FIN7
MISPCriminal
RU
Unknown
[FIN7](https://attack.mitre.org/groups/G0046) is a financially-motivated threat group that has been active since 2013. [FIN7](https://attack.mitre.org/groups/G0046) has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of [FIN7](https://attack.mitre.org/groups/G0046) was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, [FIN7](https://attack.mitre.org/groups/G0046) shifted operations to big game hunting (BGH), including use of [REvil](https://attack.mitre.org/software/S0496) ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the [Carbanak](https://attack.mitre.org/groups/G0008) Group, but multiple threat groups have been observed using [Carbanak](https://attack.mitre.org/software/S0030), leading these groups to be tracked separately.(Citation: FireEye FIN7 March 2017)(Citation: FireEye FIN7 April 2017)(Citation: FireEye CARBANAK June 2017)(Citation: FireEye FIN7 Aug 2018)(Citation: CrowdStrike Carbon Spider August 2021)(Citation: Mandiant FIN7 Apr 2022)(Citation: BiZone Lizar May 2021)
Tecniche Utilizzate (67)
| ID | ATT&CK | Tattiche |
|---|---|---|
| T1005 | Data from Local System | - |
| T1008 | Fallback Channels | - |
| T1021.001 | Remote Desktop Protocol | - |
| T1021.004 | SSH | - |
| T1021.005 | VNC | - |
| T1027.010 | Command Obfuscation | - |
| T1027.016 | Junk Code Insertion | - |
| T1033 | System Owner/User Discovery | - |
| T1036.004 | Masquerade Task or Service | - |
| T1036.005 | Match Legitimate Resource Name or Location | - |
| T1047 | Windows Management Instrumentation | - |
| T1053.005 | Scheduled Task | - |
| T1057 | Process Discovery | - |
| T1059 | Command and Scripting Interpreter | - |
| T1059.001 | PowerShell | - |
Riferimenti (10)
- en.wikipedia.org - Carbanak
- app.box.com - P7qzcury97tuwk26694uutujwqmwqyhe
- 2014.zeronights.ru - Ivanovb Zeronights.pdf
- web.archive.org - Odinaff New Trojan Used High Level Financial Attacks
- proofpoint.com - Fin7carbanak Threat Actor Unleashes Bateleur Jscript Backdoor
- icebrg.io - Footprints Of Fin7 Tracking Actor Patterns
- crowdstrike.com - Arrests Put New Focus On Carbon Spider Adversary Group
- europol.europa.eu - Mastermind Behind Eur 1 Billion Cyber Bank Robbery Arrested In Spain
- computerweekly.com - Three Carbanak Cyber Heist Gang Members Arrested
- media.kasperskycontenthub.com - Carbanak APT Eng.pdf
Alias (1756)
Malware Utilizzato (18)
Metadata
| ID: | 59 |
| Created: | 13/01/2026 17:48 |
| Updated: | 06/03/2026 04:00 |