67
Techniques
19
Toolsets
3
CVEs Referenced
1
KEV Entries
CISA Known Exploited
About FIN7

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.

View MITRE record ↗

Techniques by Tactic (67)
Credential Access
Toolsets (19)
🐛
Malware · Windows
🐛
Carbanak S0030
Malware · Windows
🐛
Malware · Linux, macOS, Windows
🐛
GRIFFON S0417
Malware · Windows
🐛
HALFBAKED S0151
Malware
🐛
Malware · Windows
🐛
Lizar S0681
Malware · Windows
🐛
Maze S0449
Malware · Windows
🐛
Malware · Windows
🐛
Malware · Windows
🐛
Malware · Windows
🐛
REvil S0496
Malware · Windows
🐛
SQLRat S0390
Malware
🐛
SystemBC S9001
Malware · Linux, Windows
🐛
TEXTMATE S0146
Malware · Windows
🔧
AdFind S0552
Tool · Windows
🔧
Tool · Windows
🔧
Mimikatz S0002
Tool · Windows
🔧
Tool · Windows
CVEs Referenced (3 · 1 CISA KEV)
CVE-2014-7169View full details on NVDKEV
CVE-2016-6662View full details on NVD
CVE-2017-0176View full details on NVD
References & Reports (13)
↑