FIN7 — Ransomware Profile
FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS, Sangria Tempest
IntelFusions coverage (2)
- PackXOR Unpacked: Inside FIN7's Private Packer Used to Conceal AvNeutralizer and Other Payloads 2026-02-16 · Nation-State
- Carbanak and FIN7: Inside the TTPs of Financially Motivated Threat Groups Targeting Banks, Retail, and Hospitality 2026-02-16 · Nation-State
Tools & malware
- AdFind Network Reconnaissance
- BOOSTWRITE Loader
- Carbanak Banking Trojan
- Cobalt Strike Adversary Simulation
- CrackMapExec Network Toolkit
- GRIFFON Backdoor
- HALFBAKED Backdoor
- JSS Loader Loader
- Lizar Backdoor
- Maze Ransomware
- Mimikatz Credential Harvesting
- Pillowmint POS Malware
- POWERSOURCE Backdoor
- PowerSploit Post-Exploitation Framework
- RDFSNIFFER Backdoor
- REvil Ransomware
- SQLRat Remote Access Trojan
- TEXTMATE Backdoor
Vendor research
- To SDB, Or Not To SDB: FIN7 Leveraging Shim Databases for Persistence Erickson, J., McWhirt, M., Palombo, D
- On the Hunt for FIN7: Pursuing an Enigmatic and Evasive Global Criminal Operation Carr, N., et al
- GOLD NIAGARA CTU
- FIN7 Evolution and the Phishing LNK Carr, N., et al
- Behind the CARBANAK Backdoor Bennett, J., Vengerik, B
- FIN7 Power Hour: Adversary Archaeology and the Evolution of FIN7 Abdo, B., et al
- How Microsoft names threat actors Microsoft
- FIN7 Evolution and the Phishing LNK FireEye
- On the Hunt for FIN7: Pursuing an Enigmatic and Evasive Global Criminal Operation FireEye
- FIN7 Power Hour: Adversary Archaeology and the Evolution of FIN7 Mandiant
- Behind the CARBANAK Backdoor FireEye
- From pentest to APT attack: cybercriminal group FIN7 disguises its malware as an ethical hacker’s toolkit BiZone Lizar
- To SDB, Or Not To SDB: FIN7 Leveraging Shim Databases for Persistence FireEye
- CTU. (n.d.). GOLD NIAGARA Secureworks
- FIN7 Takes Another Bite at the Restaurant Industry Morphisec
- CARBON SPIDER Embraces Big Game Hunting, Part 1 Crowdstrike
- Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself Microsoft
- FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC Filings FireEye
- Ransomware 2020: Attack Trends Affecting Organizations Worldwide IBM