Threat group.View on attack.mitre.org
FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
FIN7 has collected files and other sensitive information from a compromised network. |
| T1008 Fallback Channels |
FIN7's Harpy backdoor malware can use DNS as a backup channel for C2 if HTTP fails. |
| T1021.001 Remote Desktop Protocol |
FIN7 has used RDP to move laterally in victim environments. |
| T1021.004 SSH |
FIN7 has used SSH to move laterally through victim environments. |
| T1021.005 VNC |
FIN7 has used TightVNC to control compromised hosts. |
| T1027.010 Command Obfuscation |
FIN7 has used fragmented strings, environment variables, standard input (stdin), and native character-replacement functionalities to obfuscate commands. |
| T1027.016 Junk Code Insertion |
FIN7 has used random junk code to obfuscate malware code. |
| T1033 System Owner/User Discovery |
FIN7 has used the command `cmd.exe /C quser` to collect user session information. |
| T1036.004 Masquerade Task or Service |
FIN7 has created a scheduled task named “AdobeFlashSync” to establish persistence. |
| T1036.005 Match Legitimate Resource Name or Location |
FIN7 has attempted to run Darkside ransomware with the filename sleep.exe. Additionally, FIN7 has mimicked WsTaskLoad.exe, which is associated with the Wondershare software suite, by using a malicious executable under the same name. |
| T1047 Windows Management Instrumentation |
FIN7 has used WMI to install malware on targeted systems. |
| T1053.005 Scheduled Task |
FIN7 malware has created scheduled tasks to establish persistence. Specifically, FIN7 has used OpenSSH to establish persistence. |
| T1057 Process Discovery |
FIN7 has used the PowerShell script 3CF9.ps1 to perform process discovery by executing `tasklist /v`. Additionally, WsTaskLoad.exe executes `tasklist /v` to perform process discovery. |
| T1059 Command and Scripting Interpreter |
FIN7 used SQL scripts to help perform tasks on the victim's machine. |
| T1059.001 PowerShell |
FIN7 used a PowerShell script to launch shellcode that retrieved an additional payload. Additionally, FIN7 has executed a custom obfuscation of the shellcode invoker in PowerSploit called POWERTRASH. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.