Categories: NewsSecurity

Carbanak Cybercrime Group Uses Public Google Services to Control Malware Operations

Cybercrime gangs are becoming bolder at every turn. The Carbanak group is back after a brief absence, and they are now using cloud servers to operate their command-and-control servers. To be more precise, the group employs Google’s servers to distribute and control its malware. A brash move that goes to show cyber criminals aren’t afraid of anything.

Carbanak Returns With A Bang

Forcepoint Security Labs researchers announced that they have spotted new activity linked to the Carbanak crime gang. This particular group of criminals is responsible for hacking and stealing funds from various financial institutions throughout the course of 2015. By using highly sophisticated malware, the group was able to infiltrate computer networks and conduct their business without being caught.

Damages done by the Carbanak group are estimated to top US$1bn. This notorious group of criminals stole the funds over the course of two years by integrating close to 100 banks in several dozen countries. In most cases, they targeted bank employees with spear phishing campaigns. Primary targets include Russian, Danish, and American financial institutions. None of the money stolen during these attacks was ever recovered.



As of 2017, the Carbanak group is back with a vengeance, and they have a new trick up their sleeve. It turns out they use Google’s Apps Script, Sheets, and Forms cloud-based services. All of these platforms are used to control their command-and-control operations related to the new type of malware being spread. The objective remains unchanged, defrauding banks and customers whenever they can.

Related Post

The malware is being deployed through an RTF document containing an encoded Visual Basic script. Once a user is infected, the information will be sent back to the C&C server, which then makes a separate spreadsheet tab for each victim.In doing so, the Carbanak group uses a free tool to maintain a virtual “trophy hall” of victims, so to speak.

While most cybercrime gangs tend to lurk in the hidden corners of the internet, Carbanak is taking a very different approach. In fact, they are hiding in plain sight, and use one of the world’s largest technology companies’ public services. Google has been notified of this incident, but for now, no resolution has been offered yet.

One thing of particular concern is how using Google’s services will benefit their command-and-control server operations. New domains, or domains without any reputation, are less likely to be visited by recipients of the spear phishing emails. Google, on the other hand, is a household brand most people are all too familiar with. We can only hope the technology giant takes the necessary actions sooner rather than later.

If you liked this article, follow us on Twitter @themerklenews and make sure to subscribe to our newsletter to receive the latest bitcoin, cryptocurrency, and technology news.

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

Bitwise Launches Its First Tokenized Fund With $259M in Assets and 4% Annual Yield

Bitwise Asset Management has just made its first move into tokenized funds, and it comes…

13 hours ago

Binance Launches US Stocks and ETFs Trading for Non-US Users With Zero Commission

Binance just made a move that blurs the line between crypto exchange and traditional brokerage…

14 hours ago

NEAR Protocol Ships Confidential Payments, Crosses $19B in Intents Volume, and Partners With Bermuda Government

NEAR Protocol has had a month that most blockchain projects would stretch across an entire…

1 day ago

Chainlink Records 7 New Integrations Across 6 Services and 4 Chains

Something is becoming increasingly clear about Chainlink, the integrations are not slowing down. The protocol…

2 days ago

Circle Freezes $12.6 Million in Zama’s Confidential USDC Contract on Ethereum

Blockchain investigator ZachXBT has flagged a major stablecoin freeze that is sending shockwaves through the…

3 days ago

Exponent Finance Launches V2 To Expand Institutional Yield Markets On Solana

From a primarily interest rate swap niche product, Exponent has developed into an onchain capital…

3 days ago