Overview 17 indicators
FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.
| domain | 16 | G0046-domain.txt |
| url | 1 | G0046.json |
Techniques 67 ATT&CK
Open in ATT&CK Navigator → or download the layer (67 techniques, layer 4.5)
- T1005 Data from Local System
- T1008 Fallback Channels
- T1021.001 Remote Desktop Protocol
- T1021.004 SSH
- T1021.005 VNC
- T1027.010 Command Obfuscation
- T1027.016 Junk Code Insertion
- T1033 System Owner/User Discovery
- T1036.004 Masquerade Task or Service
- T1036.005 Match Legitimate Resource Name or Location
- T1047 Windows Management Instrumentation
- T1053.005 Scheduled Task
- T1057 Process Discovery
- T1059 Command and Scripting Interpreter
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1059.007 JavaScript
- T1069.002 Domain Groups
- T1071.004 DNS
- T1078 Valid Accounts
- T1078.003 Local Accounts
- T1082 System Information Discovery
- T1087.002 Domain Account
- T1091 Replication Through Removable Media
- T1102.002 Bidirectional Communication
- T1105 Ingress Tool Transfer
- T1113 Screen Capture
- T1124 System Time Discovery
- T1125 Video Capture
- T1140 Deobfuscate/Decode Files or Information
- T1190 Exploit Public-Facing Application
- T1195.002 Compromise Software Supply Chain
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1210 Exploitation of Remote Services
- T1218.005 Mshta
- T1218.011 Rundll32
- T1219 Remote Access Tools
- T1486 Data Encrypted for Impact
- T1497.002 User Activity Based Checks
- T1543.003 Windows Service
- T1546.011 Application Shimming
- T1547.001 Registry Run Keys / Startup Folder
- T1553.002 Code Signing
- T1558.003 Kerberoasting
- T1559.002 Dynamic Data Exchange
- T1564.001 Hidden Files and Directories
- T1564.003 Hidden Window
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1567.002 Exfiltration to Cloud Storage
- T1569.002 Service Execution
- T1571 Non-Standard Port
- T1572 Protocol Tunneling
- T1583.001 Domains
- T1583.006 Web Services
- T1587.001 Malware
- T1588.002 Tool
- T1591 Gather Victim Org Information
- T1591.004 Identify Roles
- T1608.001 Upload Malware
- T1608.004 Drive-by Target
- T1608.005 Link Target
- T1620 Reflective Code Loading
- T1674 Input Injection
- T1686 Disable or Modify System Firewall
Software 19
- Mimikatz
- Carbanak
- POWERSOURCE
- TEXTMATE
- HALFBAKED
- Cobalt Strike
- PowerSploit
- SQLRat
- BOOSTWRITE
- RDFSNIFFER
- GRIFFON
- Maze
- CrackMapExec
- REvil
- Pillowmint
- AdFind
- JSS Loader
- Lizar
- SystemBC
Principal sources 6 reports
Ranked by how many of this actor's indicators each report brought in.
- 9twitter.com/James_inthe_box/status/1275914690627899…
- 9twitter.com/ThreatHive/status/1275918481800617984
- 9app.any.run/tasks/d40e13a1-f17a-449c-8ac4-a7fd947f9…
- 8crowdstrike.com/blog/carbon-spider-embraces-big-game-hu…
- 8crowdstrike.com/blog/carbon-spider-embraces-big-game-hu…
- 8otx.alienvault.com/pulse/612f3d563c0ce5d63ed47842
Timeline 17 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
crowdstrike.com/blog/carbon-spider-embraces-big-game-hu… · crowdstrike.com/blog/carbon-spider-embraces-big-game-hu… · otx.alienvault.com/pulse/612f3d563c0ce5d63ed47842
domain againcome.com domain alphalanding.com domain chauvinistable.com domain colahasch.com url http://185.163.45.249 -
crowdstrike.com/blog/carbon-spider-embraces-big-game-hu… · crowdstrike.com/blog/carbon-spider-embraces-big-game-hu… · otx.alienvault.com/pulse/612f3d563c0ce5d63ed47842
petshopbook.com -
crowdstrike.com/blog/carbon-spider-embraces-big-game-hu… · crowdstrike.com/blog/carbon-spider-embraces-big-game-hu… · otx.alienvault.com/pulse/612f3d563c0ce5d63ed47842
besaintegration.com -
twitter.com/James_inthe_box/status/1275914690627899… · twitter.com/ThreatHive/status/1275918481800617984 · app.any.run/tasks/d40e13a1-f17a-449c-8ac4-a7fd947f9…
charjackyum.com gemmiparalyzed.com jaglamorous.com judicialance.com neighborhoodlumish.com podestablished.com spontaneousance.com spoolopedia.com temptationone.com -
crowdstrike.com/blog/carbon-spider-embraces-big-game-hu… · crowdstrike.com/blog/carbon-spider-embraces-big-game-hu… · otx.alienvault.com/pulse/612f3d563c0ce5d63ed47842
electroncador.com
Further reading 19
- blog.morphisec.com/fin7-attacks-restaurant-industry
- attack.mitre.org/groups/G0046
- bi-zone.medium.com/from-pentest-to-apt-attack-cybercrimina…
- learn.microsoft.com/en-us/microsoft-365/security/intelligen…
- securityintelligence.com/posts/ransomware-2020-attack-trends-new…
- web.archive.org/web/20180808125108/https:/www.fireeye.c…
- crowdstrike.com/blog/carbon-spider-embraces-big-game-hu…
- fireeye.com/blog/threat-research/2017/04/fin7-phish…
- fireeye.com/blog/threat-research/2017/05/fin7-shim-…
- fireeye.com/blog/threat-research/2017/06/behind-the…
- fireeye.com/blog/threat-research/2018/08/fin7-pursu…
- mandiant.com/resources/evolution-of-fin7
- microsoft.com/en-us/security/blog/2022/05/09/ransomwa…
- secureworks.com/research/threat-profiles/gold-niagara
- twitter.com/James_inthe_box/status/1275914690627899…
- crowdstrike.com/blog/carbon-spider-embraces-big-game-hu…
- twitter.com/ThreatHive/status/1275918481800617984
- otx.alienvault.com/pulse/612f3d563c0ce5d63ed47842
- app.any.run/tasks/d40e13a1-f17a-449c-8ac4-a7fd947f9…