Also known as: GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS, Sangria Tempest, Carbanak, Anunak, Calcium, ATK32, G0046, G0008, Coreid, JokerStash, Carbanak Group, Ukraine, WILD COMET, tracked as, Jumpy Pisces, Sangria, SSH port forwarding
FIN7 originated from a Russian‐based cybercrime ring that has evolved from basic point‑of‑sale skimmers into a multifaceted adversary capable of deploying custom malware families such as Carbanak, Bateleur and SQLRAT. A hallmark of its operations is the use of hidden LNK shortcuts and mshta.exe scripts to deliver malicious VBScript payloads that execute without user interaction, coupled with sophisticated fileless tactics involving in‑memory injection into services.exe via Application Shim databases. The group routinely embeds persistence mechanisms in registry Run/RunOnce keys, Startup folder items, scheduled tasks—including OpenSSH‑based ones—and even boot or logon autostart executables. FIN7 custom loaders (BIOLOAD, BOOSTWRITE, Astra script‑management panel) are tailored per target and often require local administrative rights to deploy. FIN7 also exploits known vulnerabilities such as CVE‑2021‑31207 in Microsoft Exchange and ZeroLogon (CVE‑2020‑1472), leverages legitimate code signatures for covert activity, and distributes malicious MSIX packages through trusted brand channels or sponsored Google ads. In recent years the group expanded into ransomware with RaaS offerings like Darkside/REvil to amplify financial gains. Operationally, FIN7 combines stealthy lateral movement via compromised VPN credentials, RDP exploits and remote access tools (Cobalt Strike, PowerSploit, Atera) with rigorous collection of business‑critical data before exfiltration over standard protocols or cloud services.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
FIN7 is a financially‐motivated threat actor that has operated since 2013, targeting high value sectors such as retail, hospitality, healthcare and finance with sophisticated point‑of‑sale malware. It employs advanced spear‑phishing and fileless persistence techniques to infiltrate organizations, harvest credential or financial data, and in recent campaigns leverage ransomware-as‑a‑service tools for secondary monetization.
Goals & Targeting
FIN7’s strategic objective is purely monetary—acquiring financial gain through the theft of payment card information, credentials, or corporate data and later monetizing it via ransomware. The group targets high‑profile sectors (retail, hospitality, finance, healthcare, government) that exhibit frequent use of point‑of‑sale systems, legacy applications, or contain high-value data assets. FIN7’s operations are opportunistic yet calculated; it scales its infrastructure to the size and complexity of an organization, tailoring delivery mechanisms to the victim’s environment and using lateral movement tools when direct credential access is available.
Enhanced Description
Key Capabilities
Odinaff
No observed data linked yet.
85
Techniques
51
Tools
1
Campaigns
28
IOCs
0
Observed Data
15
Tactics