FIN7
MITRE ATT&CK: G0046 View on attack.mitre.org
Aliases: GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS, Sangria Tempest, CARBON SPIDER, Calcium, ATK32, Coreid, Carbanak, JokerStash, FIN7
- First seen
- 2013-01-01 00:00:00
- Origin
- RU
- Primary motivation
- financial-gain
- Sophistication
- expert
- Resource level
- organization
- Actor type
- Financial Theft
- Related IoCs
- 34 (23 malicious)
- Last IoC activity
- 2026-08-14 00:47:53
- Profile updated
- 2026-07-07 12:34:01
Targeted industries: retail-and-hospitality professional-services financial-services healthcare-and-pharmaceutical media-and-entertainment transportation-and-logistics energy-and-utilities technology-and-telecommunications
Targeted regions: country_code:us
Context
FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.
Recent IoC activity
23 malicious indicators in Maltiverse are attributed to FIN7 (G0046). The 20 most recently updated:
Detection coverage
- 171 YARA rules
- 829 Sigma rules
Malware & tools used
- Code Signing (attack-pattern)
- Valid Accounts (attack-pattern)
- Command and Scripting Interpreter (attack-pattern)
- SSH (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- Junk Code Insertion (attack-pattern)
- Link Target (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Scheduled Task (attack-pattern)
- VNC (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Hidden Window (attack-pattern)
- Spearphishing Link (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Rundll32 (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Reflective Code Loading (attack-pattern)
- Visual Basic (attack-pattern)
- Remote Access Tools (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- PowerShell (attack-pattern)
- Protocol Tunneling (attack-pattern)
- Application Shimming (attack-pattern)
- Dynamic Data Exchange (attack-pattern)
- Domain Groups (attack-pattern)
Related threat objects
- Carbanak (threat-actor)
Reports & references
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- Wikipedia — Carbanak (report)
- app.box.com — P7Qzcury97Tuwk26694Uutujwqmwqyhe (report)
- 2014.zeronights.ru — Ivanovb Zeronights (report)
- web.archive.org — Odinaff New Trojan Used High Level Financial Attacks (report)
- proofpoint.com — Fin7Carbanak Threat Actor Unleashes Bateleur Jscript Backdoor (report)
- icebrg.io — Footprints Of Fin7 Tracking Actor Patterns (report)
- CrowdStrike — Arrests Put New Focus On Carbon Spider Adversary Group (report)
- europol.europa.eu — Mastermind Behind Eur 1 Billion Cyber Bank Robbery Arrested In Spain (report)
- computerweekly.com — Three Carbanak Cyber Heist Gang Members Arrested (report)
- media.kasperskycontenthub.com — Carbanak Apt Eng (report)
- group-ib.com — Anunak Apt Against Financial Institutions (report)
- MITRE ATT&CK — G0008 (report)
- Mandiant — Fin7 Spear Phishing (report)
- threatpost.com — 124369 (report)
- Mandiant — Fin7 Phishing Lnk (report)
- Mandiant — Fin7 Shim Databases Persistence (report)
- blog.morphisec.com — Fin7 Attacks Restaurant Industry (report)
- flashpoint-intel.com — Fin7 Revisited Inside Astra Panel And Sqlrat Malware (report)
- blog.morphisec.com — Fin7 Attack Modifications Revealed (report)
- blog.morphisec.com — Fin7 Not Finished Morphisec Spots New Campaign (report)
- Kaspersky — 90703 (report)
- Mandiant — Fin7 Pursuing An Enigmatic And Evasive Global Criminal Operation (report)
- MITRE ATT&CK — G0046 (report)
Attributed from
- April 2024 FIN7 Malvertising Campaign (campaign)
- FIN7 Anubis Backdoor Activity (campaign)
External references
- mitre-attack — G0046
- Carbon Spider
- FIN7
- ELBRUS
- Sangria Tempest
- GOLD NIAGARA
- Mandiant FIN7 Apr 2022
- FireEye CARBANAK June 2017
- BiZone Lizar May 2021
- FireEye FIN7 April 2017
- FireEye FIN7 Aug 2018
- Secureworks GOLD NIAGARA Threat Profile
- FireEye FIN7 Shim Databases
- Morphisec FIN7 June 2017
- ITG14
- CrowdStrike Carbon Spider August 2021
- Microsoft Threat Actor Naming July 2023
- Microsoft Ransomware as a Service
- FireEye FIN7 March 2017
- IBM Ransomware Trends September 2020