FIN7
Also tracked as GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS, Sangria Tempest
FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.
- Documented techniques
- 67
- First seen
- 2013
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
reconnaissance2
resource development7
initial access4
execution12
- T1047 Windows Management Instrumentation
- T1053.005 Scheduled Task
- T1059 Command and Scripting Interpreter
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1059.007 JavaScript
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1559.002 Dynamic Data Exchange
- T1569.002 Service Execution
- T1674 Input Injection
privilege escalation1
credential access1
discovery6
lateral movement5
command and control7
exfiltration1
defense impairment2
stealth13
- T1027.010 Command Obfuscation
- T1027.016 Junk Code Insertion
- T1036.004 Masquerade Task or Service
- T1036.005 Match Legitimate Resource Name or Location
- T1078 Valid Accounts
- T1078.003 Local Accounts
- T1140 Deobfuscate/Decode Files or Information
- T1218.005 Mshta
- T1218.011 Rundll32
- T1497.002 User Activity Based Checks
- T1564.001 Hidden Files and Directories
- T1564.003 Hidden Window
- T1620 Reflective Code Loading
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.