ATT&CKReferencesBlackBerry_FIN7_April2024

BlackBerry_FIN7_April2024

The BlackBerry Research and Intelligence Team. (2024, April 17). Threat Group FIN7 Targets the U.S. Automotive Industry. Retrieved May 1, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
GroupFIN7

FIN7 has attempted to run Darkside ransomware with the filename sleep.exe. Additionally, FIN7 has mimicked WsTaskLoad.exe, which is associated with the Wondershare software suite, by using a malicious executable under the same name.

T1053.005
Scheduled Task
GroupFIN7

FIN7 malware has created scheduled tasks to establish persistence. Specifically, FIN7 has used OpenSSH to establish persistence.

T1057
Process Discovery
GroupFIN7

FIN7 has used the PowerShell script 3CF9.ps1 to perform process discovery by executing `tasklist /v`. Additionally, WsTaskLoad.exe executes `tasklist /v` to perform process discovery.

T1059.001
PowerShell
GroupFIN7

FIN7 used a PowerShell script to launch shellcode that retrieved an additional payload. Additionally, FIN7 has executed a custom obfuscation of the shellcode invoker in PowerSploit called POWERTRASH.

T1069.002
Domain Groups
GroupFIN7

FIN7 has used the command `net group "domain admins" /domain` to enumerate domain groups.

T1082
System Information Discovery
GroupFIN7

FIN7 has used csvde.exe, which is a built-in Windows command line tool, to export system information. Additionally, WsTaskLoad has gathered system information, such as operating system and hostname.

T1087.002
Domain Account
GroupFIN7

FIN7 has used the PowerShell script 3CF9.ps1 and the executable WsTaskLoad to enumerate domain administrations by executing `net group “Domain Admins” /domain`. FIN7 has also used csvde.exe, which is a built-in Windows command line tool, to export Active Directory information.

T1124
System Time Discovery
GroupFIN7

FIN7 has used the PowerShell script 3CF9.ps1 to execute `net time`.

T1486
Data Encrypted for Impact
GroupFIN7

FIN7 has encrypted virtual disk volumes on ESXi servers using a version of Darkside ransomware. Additionally, FIN7 has deployed ransomware as the end payload during big game hunting.

T1564.001
Hidden Files and Directories
GroupFIN7

FIN7 has used `attrib +h “C:\ProgramData\ssh”` to make the SSH folder hidden.

T1566.002
Spearphishing Link
GroupFIN7

FIN7 has conducted broad phishing campaigns using malicious links. Additionally, FIN7 has sent spearphishing emails containing a typosquatted link to “ip-sccanner[.]com.”

T1569.002
Service Execution
GroupFIN7

FIN7 has started the SSH service by executing `sc start sshd`.

T1571
Non-Standard Port
GroupFIN7

FIN7 has used port-protocol mismatches on ports such as 53, 80, 443, and 8080 during C2. FIN7 has used TCP ports 59999 and 9898 for firewall rules.

T1572
Protocol Tunneling
GroupFIN7

FIN7 has tunneled C2 traffic via OpenSSH.

T1583.001
Domains
GroupFIN7

FIN7 has registered look-alike domains for use in phishing campaigns. Additionally, FIN7 has registered a malicious domain as `advanced-ip-sccanner[.]com` that redirected to an adversary-controlled Dropbox which contained the malicious executable.

T1591.004
Identify Roles
GroupFIN7

FIN7 has identified IT staff and employees who had higher levels of administrative rights.

T1608.005
Link Target
GroupFIN7

FIN7 has created a fake link that redirected to an adversary-controlled Dropbox that downloaded the malicious executable.

T1686
Disable or Modify System Firewall
GroupFIN7

FIN7 has added a firewall rule to allow TCP port 59999 inbound and a rule to allow sshd.exe on TCP port 9898.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.