logo

white-papers-win-32-carberp.pdf

ID: 1d8bdcbe-9897-4b1d-b9f6-ea7e6bb0803f

STIX ID: report--1d8bdcbe-9897-4b1d-b9f6-ea7e6bb0803f

Threat Score

78/100

Uploaded: 2026-08-05

Published Date: 2026-08-05

Last Modified Date: 2026-08-05

Created by: gogogo

TLP:GREEN
...
...
ESET/Group-IB provide a technical analysis of Win32/Carberp evolving to include a kernel-mode bootkit (Zerokit/Rovnix), its installer and privilege-escalation exploits (MS10-073, MS10-092, MS11-011, .NET vuln), distribution via Black Hole exploit kit (notably Java exploits), C2/debug logs, plugin architecture for targeting Russian remote banking systems, and related malware (SpyEye) and criminal ecosystem activity.