MoneyTaker was the name Group-IB gave to a financially motivated cybercrime group it linked to attacks on banks and related organizations from 2016 through 2018. The group’s reported targets were in the United States, the United Kingdom and Russia; the evidence described by researchers does not establish that it was directed by the Russian government. “Latest” was apt to a December 2017 news report, not a verified description of the threat landscape in 2026.
Who was MoneyTaker?
Group-IB named the group after a custom, modular malware framework it said was used to spy on banks and manipulate payment data. In its December 2017 account, the company described MoneyTaker as previously unknown. CyberScoop’s contemporaneous report said Group-IB considered it likely unaffiliated with any government, so “Russian cybercrime” should not be read as proof of state sponsorship. The reporting concerned criminal activity and researchers’ attribution, not a public finding that a government directed the attacks. CyberScoop’s December 11, 2017 report summarizes that assessment.
What did MoneyTaker target?
Group-IB reported attacks on financial organizations in the U.S., Russia and the U.K., as well as entities connected to banking operations. Its December 2017 report counted 20 incidents over 2016 and 2017: 16 in the U.S., five against Russian banks, and one against a U.K. banking software company. Those category counts sum to 22, despite the report’s stated total of 20; they should therefore be treated as the vendor’s reported figures rather than reconciled into a single, precise breakdown. Group-IB’s original report linked the incidents through shared tools, infrastructure, one-time-use components and withdrawal schemes.
The reported targets were not limited to banks. Group-IB and CyberScoop also described attacks involving a U.S. service provider, financial software vendors and international law firms. Researchers said the attackers sought internal manuals, administrative guides and other documents, including material related to SWIFT, First Data’s STAR network and Russia’s interbank system, AWS CBR. Group-IB’s interpretation was that access to these documents helped the attackers understand how banking processes worked.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
How did the attacks work?
Group-IB described a combination of publicly available intrusion tools and custom malware. The MoneyTaker framework was modular. In its account of activity involving the Russian interbank system, researchers said it could search for payment orders, replace payment details with fraudulent ones and erase traces. Other reported capabilities included keylogging and screenshots; some operations also involved banking trojans. These are historical descriptions, not a current list of indicators that a bank or customer can use to detect an attack.
The initial infection route was not established in the 2017 reporting. Group-IB said the exact entry point was unclear in the incident-response cases it discussed, though one case involved an employee’s compromised personal computer being used as an entry point. As Group-IB Director Nik Palmer put it in CyberScoop’s account, “The primary infection vector remains unknown as Group-IB conducted their analysis on MoneyTaker’s infrastructure.”
Rank #2
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
What is known about MoneyTaker’s timeline?
Group-IB said it identified 10 attacks in 2016 and another 10 in 2017, then reported tracking two attacks in Russia in 2018. These are vendor-reported cases, not a complete count of all activity. In its 2018 update, Group-IB described a Russian-bank incident in which payment orders were sent in several tranches to mule accounts. It also estimated average damage of about $500,000 per U.S. attack at that time; that historical estimate is not a current loss benchmark. Group-IB’s 2018 update includes the incident account and estimate.
Group-IB said it provided information about the group to Europol and Interpol for investigative work. That statement does not, by itself, establish the outcome of an investigation, a prosecution or an attribution by law enforcement.
Recommended Free Tools
Rank #3
Is MoneyTaker still active?
The sources cited here document MoneyTaker activity through 2018 and do not establish whether the group remains active in 2026. Group-IB’s June 2026 threat-actor ranking discusses other actors, but its omission of MoneyTaker is not evidence that the group is inactive: a ranking is not a comprehensive status check. Group-IB’s 2026 ranking describes its own selection methodology, not a definitive account of every group’s current status.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What does this mean for bank customers?
The reporting focuses on attacks against financial institutions and their suppliers; it does not establish that MoneyTaker targeted individual bank customers directly. For customers, the useful distinction is between a historical breach of a bank’s systems and evidence of compromise of a particular account. The articles cited do not provide a basis for concluding that a specific customer’s account was affected.
Group-IB’s 2018 update advised banks to review router firmware, test for brute-force vulnerabilities and monitor router-configuration changes after the Russian-bank incident it described. That advice belongs to the context of that incident and is not a complete current security checklist for institutions or consumers.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




