Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ FIN7

🇷🇺FIN7

🇷🇺 FIN7 is a tracked threat actor in the Clankerusecase corpus. RU-aligned. Primary motivation: Criminal. We map 14 detection use cases to this actor across 67 MITRE ATT&CK techniques, with 0 threat-intel articles citing them.

View full actor card → All threat actors MITRE ATT&CK group spec (G0046) ↗
14Use cases
0Articles
67Techniques
0IOCs

About this actor (MITRE)

[FIN7](https://attack.mitre.org/groups/G0046) is a financially-motivated threat group that has been active since 2013. [FIN7](https://attack.mitre.org/groups/G0046) has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of [FIN7](https://attack.mitre.org/groups/G0046) was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, [FIN7](https:/

Known aliases

FIN7GOLD NIAGARAITG14Carbon SpiderELBRUSSangria Tempest

Top techniques

All other tracked techniques

T1021.004 · SSHT1021.005 · VNCT1027.010 · Command ObfuscationT1027.016 · Junk Code InsertionT1033 · System Owner/User DiscoveryT1036.004 · Masquerade Task or ServiceT1036.005 · Match Legitimate Resource Name or LocationT1047 · Windows Management InstrumentationT1053.005 · Scheduled TaskT1057 · Process DiscoveryT1059 · Command and Scripting InterpreterT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.007 · JavaScriptT1069.002 · Domain GroupsT1071.004 · DNST1078 · Valid AccountsT1078.003 · Local AccountsT1082 · System Information DiscoveryT1087.002 · Domain AccountT1091 · Replication Through Removable MediaT1102.002 · Bidirectional CommunicationT1105 · Ingress Tool TransferT1113 · Screen CaptureT1124 · System Time DiscoveryT1125 · Video CaptureT1140 · Deobfuscate/Decode Files or InformationT1190 · Exploit Public-Facing ApplicationT1195.002 · Compromise Software Supply ChainT1204.001 · Malicious LinkT1204.002 · Malicious FileT1210 · Exploitation of Remote ServicesT1218.005 · MshtaT1218.011 · Rundll32T1219 · Remote Access ToolsT1486 · Data Encrypted for ImpactT1497.002 · User Activity Based ChecksT1543.003 · Windows ServiceT1546.011 · Application ShimmingT1547.001 · Registry Run Keys / Startup FolderT1553.002 · Code SigningT1558.003 · KerberoastingT1559.002 · Dynamic Data ExchangeT1564.001 · Hidden Files and DirectoriesT1564.003 · Hidden WindowT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1567.002 · Exfiltration to Cloud StorageT1569.002 · Service ExecutionT1571 · Non-Standard PortT1572 · Protocol TunnelingT1583.001 · DomainsT1583.006 · Web ServicesT1587.001 · MalwareT1588.002 · ToolT1591 · Gather Victim Org InformationT1591.004 · Identify RolesT1608.001 · Upload MalwareT1608.004 · Drive-by TargetT1608.005 · Link TargetT1620 · Reflective Code LoadingT1674 · Input InjectionT1686 · Disable or Modify System Firewall

Detection use cases (14)

FIN7 (Carbon Spider / Sangria Tempest) POWERTRASH loader — obfuscated PowerShell from ISO/LNK lure parents AI · profile SΣ FIN7 RMM staging — silent Atera / Splashtop / ScreenConnect deployment for ransomware affiliate access AI · profile SΣ 1Password impossible-travel sign-in MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains MITRE match Developer package install spawning script-host with non-registry C2 within 5 minutes MITRE match Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint MITRE match Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) MITRE match Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution MITRE match Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress MITRE match Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes MITRE match npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules MITRE match