{"id":12782,"date":"2018-07-12T07:30:52","date_gmt":"2018-07-12T15:30:52","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2018\/07\/12\/news-6550\/"},"modified":"2018-07-12T07:30:52","modified_gmt":"2018-07-12T15:30:52","slug":"news-6550","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/07\/12\/news-6550\/","title":{"rendered":"Recently leaked malware source code isn&#8217;t Carbanak"},"content":{"rendered":"<p><strong>Credit to Author: Kaspersky Team| Date: Thu, 12 Jul 2018 13:46:40 +0000<\/strong><\/p>\n<p><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/07\/12094337\/not-carbanak-source-code-featured.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/07\/12094337\/not-carbanak-source-code-featured.jpg\" alt=\"\" width=\"1280\" height=\"840\" class=\"aligncenter size-full wp-image-23056\" \/><\/a> <\/p>\n<p>Previous statements claimed that it was <a href=\"https:\/\/www.kaspersky.com\/blog\/billion-dollar-apt-carbanak\/7519\/\">Carbanak<\/a> source code that was leaked recently. Kaspersky Lab analysis, however, reveals that the code belongs to another piece of financial malware called Karamanak\/Pegasus\/Ratopak (not to be confused with Pegasus for iOS spyware). Timestamps suggest that this source code was produced in 2015\u20132016. The language of the virus writers was definitely native Russian, and they were targeting financial institutions in Russia.<\/p>\n<p>Any financial malware attack, and particularly any attack against well-protected organizations, is a sophisticated operation that requires a lot of preparation and incorporates two key steps: infection and money withdrawal. Although a source code leak could help criminals with the first step, the second stage requires a lot of planning and effort. Therefore, it is unlikely that we will immediately hear about new cyberincidents based on this leak very soon.<\/p>\n<p>Such leaks are a big deal in the long run. Still, history teaches us that in the long term, it is highly likely the leak of this source code will have the devastating effect of leading to different cybercriminals developing new malware modifications. For example, that&#8217;s what happened after the <a href=\"https:\/\/threatpost.com\/zeus-source-code-leaked-051011\/75217\/\">Zeus source code leak<\/a> in 2011, so in the long term we can expect the appearance of new financial malware strains and groups of criminals involved in financial cybercrime.<\/p>\n<p> <input type=\"hidden\" class=\"category_for_banner\" value=\"kesb-trial\" \/> <br \/><a href=\"https:\/\/www.kaspersky.com\/blog\/not-carbanak-source-code\/23055\/\" target=\"bwo\" >https:\/\/blog.kaspersky.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Kaspersky Team| Date: Thu, 12 Jul 2018 13:46:40 +0000<\/strong><\/p>\n<p>The recently leaked source code actually isn&#8217;t Carbanak \u2014 it&#8217;s another advanced financial malware family. And the leak will likely have a huge ripple effect.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10425,10378],"tags":[1001,11544,9190,18954,17442,3764,32,11940,18955,17475,10438],"class_list":["post-12782","post","type-post","status-publish","format-standard","hentry","category-kaspersky","category-security","tag-business","tag-carbanak","tag-finance","tag-karamanak","tag-kaspersky-endpoint-security","tag-malware","tag-news","tag-pegasus","tag-ratopak","tag-source-code","tag-threats"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12782","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=12782"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12782\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=12782"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=12782"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=12782"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}