October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Who Was MoneyTaker? The Russian-Linked Banking Crime Group, Explained

MoneyTaker was a financially motivated group that Group-IB linked to attacks on banks and related organizations from 2016 through 2018. Its current status is unconfirmed.
From TheFinanceBase Team3 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

MoneyTaker was the name Group-IB gave to a financially motivated cybercrime group it linked to attacks on banks and related organizations from 2016 through 2018. The group’s reported targets were in the United States, the United Kingdom and Russia; the evidence described by researchers does not establish that it was directed by the Russian government. “Latest” was apt to a December 2017 news report, not a verified description of the threat landscape in 2026.

Who was MoneyTaker?

Group-IB named the group after a custom, modular malware framework it said was used to spy on banks and manipulate payment data. In its December 2017 account, the company described MoneyTaker as previously unknown. CyberScoop’s contemporaneous report said Group-IB considered it likely unaffiliated with any government, so “Russian cybercrime” should not be read as proof of state sponsorship. The reporting concerned criminal activity and researchers’ attribution, not a public finding that a government directed the attacks. CyberScoop’s December 11, 2017 report summarizes that assessment.

What did MoneyTaker target?

Group-IB reported attacks on financial organizations in the U.S., Russia and the U.K., as well as entities connected to banking operations. Its December 2017 report counted 20 incidents over 2016 and 2017: 16 in the U.S., five against Russian banks, and one against a U.K. banking software company. Those category counts sum to 22, despite the report’s stated total of 20; they should therefore be treated as the vendor’s reported figures rather than reconciled into a single, precise breakdown. Group-IB’s original report linked the incidents through shared tools, infrastructure, one-time-use components and withdrawal schemes.

The reported targets were not limited to banks. Group-IB and CyberScoop also described attacks involving a U.S. service provider, financial software vendors and international law firms. Researchers said the attackers sought internal manuals, administrative guides and other documents, including material related to SWIFT, First Data’s STAR network and Russia’s interbank system, AWS CBR. Group-IB’s interpretation was that access to these documents helped the attackers understand how banking processes worked.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How did the attacks work?

Group-IB described a combination of publicly available intrusion tools and custom malware. The MoneyTaker framework was modular. In its account of activity involving the Russian interbank system, researchers said it could search for payment orders, replace payment details with fraudulent ones and erase traces. Other reported capabilities included keylogging and screenshots; some operations also involved banking trojans. These are historical descriptions, not a current list of indicators that a bank or customer can use to detect an attack.

The initial infection route was not established in the 2017 reporting. Group-IB said the exact entry point was unclear in the incident-response cases it discussed, though one case involved an employee’s compromised personal computer being used as an entry point. As Group-IB Director Nik Palmer put it in CyberScoop’s account, “The primary infection vector remains unknown as Group-IB conducted their analysis on MoneyTaker’s infrastructure.”

Rank #2
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)

What is known about MoneyTaker’s timeline?

Group-IB said it identified 10 attacks in 2016 and another 10 in 2017, then reported tracking two attacks in Russia in 2018. These are vendor-reported cases, not a complete count of all activity. In its 2018 update, Group-IB described a Russian-bank incident in which payment orders were sent in several tranches to mule accounts. It also estimated average damage of about $500,000 per U.S. attack at that time; that historical estimate is not a current loss benchmark. Group-IB’s 2018 update includes the incident account and estimate.

Group-IB said it provided information about the group to Europol and Interpol for investigative work. That statement does not, by itself, establish the outcome of an investigation, a prosecution or an attribution by law enforcement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Is MoneyTaker still active?

The sources cited here document MoneyTaker activity through 2018 and do not establish whether the group remains active in 2026. Group-IB’s June 2026 threat-actor ranking discusses other actors, but its omission of MoneyTaker is not evidence that the group is inactive: a ranking is not a comprehensive status check. Group-IB’s 2026 ranking describes its own selection methodology, not a definitive account of every group’s current status.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What does this mean for bank customers?

The reporting focuses on attacks against financial institutions and their suppliers; it does not establish that MoneyTaker targeted individual bank customers directly. For customers, the useful distinction is between a historical breach of a bank’s systems and evidence of compromise of a particular account. The articles cited do not provide a basis for concluding that a specific customer’s account was affected.

Group-IB’s 2018 update advised banks to review router firmware, test for brute-force vulnerabilities and monitor router-configuration changes after the Russian-bank incident it described. That advice belongs to the context of that incident and is not a complete current security checklist for institutions or consumers.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.