Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS, Sangria Tempest, Carbanak, Anunak, Calcium, ATK32, G0046, G0008, Coreid, JokerStash, Carbanak Group, Ukraine, WILD COMET, tracked as, Jumpy Pisces, Sangria, SSH port forwarding

Description

FIN7 originated from a Russian‐based cybercrime ring that has evolved from basic point‑of‑sale skimmers into a multifaceted adversary capable of deploying custom malware families such as Carbanak, Bateleur and SQLRAT. A hallmark of its operations is the use of hidden LNK shortcuts and mshta.exe scripts to deliver malicious VBScript payloads that execute without user interaction, coupled with sophisticated fileless tactics involving in‑memory injection into services.exe via Application Shim databases. The group routinely embeds persistence mechanisms in registry Run/RunOnce keys, Startup folder items, scheduled tasks—including OpenSSH‑based ones—and even boot or logon autostart executables. FIN7 custom loaders (BIOLOAD, BOOSTWRITE, Astra script‑management panel) are tailored per target and often require local administrative rights to deploy. FIN7 also exploits known vulnerabilities such as CVE‑2021‑31207 in Microsoft Exchange and ZeroLogon (CVE‑2020‑1472), leverages legitimate code signatures for covert activity, and distributes malicious MSIX packages through trusted brand channels or sponsored Google ads. In recent years the group expanded into ransomware with RaaS offerings like Darkside/REvil to amplify financial gains. Operationally, FIN7 combines stealthy lateral movement via compromised VPN credentials, RDP exploits and remote access tools (Cobalt Strike, PowerSploit, Atera) with rigorous collection of business‑critical data before exfiltration over standard protocols or cloud services.

Goals & Targeting

Targeted Sectors

Financial services
Financial services
Healthcare
Hospitality
Government
Retail
Defense
Pharmaceutical
Gaming
Utilities
Transportation
Media
Telecommunications
Critical infrastructure
Energy
Education
Construction
Legal services

Targeted Countries / Regions

RU
US
UA
JP
TW

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 2 days ago

Executive Summary

FIN7 is a financially‐motivated threat actor that has operated since 2013, targeting high value sectors such as retail, hospitality, healthcare and finance with sophisticated point‑of‑sale malware. It employs advanced spear‑phishing and fileless persistence techniques to infiltrate organizations, harvest credential or financial data, and in recent campaigns leverage ransomware-as‑a‑service tools for secondary monetization.

Goals & Targeting

FIN7’s strategic objective is purely monetary—acquiring financial gain through the theft of payment card information, credentials, or corporate data and later monetizing it via ransomware. The group targets high‑profile sectors (retail, hospitality, finance, healthcare, government) that exhibit frequent use of point‑of‑sale systems, legacy applications, or contain high-value data assets. FIN7’s operations are opportunistic yet calculated; it scales its infrastructure to the size and complexity of an organization, tailoring delivery mechanisms to the victim’s environment and using lateral movement tools when direct credential access is available.

Enhanced Description

Key Capabilities

  • Spear‑phishing with hidden LNK shortcuts and macro‑enabled attachments
  • Execution via mshta.exe executing VBScript
  • Fileless in‑memory injection into system processes (services.exe) via Application Shim databases
  • Persistence through registry Run/RunOnce keys, Startup folder items, scheduled tasks and OpenSSH services
  • Custom loaders per target that require administrative privileges
  • Deployment of JavaScript backdoors such as Bateleur and Carbanak
  • Use of Exchange CVE‑2021‑31207 and ZeroLogon CVE‑2020‑1472 for initial access
  • Exploitation of compromised credentials, VPN and RDP vulnerabilities for lateral movement
  • Distribution of malicious MSIX packages via trusted brand channels or Google ads
  • Legitimate code signing certificate abuse to evade detection
  • Use of remote management tools (Cobalt Strike, PowerSploit, Atera) for post‑exfiltration operations

ATT&CK Techniques

Command & Control
8 techniques
Discovery
8 techniques
Execution
14 techniques
Initial Access
5 techniques
Lateral Movement
7 techniques
Resource Development
10 techniques
Stealth
16 techniques

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

References

  1. Mandiant FIN7 Apr 2022 — Abdo, B., et al. (2022, April 4). FIN7 Power Hour: Adversary Archaeology and the Evolution of FIN7. Retrieved April 5, 2022.
  2. FireEye CARBANAK June 2017 — Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.
  3. BiZone Lizar May 2021 — BI.ZONE Cyber Threats Research Team. (2021, May 13). From pentest to APT attack: cybercriminal group FIN7 disguises its malware as an ethical hacker’s toolkit. Retrieved February 2, 2022.
  4. FireEye FIN7 April 2017 — Carr, N., et al. (2017, April 24). FIN7 Evolution and the Phishing LNK. Retrieved April 24, 2017.
  5. FireEye FIN7 Aug 2018 — Carr, N., et al. (2018, August 01). On the Hunt for FIN7: Pursuing an Enigmatic and Evasive Global Criminal Operation. Retrieved August 23, 2018.
  6. Secureworks GOLD NIAGARA Threat Profile — CTU. (n.d.). GOLD NIAGARA. Retrieved September 21, 2021.
  7. FireEye FIN7 Shim Databases — Erickson, J., McWhirt, M., Palombo, D. (2017, May 3). To SDB, Or Not To SDB: FIN7 Leveraging Shim Databases for Persistence. Retrieved July 18, 2017.
  8. Morphisec FIN7 June 2017 — Gorelik, M.. (2017, June 9). FIN7 Takes Another Bite at the Restaurant Industry. Retrieved July 13, 2017.
  9. CrowdStrike Carbon Spider August 2021 — Loui, E. and Reynolds, J. (2021, August 30). CARBON SPIDER Embraces Big Game Hunting, Part 1. Retrieved September 20, 2021.
  10. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  11. Microsoft Ransomware as a Service — Microsoft. (2022, May 9). Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself. Retrieved March 10, 2023.
  12. FireEye FIN7 March 2017 — Miller, S., et al. (2017, March 7). FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC Filings. Retrieved March 8, 2017.
  13. IBM Ransomware Trends September 2020 — Singleton, C. and Kiefer, C. (2020, September 28). Ransomware 2020: Attack Trends Affecting Organizations Worldwide. Retrieved September 20, 2021.
  14. attack.mitre.org — Cited by web research for: SSH port forwarding
  15. attack.mitre.org — Cited by web research for: T1087
  16. apt.etda.or.th — Cited by web research for: Cobalt
  17. www.huntress.com — Cited by web research for: DARKSIDE ransomware

Intel Summary

85

Techniques

51

Tools

1

Campaigns

28

IOCs

0

Observed Data

15

Tactics

Tags

Ransomware
Healthcare Targeting
APT Group
Financial Sector
Big Game Hunting

Details

MITRE ID
G0046
Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
Russia (RU)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--3753cc21-2dae-4dfb-8481-d004e74502cc
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.