Carbanak 2.0: A year ago, Kaspersky Lab warned that cybercriminals would begin to adopt tools and tactics to carry out state-sponsored APT (Advanced Persistent Threat) attacks for bank robberies. 
This year, the company confirms the return of the Carbanak campaign , as Carbanak 2.0, while revealing two more groups operating in the same manner: Metel and GCMAN . These groups attack financial institutions using covert identification, similar to APT attacks, as well as customized malware, combined with legitimate software and new, innovative methods to extort money.
Kaspersky Lab's Global Research and Analysis Team made these revelations during the Kaspersky Security Analyst Summit (SAS), the company's annual event, which is a platform for discussion for malware researchers, developers, law enforcement agencies and Cyber Emergency Response Teams (CERTs) from around the world, and members of the broader security research community.
The Met e l cybercrime group uses many techniques. The interest surrounding its activities is mainly focused on the use of an extremely clever method of action. Specifically, this group gains control of devices and systems within a bank that have access to financial transactions (e.g. call center, support computers), in order to automate the reversal of transactions from ATM machines.
The reset feature ensures that the debit card balance remains the same, regardless of the number of transactions made through the ATM. In the cases observed to date, the criminal group steals money as follows: While traveling at night, they make various stops in Russian cities and empty the ATMs of various banks, repeatedly using the same debit cards issued by the “compromised” bank. In this way, they cash out the money they want in just one night.
“Today, the active phase of a digital attack is becoming shorter and shorter. When attackers specialize in a particular operation, it only takes a few days or a week to get what they want and disappear,” commented Sergey Golovanov, Principal Security Researcher at Kaspersky Lab’s Global Research and Analysis Team.
During the forensic investigation, Kaspersky Lab experts discovered that the perpetrators behind the Metel campaign achieve the initial “infection” of systems via specially crafted spear-phishing emails containing malicious attachments, as well as via the Niteris exploit package, targeting vulnerabilities in the victim’s browser. Once inside the network, the cybercriminals use legitimate tools and penetration testing tools to move stealthily, compromising the local domain controller and – ultimately – locating and controlling the computers of bank employees, who are responsible for processing card payments.
The Metel group remains active and the investigation into its activities is ongoing. So far, no attacks have been detected outside of Russia. However, there are suspicions that the “infection” is much more widespread. For this reason, it is recommended that banks carry out preventive checks.
All three gangs identified are shifting to using malware bundled with legitimate software for their fraudulent activities. Why create multiple custom malware tools when multiple legitimate tools can be just as effective, triggering far fewer alerts?
However, in terms of stealth efforts, the GCMAN goes even further. Sometimes, it can successfully attack without using any malware, just by running legitimate tools and penetration testing tools. In cases investigated by Kaspersky Lab experts, the GCMAN campaign used the Putty, VNC, and Meterpreter utilities to move stealthily through the network until the attackers reached a machine that could be used to transfer money to e-currency services without alerting other banking systems.
In one of the attacks investigated by Kaspersky Lab, cybercriminals remained on the network for a year and a half before committing the theft. The money was transferred in amounts of about $200. This amount is the maximum for anonymous payments in Russia. Every minute, the CRON scheduler sent a malicious script and another amount was transferred to electronic currency accounts, which were intended for money laundering. The transaction orders were sent directly to the bank’s upstream payment gateway and did not appear anywhere in its internal systems.
Finally, Carbanak 2.0 marks the reemergence of the Carbanak APT attack. This campaign uses the same tools and techniques, but the victim profile is different, and innovative ways of extorting money are also observed.
The Carbanak 2.0 campaign targets not only banks, but also the financial and accounting departments of organizations of interest to cybercriminals. In a typical case investigated by Kaspersky Lab, the Carbanak 2.0 gang gained access to a financial institution and proceeded to change the ownership credentials of a large company. The information was modified to present an “intermediary” as a shareholder of the company, displaying his own identity.
“The attacks on financial institutions revealed in 2015 show a worrying trend: cybercriminals are adopting tactics similar to those of APT attacks. The Carbanak gang was just the first of many that we will see. Today, cybercriminals are quickly learning how to use new techniques in their activities, while many criminal groups are shifting their focus from targeting users to direct attacks on banks. Their logic is simple: that’s where the money is,” warns Sergey Golovanov. “Our goal is to highlight how and where, specifically, threat actors can strike to extort your money. After the news of the GCMAN gang attacks, we expect that checks will be carried out to see whether web banking serversare protected. "Regarding the Carbanak case, it is recommended that businesses strengthen the protection of the database that contains information about account owners, not just bank balances," he added.
Kaspersky Lab products detect and block malware used in the Carbanak 2.0, Metel and GCMAN campaigns. The company will also release a set of Critical Indicators of Breach and other data to help organizations track these gangs in their corporate networks. More information is available at: https://securelist.com/blog/research/73638/apt-style-bank-robberies-increase-with-metel-gcman-and-carbanak-2-0-attacks/.
Following the latest developments, Kaspersky Lab is urging all organizations to carefully check their networks for the presence of Carbanak, Metel, and GCMAN. If detected, organizations are urged to remove the “infection” from their systems and report the intrusion to law enforcement.
