Cyber Resilience

Threat actor · all actors

CarbanakG0008 state

🇷🇺 RU

aka Carbanak, Anunak, FIN7, CARBON SPIDER, GOLD NIAGARA, Calcium, ATK32, G0046, G0008, Coreid, Sangria Tempest, ELBRUS, JokerStash

Last updated: 2026-07-03

0attributed CVEs
14ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
years active

About this actor

[Carbanak](https://attack.mitre.org/groups/G0008) is a cybercriminal group that has used [Carbanak](https://attack.mitre.org/software/S0030) malware to target financial institutions since at least 2013. [Carbanak](https://attack.mitre.org/groups/G0008) may be linked to groups tracked separately as [Cobalt Group](https://attack.mitre.org/groups/G0080) and [FIN7](https://attack.mitre.org/groups/G0046) that have also used [Carbanak](https://attack.mitre.org/software/S0030) malware.(Citation: Kaspersky Carbanak)(Citation: FireEye FIN7 April 2017)(Citation: Europol Cobalt Mar 2018)(Citation: Secureworks GOLD NIAGARA Threat Profile)(Citation: Secureworks GOLD KINGSWOOD Threat Profile)

Source: MITRE ATT&CK

Activity timeline

No activity events recorded.

Profile

CVERiskCVSSEPSSPublishedProducts
No attributed CVEs.

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
CA-710 / 1471%
SI-410 / 1471%
CM-29 / 1464%
CM-69 / 1464%
CM-79 / 1464%
AC-38 / 1457%
SI-38 / 1457%
AC-27 / 1450%
AC-67 / 1450%
SI-77 / 1450%
AC-55 / 1436%
CM-55 / 1436%
IA-25 / 1436%
SC-75 / 1436%
SI-105 / 1436%

Co-occurring actors

None.

Similar actors

Similar TTPs