Abdo, B., et al. (2022, April 4). FIN7 Power Hour: Adversary Archaeology and the Evolution of FIN7. Retrieved April 5, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.016 Junk Code Insertion |
GroupFIN7 | FIN7 has used random junk code to obfuscate malware code. |
| T1033 System Owner/User Discovery |
GroupFIN7 | FIN7 has used the command `cmd.exe /C quser` to collect user session information. |
| T1059.001 PowerShell |
GroupFIN7 | FIN7 used a PowerShell script to launch shellcode that retrieved an additional payload. Additionally, FIN7 has executed a custom obfuscation of the shellcode invoker in PowerSploit called POWERTRASH. |
| T1059.003 Windows Command Shell |
GroupFIN7 | FIN7 used the command prompt to launch commands on the victim’s machine. Additionally, FIN7 has used cmd.exe to open the Run dialog by sending the “Windows + R” keys through malicious USBs acting as virtual keyboards. |
| T1069.002 Domain Groups |
GroupFIN7 | FIN7 has used the command `net group "domain admins" /domain` to enumerate domain groups. |
| T1105 Ingress Tool Transfer |
GroupFIN7 | FIN7 has downloaded additional malware to execute on the victim's machine, including by using a PowerShell script to launch shellcode that retrieves an additional payload. |
| T1195.002 Compromise Software Supply Chain |
GroupFIN7 | FIN7 has gained initial access by compromising a victim's software supply chain. |
| T1218.011 Rundll32 |
GroupFIN7 | FIN7 has used `rundll32.exe` to execute malware on a compromised network. |
| T1219 Remote Access Tools |
GroupFIN7 | FIN7 has utilized the remote management tool Atera to download malware to a compromised system. |
| T1486 Data Encrypted for Impact |
GroupFIN7 | FIN7 has encrypted virtual disk volumes on ESXi servers using a version of Darkside ransomware. Additionally, FIN7 has deployed ransomware as the end payload during big game hunting. |
| T1558.003 Kerberoasting |
GroupFIN7 | FIN7 has used Kerberoasting PowerShell commands such as, `Invoke-Kerberoast` for credential access and to enable lateral movement. |
| T1583.006 Web Services |
GroupFIN7 | FIN7 has set up Amazon S3 buckets to host trojanized digital products. |
| T1588.002 Tool |
GroupFIN7 | FIN7 has utilized a variety of tools such as Cobalt Strike, PowerSploit, and the remote management tool, Atera for targeting efforts. |
| T1608.001 Upload Malware |
GroupFIN7 | FIN7 has staged legitimate software, that was trojanized to contain an Atera agent installer, on Amazon S3. FIN7 has also used an open directory web server as a staging server for payloads and other tools, such as OpenSSH and 7zip. |
| T1608.004 Drive-by Target |
GroupFIN7 | FIN7 has compromised a digital product website and modified multiple download links to point to trojanized versions of offered digital products. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.