FIN7

G0046

Threat group.View on attack.mitre.org

About this group

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.

Techniques used67

Procedure examples67

TechniqueProcedure example
T1005
Data from Local System

FIN7 has collected files and other sensitive information from a compromised network.

T1008
Fallback Channels

FIN7's Harpy backdoor malware can use DNS as a backup channel for C2 if HTTP fails.

T1021.001
Remote Desktop Protocol

FIN7 has used RDP to move laterally in victim environments.

T1021.004
SSH

FIN7 has used SSH to move laterally through victim environments.

T1021.005
VNC

FIN7 has used TightVNC to control compromised hosts.

T1027.010
Command Obfuscation

FIN7 has used fragmented strings, environment variables, standard input (stdin), and native character-replacement functionalities to obfuscate commands.

T1027.016
Junk Code Insertion

FIN7 has used random junk code to obfuscate malware code.

T1033
System Owner/User Discovery

FIN7 has used the command `cmd.exe /C quser` to collect user session information.

T1036.004
Masquerade Task or Service

FIN7 has created a scheduled task named “AdobeFlashSync” to establish persistence.

T1036.005
Match Legitimate Resource Name or Location

FIN7 has attempted to run Darkside ransomware with the filename sleep.exe. Additionally, FIN7 has mimicked WsTaskLoad.exe, which is associated with the Wondershare software suite, by using a malicious executable under the same name.

T1047
Windows Management Instrumentation

FIN7 has used WMI to install malware on targeted systems.

T1053.005
Scheduled Task

FIN7 malware has created scheduled tasks to establish persistence. Specifically, FIN7 has used OpenSSH to establish persistence.

T1057
Process Discovery

FIN7 has used the PowerShell script 3CF9.ps1 to perform process discovery by executing `tasklist /v`. Additionally, WsTaskLoad.exe executes `tasklist /v` to perform process discovery.

T1059
Command and Scripting Interpreter

FIN7 used SQL scripts to help perform tasks on the victim's machine.

T1059.001
PowerShell

FIN7 used a PowerShell script to launch shellcode that retrieved an additional payload. Additionally, FIN7 has executed a custom obfuscation of the shellcode invoker in PowerSploit called POWERTRASH.

View all 67 procedure examples

Software19

Campaigns0

None recorded.

References7

  1. BiZone Lizar May 2021 Open source
    BI.ZONE Cyber Threats Research Team. (2021, May 13). From pentest to APT attack: cybercriminal group FIN7 disguises its malware as an ethical hacker’s toolkit. Retrieved February 2, 2022.
  2. CrowdStrike Carbon Spider August 2021 Open source
    Loui, E. and Reynolds, J. (2021, August 30). CARBON SPIDER Embraces Big Game Hunting, Part 1. Retrieved September 20, 2021.
  3. FireEye CARBANAK June 2017 Open source
    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.
  4. FireEye FIN7 April 2017 Open source
    Carr, N., et al. (2017, April 24). FIN7 Evolution and the Phishing LNK. Retrieved April 24, 2017.
  5. FireEye FIN7 Aug 2018 Open source
    Carr, N., et al. (2018, August 01). On the Hunt for FIN7: Pursuing an Enigmatic and Evasive Global Criminal Operation. Retrieved August 23, 2018.
  6. FireEye FIN7 March 2017 Open source
    Miller, S., et al. (2017, March 7). FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC Filings. Retrieved March 8, 2017.
  7. Mandiant FIN7 Apr 2022 Open source
    Abdo, B., et al. (2022, April 4). FIN7 Power Hour: Adversary Archaeology and the Evolution of FIN7. Retrieved April 5, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.