{"id":20602,"date":"2018-07-12T09:46:40","date_gmt":"2018-07-12T13:46:40","guid":{"rendered":"https:\/\/www.kaspersky.com.au\/blog\/not-carbanak-source-code\/20602\/"},"modified":"2022-05-05T03:17:41","modified_gmt":"2022-05-04T16:17:41","slug":"not-carbanak-source-code","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.au\/blog\/not-carbanak-source-code\/20602\/","title":{"rendered":"Recently leaked malware source code isn&#8217;t Carbanak"},"content":{"rendered":"<p>Previous statements claimed that it was <a href=\"https:\/\/www.kaspersky.com\/blog\/billion-dollar-apt-carbanak\/7519\/\" target=\"_blank\" rel=\"noopener nofollow\">Carbanak<\/a> source code that was leaked recently. Kaspersky Lab analysis, however, reveals that the code belongs to another piece of financial malware called Karamanak\/Pegasus\/Ratopak (not to be confused with Pegasus for iOS spyware). Timestamps suggest that this <a href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/source-code\/?utm_source=kdaily&amp;utm_medium=blog&amp;utm_campaign=termin-explanation\" target=\"_blank\" rel=\"noopener noreferrer\">source code<\/a> was produced in 2015\u20132016. The language of the virus writers was definitely native Russian, and they were targeting financial institutions in Russia.<\/p>\n<p>Any financial malware attack, and particularly any attack against well-protected organizations, is a sophisticated operation that requires a lot of preparation and incorporates two key steps: infection and money withdrawal. Although a source code leak could help criminals with the first step, the second stage requires a lot of planning and effort. Therefore, it is unlikely that we will immediately hear about new cyberincidents based on this leak very soon.<\/p>\n<p>Such leaks are a big deal in the long run. Still, history teaches us that in the long term, it is highly likely the leak of this source code will have the devastating effect of leading to different cybercriminals developing new malware modifications. For example, that\u2019s what happened after the <a href=\"https:\/\/threatpost.com\/zeus-source-code-leaked-051011\/75217\/\" target=\"_blank\" rel=\"noopener nofollow\">Zeus source code leak<\/a> in 2011, so in the long term we can expect the appearance of new financial malware strains and groups of criminals involved in financial cybercrime.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kesb-trial\">\n","protected":false},"excerpt":{"rendered":"<p>The recently leaked source code actually isn&#8217;t Carbanak \u2014 it&#8217;s another advanced financial malware family. And the leak will likely have a huge ripple effect.<\/p>\n","protected":false},"author":2706,"featured_media":20603,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1999,5,2994,2646],"tags":[963,2420,1161,2925,2041,36,1991,2926,2782],"class_list":{"0":"post-20602","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-business","8":"category-news","9":"category-smb","10":"category-threats","11":"tag-carbanak","12":"tag-endpoint","13":"tag-finance","14":"tag-karamanak","15":"tag-kaspersky-endpoint-security","16":"tag-malware-2","17":"tag-pegasus","18":"tag-ratopak","19":"tag-source-code"},"hreflang":[{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/not-carbanak-source-code\/20602\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/not-carbanak-source-code\/13666\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/not-carbanak-source-code\/11434\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/not-carbanak-source-code\/15731\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/not-carbanak-source-code\/13979\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/not-carbanak-source-code\/13155\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/not-carbanak-source-code\/16463\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/not-carbanak-source-code\/15953\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/not-carbanak-source-code\/20893\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/not-carbanak-source-code\/23055\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/not-carbanak-source-code\/10498\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/not-carbanak-source-code\/9397\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/not-carbanak-source-code\/17234\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/not-carbanak-source-code\/20765\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/not-carbanak-source-code\/16936\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/not-carbanak-source-code\/20591\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.au\/blog\/tag\/finance\/","name":"finance"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/20602","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/users\/2706"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/comments?post=20602"}],"version-history":[{"count":9,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/20602\/revisions"}],"predecessor-version":[{"id":30476,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/20602\/revisions\/30476"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/media\/20603"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/media?parent=20602"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/categories?post=20602"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/tags?post=20602"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}