FIN7
Groups targeting financial organizations or people with significant financial assets.
FIN7 is a financially motivated threat group known for targeting financial organizations with Carbanak malware.
FIN7, also tracked as CARBON SPIDER, is a threat group primarily targeting financial organizations and individuals with significant financial assets. The group leverages the Carbanak malware alongside tools like Mimikatz, PsExec, and netsh to compromise systems, gains persistence via Windows Services, and masks its activity using techniques such as Rundll32. Defenders should prioritize monitoring for unexpected firewall modifications, unauthorized remote access tools, and anomalous Windows service configurations.
Groups targeting financial organizations or people with significant financial assets.
Monitor network traffic and executed files on host systems to detect the use of tools obtained from external sources.
Monitor system configuration changes and log service creation events to detect newly created Windows services.
Monitor process creation and system configuration changes to detect suspicious task and service names, as well as unusual uses of the Rundll32 process.
Monitor network traffic and process behavior to detect suspicious bidirectional network communication and the use of remote access tools.
Monitor system configuration changes and security-related events to detect changes to system firewall configurations.
FIN7 is a threat group primarily targeting financial organizations and individuals with significant financial assets.
Defenders should prioritize monitoring for unexpected firewall modifications, unauthorized remote access tools, and anomalous Windows service configurations.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.