G0046

G0046FIN7

Description

[FIN7](https://attack.mitre.org/groups/G0046) is a financially-motivated threat group that has been active since 2013. [FIN7](https://attack.mitre.org/groups/G0046) has primarily targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, and utilities industries in the U.S. A portion of [FIN7](https://attack.mitre.org/groups/G0046) was run out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, [FIN7](https://attack.mitre.org/groups/G0046) shifted operations to a big game hunting (BGH) approach including use of [REvil](https://attack.mitre.org/software/S0496) ransomware and their own Ransomware as a Service (RaaS), Darkside. FIN7 may be linked to the [Carbanak](https://attack.mitre.org/groups/G0008) Group, but there appears to be several groups using [Carbanak](https://attack.mitre.org/software/S0030) malware and are therefore tracked separately.(Citation: FireEye FIN7 March 2017)(Citation: FireEye FIN7 April 2017)(Citation: FireEye CARBANAK June 2017)(Citation: FireEye FIN7 Aug 2018)(Citation: CrowdStrike Carbon Spider August 2021)(Citation: Mandiant FIN7 Apr 2022)

References

  1. https://attack.mitre.org/groups/G0046
  2. https://www.mandiant.com/resources/evolution-of-fin7
  3. https://www.fireeye.com/blog/threat-research/2017/06/behind-the-carbanak-backdoor.html
  4. https://www.fireeye.com/blog/threat-research/2017/04/fin7-phishing-lnk.html
  5. https://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html
  6. https://www.secureworks.com/research/threat-profiles/gold-niagara
  7. https://www.fireeye.com/blog/threat-research/2017/05/fin7-shim-databases-persistence.html
  8. http://blog.morphisec.com/fin7-attacks-restaurant-industry
  9. https://www.crowdstrike.com/blog/carbon-spider-embraces-big-game-hunting-part-1/
  10. https://web.archive.org/web/20180808125108/https:/www.fireeye.com/blog/threat-research/2017/03/fin7_spear_phishing.html

Software attributed to this4

TypeTargetConfidenceTier
SoftwareGRIFFONs0417100%live
SoftwareBOOSTWRITEs041595%live
SoftwareSQLRats039095%live
SoftwareJSS Loaders064895%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Group
FIN8
Group
FIN6
Group
Carbanak
Group
FIN10
Actor
FIN11
Group
FIN13
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.