FIN7

MITRE ATT&CK: G0046 View on attack.mitre.org

Aliases: GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS, Sangria Tempest, CARBON SPIDER, Calcium, ATK32, Coreid, Carbanak, JokerStash, FIN7

First seen
2013-01-01 00:00:00
Origin
RU
Primary motivation
financial-gain
Sophistication
expert
Resource level
organization
Actor type
Financial Theft
Related IoCs
34 (23 malicious)
Last IoC activity
2026-08-14 00:47:53
Profile updated
2026-07-07 12:34:01

Targeted industries: retail-and-hospitality professional-services financial-services healthcare-and-pharmaceutical media-and-entertainment transportation-and-logistics energy-and-utilities technology-and-telecommunications

Targeted regions: country_code:us

Context

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.

Recent IoC activity

23 malicious indicators in Maltiverse are attributed to FIN7 (G0046). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample updater.exe 2026-08-14 2
file sample fbd2d816147112bd408e26b1300775bbaa482342f9b33924d93fd71a5c312cce.bin 2026-08-01 1
file sample 21850bb5d8df021e850e740c1899353f40af72f119f2cd71ad234e91c2ccb772.bin 2026-07-27 1
hostname fsdgh.com 2026-07-21 1
file sample 61cfe83259640df9f19df2be4b67bb1c6e5816ac52b8a5a02ee8b79bde4b2b70.bin 2026-07-04 1
hostname git-api.com 2026-06-26 2
file sample 188d76c31fa7f500799762237508203bdd1927ec4d5232cc189d46bc76b7a30d.bin 2026-06-19 1
file sample 307c3e23a4ba65749e49932c03d5d3eb58d133bc6623c436756e48de68b9cc45 2026-04-17 1
file sample 48e3add1881d60e0f6a036cfdb24426266f23f624a4cd57b8ea945e9ca98e6fd 2026-03-26 1
file sample 1d3e573d432ef094fba33f615aa0564feffa99853af77e10367f54dc6df95509 2026-03-24 1
file sample bd1e5ea9556cb6cba9a509eab8442bf37ca40006c0894c5a98ce77f6d84b03c7.bin 2026-03-09 1
file sample e3505901fd44c8f6597ca9c512375b6ecbf3dc21dbae3d373318c99929d62091 2026-03-03 1
file sample cf1d985a33b39d332d4bac33d971a004dcd18cea82ff1b291c6a5046e073414d 2026-03-03 1
file sample 632b068e1b8fbc54eb0b30f01455c73396deb5f8e3bbd3b171fb69b6936a6019 2026-03-03 1
file sample b86612a6d62a1789031248bdb732b8bff51acaeaa687c3559f0980560a8abf2f 2026-03-03 1
file sample 42ca0d62a9516cbf4a1ffcd9097d2f2c3b135f82b1c07adf586ef5b23ce96197 2026-03-03 1
file sample 0506372e2c2b6646c539ac5a08265dd66d0da58a25545e444c25b9a02f8d9a44 2026-03-03 1
file sample 1428e14c9c86e8f068e37efc11190ee16f2cdb9bc808308c5450389ee2893c10 2026-03-03 1
file sample 4db89c39db14f4d9f76d06c50fef2d9282e83c03e8c948a863b58dedc43edd31 2025-12-20 1
file sample 166b0c5e49c44f87886ecaad46e60b496b6b7512d1c57db41d9cf752fada95c8.bin 2025-10-14 1

Detection coverage

  • 171 YARA rules
  • 829 Sigma rules

Malware & tools used

  • Code Signing (attack-pattern)
  • Valid Accounts (attack-pattern)
  • Command and Scripting Interpreter (attack-pattern)
  • SSH (attack-pattern)
  • Exploit Public-Facing Application (attack-pattern)
  • Junk Code Insertion (attack-pattern)
  • Link Target (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Scheduled Task (attack-pattern)
  • VNC (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Hidden Window (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Rundll32 (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Reflective Code Loading (attack-pattern)
  • Visual Basic (attack-pattern)
  • Remote Access Tools (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • PowerShell (attack-pattern)
  • Protocol Tunneling (attack-pattern)
  • Application Shimming (attack-pattern)
  • Dynamic Data Exchange (attack-pattern)
  • Domain Groups (attack-pattern)

Related threat objects

Reports & references

  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • Wikipedia — Carbanak (report)
  • app.box.com — P7Qzcury97Tuwk26694Uutujwqmwqyhe (report)
  • 2014.zeronights.ru — Ivanovb Zeronights (report)
  • web.archive.org — Odinaff New Trojan Used High Level Financial Attacks (report)
  • proofpoint.com — Fin7Carbanak Threat Actor Unleashes Bateleur Jscript Backdoor (report)
  • icebrg.io — Footprints Of Fin7 Tracking Actor Patterns (report)
  • CrowdStrike — Arrests Put New Focus On Carbon Spider Adversary Group (report)
  • europol.europa.eu — Mastermind Behind Eur 1 Billion Cyber Bank Robbery Arrested In Spain (report)
  • computerweekly.com — Three Carbanak Cyber Heist Gang Members Arrested (report)
  • media.kasperskycontenthub.com — Carbanak Apt Eng (report)
  • group-ib.com — Anunak Apt Against Financial Institutions (report)
  • MITRE ATT&CK — G0008 (report)
  • Mandiant — Fin7 Spear Phishing (report)
  • threatpost.com — 124369 (report)
  • Mandiant — Fin7 Phishing Lnk (report)
  • Mandiant — Fin7 Shim Databases Persistence (report)
  • blog.morphisec.com — Fin7 Attacks Restaurant Industry (report)
  • flashpoint-intel.com — Fin7 Revisited Inside Astra Panel And Sqlrat Malware (report)
  • blog.morphisec.com — Fin7 Attack Modifications Revealed (report)
  • blog.morphisec.com — Fin7 Not Finished Morphisec Spots New Campaign (report)
  • Kaspersky — 90703 (report)
  • Mandiant — Fin7 Pursuing An Enigmatic And Evasive Global Criminal Operation (report)
  • MITRE ATT&CK — G0046 (report)

Attributed from

  • April 2024 FIN7 Malvertising Campaign (campaign)
  • FIN7 Anubis Backdoor Activity (campaign)

External references