Cybersecurity

Carbanak: The Hacking Group That Watched Banks First

Carbanak stole up to a billion dollars from banks by patiently watching employees work, not by breaking anything. Here's how the heist actually worked.

Editorial Team / /9 min read
Digital illustration of a bank's internal computer network under silent surveillance

In February 2015, researchers at Kaspersky, working with Interpol and Europol, announced that a criminal hacking group had spent close to two years quietly draining money from banks around the world. Their estimate: up to 100 financial institutions across roughly 30 countries, with losses that could reach as much as a billion dollars. The group behind it became known as the Carbanak hacking group, named after the malicious software, or malware, it used to get inside bank networks. The number was framed as an estimate, not a confirmed total, but it was still enough to make Carbanak one of the most closely studied bank heists of the decade. What made it notable wasn’t a clever exploit or some undiscovered flaw. It was how long the attackers were willing to wait, and watch, before touching a single account, which is the part of the story that still holds up years later.

One name, two things, and a group not to confuse

Carbanak refers to two related things at once. First, it’s a backdoor, a hidden way into a computer system that lets an attacker come and go without being noticed. Second, by extension, it’s the name given to the group of criminals who used that backdoor between roughly 2013 and 2018. Early reports sometimes called it Carbanak/Anunak, because the malware reused parts of an older banking trojan called Carberp, software originally built to steal online banking credentials from individual users rather than entire institutions.

The picture gets murkier after 2016. Around that time, some of the same infrastructure, and likely overlapping personnel, were tied to a second wave of attacks using a different piece of software, Cobalt Strike, a legitimate penetration-testing tool that security teams use to simulate attacks on their own networks, and that criminals routinely repurpose for real break-ins. That second campaign is often referred to separately as the “Cobalt group.” When Europol announced an arrest in 2018, it treated the two as connected parts of one criminal organization rather than two unrelated stories that happened to overlap.

It’s also worth being precise about who Carbanak is not. A separate, better-known group called FIN7 has been documented by researchers at Mandiant and FireEye as reusing chunks of code from the original Carbanak backdoor, and FIN7 has continued operating, in various forms, well after 2018. That’s a real technical link, not proof the two are the same group. Reporting on the case has never settled on one name either: outlets and vendors have called the same activity Carbanak, Anunak, and Cobalt, and some fold FIN7 into the mix too, which is part of why casual summaries of the case still mix the entities up. FIN7 and Carbanak are best described as related by shared tools, not confirmed as a single organization under two names, and treating them as interchangeable would blur two separate investigations into one.

cybersecurity illustration

Weeks of watching before touching a single account

The way Carbanak got inside a bank was mundane. Employees received spear-phishing emails, meaning messages crafted to look legitimate and aimed at a specific target, carrying Word documents or CPL files (a Windows file type that can run code when opened). These exploited flaws in Microsoft Office that were, in many cases, already known and patchable at the time of the attack. Nothing exotic. Just an employee opening an attachment they had no obvious reason to distrust, on a normal working day, doing exactly what their job asked of them.

What happened after that is the part that made Carbanak different. Once inside a bank’s network, the group didn’t rush to move money. According to Kaspersky’s original 2015 report, the attackers recorded the screens of administrators and staff for weeks, sometimes longer, studying exactly how the bank’s internal software worked. They learned which buttons authorized a transfer, how balances were adjusted, what a normal day looked like from the inside, down to the small habits an employee might not even notice they had. Only after that groundwork did they act, and when they did, they didn’t hack the software so much as operate it the way an employee would, submitting transfers that looked, on paper, like any other routine batch, which is precisely why it went unnoticed for so long.

That patience is the durable idea behind Carbanak, and it still applies well beyond banking. A system that only defends against unusual code or unfamiliar login locations can still be walked through the front door by someone who has learned to look exactly like a normal user, because the alarm most systems are built to catch is a stranger, not a very well-informed impostor.

Turning patience into cash

Once the attackers understood a bank’s workflow, they had two main ways of turning that knowledge into money. The first was straightforward: inflate an account balance through the bank’s own transfer systems, then move the difference into an account they controlled, all while imitating the click-by-click behavior of a real employee closely enough that the transaction never stood out in a routine audit.

The second was more theatrical: ATM jackpotting, a technique that forces a cash machine to dispense money on command, without a card or PIN, essentially telling the machine it owes someone a stack of bills for no legitimate reason. Jackpotting wasn’t invented by Carbanak. It was demonstrated publicly for the first time by New Zealand researcher Barnaby Jack at the Black Hat USA security conference in 2010, as a way of showing banks how exposed their ATM software really was. Several criminal groups picked up variations of the technique afterward, Carbanak among them, using it to have machines pay out cash directly to people waiting nearby, sometimes at a prearranged time down to the minute.

Neither method required breaking new cryptography or discovering some undiscovered flaw. Both depended on the same asset: time spent learning how a specific bank actually worked, which is a much harder thing to defend against than a single software patch, since there’s no update that removes an attacker’s accumulated knowledge of your own routine.

The heist that led investigators to a suspect

One case did more than any other to connect Carbanak’s activity to an actual person: the July 2016 theft from First Commercial Bank in Taiwan. Attackers used the group’s methods to force 41 ATMs across 22 branches to dispense cash, walking away with roughly NT$83.27 million, around $2.63 million at the time, in a coordinated operation that played out across the island in a single window of time.

Taiwanese investigators eventually identified 22 suspects from nine countries, though only three so-called money mules, people used to physically collect and move stolen cash, were arrested on the spot, reportedly of Latvian, Romanian, and Moldovan nationality. The rest of the network stayed out of reach for almost two more years, a gap that says as much about how hard cross-border cybercrime cases are to close as it does about the group itself.

That changed on March 26, 2018, when Spanish police, working with Europol, arrested a man in Alicante identified only as “Denis K.,” a Ukrainian national, as the alleged leader of the group. No official source, not Europol, not the Spanish police, has published his full name, and none should be assumed or repeated as fact. Taiwanese and Spanish investigators explicitly linked that arrest back to the First Commercial Bank case, making it one of the few Carbanak incidents with a documented line from crime to arrest.

cybersecurity illustration

What “dismantled” actually means

Europol’s March 2018 statement put the group’s cumulative damage at more than one billion euros, spread across more than 100 banks and other financial firms in over 40 countries, a larger and later figure than Kaspersky’s original 2015 estimate, reflecting three additional years of activity investigators had since documented. The statement described the network as dismantled following the arrest.

Dismantled doesn’t mean every technique died with it. The same investigation tied part of Carbanak’s infrastructure to that separate Cobalt Strike campaign, and copycat groups have kept using the same playbook, patient reconnaissance followed by quiet impersonation, on new targets ever since. The pattern shows up in other forms of quiet compromise today too, including software supply chain attacks that ride a trusted update into a network long before anyone notices something is wrong. The name Carbanak describes a specific case that ended in 2018. The method it popularized did not end with it.

Frequently asked questions

Is the Carbanak hacking group still active today?

Europol described the group as dismantled after the 2018 arrest in Spain. Even so, the technique it used, patient network surveillance followed by mimicking employee behavior, has been adopted by other criminal groups since, so the method has outlived the original organization even if the organization itself has not.

How much money did Carbanak actually steal?

The confirmed figure comes from Europol’s 2018 statement: more than one billion euros across over 100 institutions in more than 40 countries. Kaspersky’s earlier 2015 estimate, up to a billion dollars from around 100 institutions in 30 countries, was a preliminary figure covering an earlier stage of the investigation. Both are estimates tied to an ongoing case, not a single audited total, and neither should be treated as a precise accounting.

Is Carbanak the same group as FIN7?

No, not according to the researchers who have studied both. Mandiant and FireEye have documented that FIN7 reuses code originally built for the Carbanak backdoor, which shows a technical connection between the two, not proof they’re the same organization operating under different names. Treat any claim that flatly equates them with caution.

Could a Carbanak-style attack still succeed today?

In principle, yes. The specific malware and phishing lures are outdated and would likely be caught by modern email filtering, but the underlying method, patiently studying how employees actually work before acting like one of them, never depended on any particular piece of software. Any system that grants trust based on familiar-looking behavior, rather than verifying it, stays exposed to the same patience. It is the same blind spot that structured approaches like OWASP, MITRE, and NIST guidance on security risk try to formalize: treat behavior, not just code, as something to verify rather than assume.

What should a business actually take from the Carbanak case?

The specific malware and phishing emails are dated, but the underlying lesson is not: any system that assumes familiar-looking behavior is automatically safe behavior has a blind spot. Carbanak’s entire method was built around exploiting exactly that assumption, patiently, for weeks, before ever moving money.

The takeaway

Carbanak is remembered as a headline number, a billion-dollar bank heist, but the number was never really the point. The group’s real innovation was treating observation as the main tool, patient enough to learn a bank’s routine so thoroughly that its theft looked like business as usual. That’s a harder problem than patching a vulnerability, because it means the danger isn’t always unfamiliar code slipping through. It’s part of why security teams have pushed toward zero trust thinking, which starts from the assumption that no user’s behavior, however familiar it looks, should be trusted by default. Sometimes the danger is someone who has already learned to look exactly like they belong.

#cybersecurity#carbanak#cybercrime#banking-security#malware