Behind the CARBANAK Backdoor[html]
In this blog, we will take a closer look at the powerful, versatile
backdoor known as CARBANAK (aka Anunak). Specifically, we will
focus on the operational details of its use over the past few years,
including its configuration, the minor variations observed from sample
to sample, and its evolution. With these details, we will then draw
some conclusions about the operators of CARBANAK. For some additional
background on the CARBANAK backdoor, see the papers by href="https://securelist.com/files/2015/02/Carbanak_APT_eng.pdf">Kaspersky
and href="https://www.fox-it.com/en/files/2014/12/Anunak_APT-against-financial-institutions2.pdf">Group-IB
and Fox-It.
Technical Analysis
Before we dive into the meat of this blog, a brief technical
analysis of the backdoor is necessary to provide some context.
CARBANAK is a full-featured backdoor with data-stealing capabilities
and a plugin architecture. Some of its capabilities include key
logging, desktop video capture, VNC, HTTP form grabbing, file system
management, file transfer, TCP tunneling, HTTP proxy, OS destruction,
POS and Outlook data theft and reverse shell. Most of these
data-stealing capabilities were present in the oldest variants of
CARBANAK that we have seen and some were added over time.
Monitoring Threads
The backdoor may optionally start one or more threads that perform
continuous monitoring for various purposes, as described in Table 1.