Overview
Carbanak is a cybercriminal intrusion set that has targeted financial institutions since at least 2013. MITRE ATT&CK tracks the group under G0008 with the associated name Anunak, and notes probable links to the separately tracked Cobalt Group and FIN7, both of which have used the same Carbanak backdoor. The group is also tracked as Carbon Spider, GOLD NIAGARA, Sangria Tempest (Microsoft), and ITG14.
Europol estimated cumulative losses from the original Carbanak bank-targeting campaign at up to EUR 1 billion across more than 100 financial institutions in over 40 countries. The campaign ran from approximately 2013 to 2018 and was distinctive for targeting banking infrastructure directly rather than individual account holders. Operators spent months recording screens and logging keystrokes to learn internal workflows before manufacturing fraudulent ATM cash disbursements, manipulating Oracle database balances, and redirecting SWIFT interbank transfers.
The group operated behind a front company, Combi Security, which recruited developers and operators under the pretense of legitimate penetration-testing work. Three Ukrainian nationals were indicted in 2018. Fedir Hladyr was sentenced to 10 years in federal prison in April 2021. Andrii Kolpakov received 7 years and $2.5 million in restitution in June 2021. A third member, Denys Iarmak, was sentenced in 2022. The enterprise did not stop after those convictions.
Since approximately 2020, the FIN7 cluster sharing Carbanak tooling pivoted to ransomware affiliate operations, gaining privileged corporate access and deploying ransomware as the final monetization step. Microsoft tracks this phase as Sangria Tempest, documenting exploitation of Exchange ProxyShell (CVE-2021-31207) and ZeroLogon (CVE-2020-1472). The tooling also evolved: GRIFFON (VBScript stager), Bateleur (JScript backdoor with sandbox detection), and JSS Loader joined the Carbanak backdoor depending on the campaign era.