspersky
  and     href="https://www.fox-it.com/en/files/2014/12/Anunak_APT-against-financial-institutions2.pdf">Group-IB
    and Fox-It.


 

Technical Analysis


 

Before we dive into the meat of this blog, a brief technical
  analysis of the backdoor is necessary to provide some context.
  CARBANAK is a full-featured backdoor with data-stealing capabilities
  and a plugin architecture. Some of its capabilities include key
  logging, desktop video capture, VNC, HTTP form grabbing, file system
  management, file transfer, TCP tunneling, HTTP proxy, OS destruction,
  POS and Outlook data theft and reverse shell. Most of these
  data-stealing capabilities were present in the oldest variants of
  CARBANAK that we have seen and some were added over time.


 
Monitoring Threads

 

The backdoor may optionally start one or more threads that perform
  continuous monitoring for various purposes, as described in Table 1.


Tags: