FIN7
Aliases: GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS, Sangria Tempest
FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has primarily targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, and utilities industries in the U.S. A portion of FIN7 was run out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to a big game hunting (BGH) approach including use of REvil ransomware and their own Ransomware as a Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but there appears to be several groups using Carbanak malware and are therefore tracked separately.
Open interactive actor investigation
ATT&CK techniques
Malicious LinkT1553.002
Code SigningT1078
Valid AccountsT1059
Command and Scripting InterpreterT1021.004
SSHT1190
Exploit Public-Facing ApplicationT1027.001
Binary PaddingT1033
System Owner/User DiscoveryT1053.005
Scheduled TaskT1021.005
VNCT1036.005
Match Legitimate Name or LocationT1566.002
Spearphishing LinkT1036.004
Masquerade Task or ServiceT1218.011
Rundll32T1047
Windows Management InstrumentationT1059.005
Visual BasicT1219
Remote Access SoftwareT1059.001
PowerShellT1546.011
Application ShimmingT1559.002
Dynamic Data ExchangeT1069.002
Domain GroupsT1021.001
Remote Desktop ProtocolT1486
Data Encrypted for ImpactT1588.002
ToolT1583.006
Web ServicesT1497.002
User Activity Based ChecksT1059.007
JavaScriptT1547.001
Registry Run Keys / Startup FolderT1608.004
Drive-by TargetT1125
Video CaptureT1571
Non-Standard PortT1027.010
Command ObfuscationT1204.002
Malicious FileT1218.005
MshtaT1102.002
Bidirectional CommunicationT1105
Ingress Tool TransferT1078.003
Local AccountsT1583.001
DomainsT1005
Data from Local SystemT1543.003
Windows ServiceT1091
Replication Through Removable MediaT1071.004
DNST1059.003
Windows Command ShellT1566.001
Spearphishing AttachmentT1608.001
Upload MalwareT1008
Fallback ChannelsT1558.003
KerberoastingT1195.002
Compromise Software Supply ChainT1113
Screen CaptureT1567.002
Exfiltration to Cloud StorageT1210
Exploitation of Remote ServicesT1587.001
Malware