GRIFFON

MITRE ATT&CK: S0417 View on attack.mitre.org

Aliases: Harpy, GRIFFON

Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:45:20

Targeted industries: financial-services retail-and-hospitality

Targeted regions: country_code:us country_code:gb country_code:ca

Context

GRIFFON is a JavaScript backdoor utilized by the cybercriminal group FIN7, known for targeting financial services and hospitality sectors. It is designed to enable remote command execution and facilitate further exploitation of compromised systems.

Detection coverage

  • 320 Sigma rules

Malware & tools used

  • Screen Capture (attack-pattern)
  • Domain Groups (attack-pattern)
  • System Time Discovery (attack-pattern)
  • JavaScript (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Scheduled Task (attack-pattern)
  • PowerShell (attack-pattern)

Used by threat actors

  • FIN7 (threat-actor)

Reports & references

  • Kaspersky — 90703 (report)
  • secureworks.com — Gold Niagara (report)
  • deepinstinct.com — Understanding The Windows Javascript Threat Landscape (report)
  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • CrowdStrike — Carbon Spider Embraces Big Game Hunting Part 1 (report)
  • Mandiant — Evolution Of Fin7 (report)
  • CrowdStrike — Carbon Spider Sprite Spider Target Esxi Servers With Ransomware (report)
  • CrowdStrike — Carbon Spider Embraces Big Game Hunting Part 2 (report)
  • cert.ssi.gouv.fr — 20220427 Np Tlpwhite Anssi Fin7 (report)
  • ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
  • Mandiant — Cds18 Technical S05 Att&Cking Fin7 (report)
  • malpedia.caad.fkie.fraunhofer.de — Js.Griffon (report)
  • twitter.com — 1059898708286939136 (report)
  • trustwave.com — Would You Exchange Your Security For A Gift Card (report)
  • MITRE ATT&CK — S0417 (report)

External references