FORENSIA

THREAT_ACTOR · G0046

FIN7

Also known as: FIN7, GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS, Sangria Tempest

Profile

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.

MITRE ATT&CK ↗

Techniques

67 ATT&CK techniques attributed to this actor.

T1005 Data from Local SystemT1008 Fallback ChannelsT1021.001 Remote Desktop ProtocolT1021.004 SSHT1021.005 VNCT1027.010 Command ObfuscationT1027.016 Junk Code InsertionT1033 System Owner/User DiscoveryT1036.004 Masquerade Task or ServiceT1036.005 Match Legitimate Resource Name or LocationT1047 Windows Management InstrumentationT1053.005 Scheduled TaskT1057 Process DiscoveryT1059 Command and Scripting InterpreterT1059.001 PowerShellT1059.003 Windows Command ShellT1059.005 Visual BasicT1059.007 JavaScriptT1069.002 Domain GroupsT1071.004 DNST1078 Valid AccountsT1078.003 Local AccountsT1082 System Information DiscoveryT1087.002 Domain AccountT1091 Replication Through Removable MediaT1102.002 Bidirectional CommunicationT1105 Ingress Tool TransferT1113 Screen CaptureT1124 System Time DiscoveryT1125 Video CaptureT1140 Deobfuscate/Decode Files or InformationT1190 Exploit Public-Facing ApplicationT1195.002 Compromise Software Supply ChainT1204.001 Malicious LinkT1204.002 Malicious FileT1210 Exploitation of Remote ServicesT1218.005 MshtaT1218.011 Rundll32T1219 Remote Access ToolsT1486 Data Encrypted for ImpactT1497.002 User Activity Based ChecksT1543.003 Windows ServiceT1546.011 Application ShimmingT1547.001 Registry Run Keys / Startup FolderT1553.002 Code SigningT1558.003 KerberoastingT1559.002 Dynamic Data ExchangeT1564.001 Hidden Files and DirectoriesT1564.003 Hidden WindowT1566.001 Spearphishing AttachmentT1566.002 Spearphishing LinkT1567.002 Exfiltration to Cloud StorageT1569.002 Service ExecutionT1571 Non-Standard PortT1572 Protocol TunnelingT1583.001 DomainsT1583.006 Web ServicesT1587.001 MalwareT1588.002 ToolT1591 Gather Victim Org InformationT1591.004 Identify RolesT1608.001 Upload MalwareT1608.004 Drive-by TargetT1608.005 Link TargetT1620 Reflective Code LoadingT1674 Input InjectionT1686 Disable or Modify System Firewall

Software

19 malware/tools attributed to this actor.

MimikatzCarbanakPOWERSOURCETEXTMATEHALFBAKEDCobalt StrikePowerSploitSQLRatBOOSTWRITERDFSNIFFERGRIFFONMazeCrackMapExecREvilPillowmintAdFindJSS LoaderLizarSystemBC

Related corpus activity

10,447 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to FIN7.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-68670cve852
cve-2026-3102cve853
cve-2025-2492cve852
cve-2021-29441cve851
cve-2026-22584cve852
cve-2025-11837cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-17456cve851
cve-2020-22658cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2025-66478cve852
cve-2025-0921cve852
cve-2021-27076cve851
cve-2013-3307cve852
cve-2016-5681cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2025-23304cve852
cve-2021-4045cve851
cve-2020-22653cve852
cve-2022-47945cve851
cve-2025-34117cve851
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,447.