ATT&CKReferencesMandiant FIN7 Apr 2022

Mandiant FIN7 Apr 2022

Abdo, B., et al. (2022, April 4). FIN7 Power Hour: Adversary Archaeology and the Evolution of FIN7. Retrieved April 5, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1027.016
Junk Code Insertion
GroupFIN7

FIN7 has used random junk code to obfuscate malware code.

T1033
System Owner/User Discovery
GroupFIN7

FIN7 has used the command `cmd.exe /C quser` to collect user session information.

T1059.001
PowerShell
GroupFIN7

FIN7 used a PowerShell script to launch shellcode that retrieved an additional payload. Additionally, FIN7 has executed a custom obfuscation of the shellcode invoker in PowerSploit called POWERTRASH.

T1059.003
Windows Command Shell
GroupFIN7

FIN7 used the command prompt to launch commands on the victim’s machine. Additionally, FIN7 has used cmd.exe to open the Run dialog by sending the “Windows + R” keys through malicious USBs acting as virtual keyboards.

T1069.002
Domain Groups
GroupFIN7

FIN7 has used the command `net group "domain admins" /domain` to enumerate domain groups.

T1105
Ingress Tool Transfer
GroupFIN7

FIN7 has downloaded additional malware to execute on the victim's machine, including by using a PowerShell script to launch shellcode that retrieves an additional payload.

T1195.002
Compromise Software Supply Chain
GroupFIN7

FIN7 has gained initial access by compromising a victim's software supply chain.

T1218.011
Rundll32
GroupFIN7

FIN7 has used `rundll32.exe` to execute malware on a compromised network.

T1219
Remote Access Tools
GroupFIN7

FIN7 has utilized the remote management tool Atera to download malware to a compromised system.

T1486
Data Encrypted for Impact
GroupFIN7

FIN7 has encrypted virtual disk volumes on ESXi servers using a version of Darkside ransomware. Additionally, FIN7 has deployed ransomware as the end payload during big game hunting.

T1558.003
Kerberoasting
GroupFIN7

FIN7 has used Kerberoasting PowerShell commands such as, `Invoke-Kerberoast` for credential access and to enable lateral movement.

T1583.006
Web Services
GroupFIN7

FIN7 has set up Amazon S3 buckets to host trojanized digital products.

T1588.002
Tool
GroupFIN7

FIN7 has utilized a variety of tools such as Cobalt Strike, PowerSploit, and the remote management tool, Atera for targeting efforts.

T1608.001
Upload Malware
GroupFIN7

FIN7 has staged legitimate software, that was trojanized to contain an Atera agent installer, on Amazon S3. FIN7 has also used an open directory web server as a staging server for payloads and other tools, such as OpenSSH and 7zip.

T1608.004
Drive-by Target
GroupFIN7

FIN7 has compromised a digital product website and modified multiple download links to point to trojanized versions of offered digital products.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.