white-papers-win-32-carberp.pdf
ID: 1d8bdcbe-9897-4b1d-b9f6-ea7e6bb0803f
STIX ID: report--1d8bdcbe-9897-4b1d-b9f6-ea7e6bb0803f
Threat Score
78/100
Uploaded: 2026-08-05
Published Date: 2026-08-05
Last Modified Date: 2026-08-05
Created by: gogogo
TLP:GREEN
...
...
ESET/Group-IB provide a technical analysis of Win32/Carberp evolving to include a kernel-mode bootkit (Zerokit/Rovnix), its installer and privilege-escalation exploits (MS10-073, MS10-092, MS11-011, .NET vuln), distribution via Black Hole exploit kit (notably Java exploits), C2/debug logs, plugin architecture for targeting Russian remote banking systems, and related malware (SpyEye) and criminal ecosystem activity.
