GRIFFON
MITRE ATT&CK: S0417 View on attack.mitre.org
Aliases: Harpy, GRIFFON
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:45:20
Targeted industries: financial-services retail-and-hospitality
Targeted regions: country_code:us country_code:gb country_code:ca
Context
GRIFFON is a JavaScript backdoor utilized by the cybercriminal group FIN7, known for targeting financial services and hospitality sectors. It is designed to enable remote command execution and facilitate further exploitation of compromised systems.
Detection coverage
- 320 Sigma rules
Malware & tools used
- Screen Capture (attack-pattern)
- Domain Groups (attack-pattern)
- System Time Discovery (attack-pattern)
- JavaScript (attack-pattern)
- System Information Discovery (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Scheduled Task (attack-pattern)
- PowerShell (attack-pattern)
Used by threat actors
- FIN7 (threat-actor)
Reports & references
- Kaspersky — 90703 (report)
- secureworks.com — Gold Niagara (report)
- deepinstinct.com — Understanding The Windows Javascript Threat Landscape (report)
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- CrowdStrike — Carbon Spider Embraces Big Game Hunting Part 1 (report)
- Mandiant — Evolution Of Fin7 (report)
- CrowdStrike — Carbon Spider Sprite Spider Target Esxi Servers With Ransomware (report)
- CrowdStrike — Carbon Spider Embraces Big Game Hunting Part 2 (report)
- cert.ssi.gouv.fr — 20220427 Np Tlpwhite Anssi Fin7 (report)
- ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
- Mandiant — Cds18 Technical S05 Att&Cking Fin7 (report)
- malpedia.caad.fkie.fraunhofer.de — Js.Griffon (report)
- twitter.com — 1059898708286939136 (report)
- trustwave.com — Would You Exchange Your Security For A Gift Card (report)
- MITRE ATT&CK — S0417 (report)